Scoping is where most CMMC Level 2 efforts succeed or stall before a single control is implemented. Our latest guide breaks down CUI asset categories, data flow mapping, and how to build an assessment boundary that holds up to C3PAO scrutiny.
https://t.co/w1QTjRd6IR
After attending the ISACA Rhode Island Annual General Meeting yesterday, the Compass IT Compliance team was back on the road today for the ISACA New England GranIT Conference 2026 in Nashua, NH. We enjoyed another great day of industry discussion and networking!
Compass #security expert Patrick Laverty recently appeared on WPRI 12 News to offer commentary on a story involving a hidden camera on campus. Patrick shares tips for how IT departments can identify & prevent unauthorized hidden devices on their networks.
https://t.co/EW6w0CYqVG
How does a growing insurance advisor protect sensitive client data while pursuing SOC 2 compliance? Our latest case study explores how HealthGuys worked with Compass to complete a SOC 2 Type 1 audit & validate its applications through penetration testing:
https://t.co/KpLabJaSW4
Compass IT Compliance is proud to be at the ISACA Rhode Island Chapter Annual General Meeting today at the Amica Insurance Amphitheater in Lincoln, RI. We're looking forward to a full day of expert insights and meaningful connections around technology, risk, and security.
ποΈ New Layer 8 Podcast episode is live. Host Patrick Laverty talks with behavioral scientist and author Dr. Abbie MaroΓ±o on the science behind body language, non-verbals, and persuasion, and how we read, trust, and influence one another. Listen now:
https://t.co/jpjaAkvV8A
Compass IT Compliance was proud to support the Ronald A. Garrison Memorial Golf Tournament at Topstone Golf Course in South Windsor, CT. We were honored to be part of an event that brought the community together to raise funds for families impacted by cancer.
SOC 2 rarely makes security questionnaires disappear. It changes who asks, what they ask, and how fast you can answer. Our latest post breaks down where the real ROI of a SOC 2 Type 2 shows up in enterprise procurement.
https://t.co/XnneAPfPm3
A Third Party Administrator (TPA) breach rarely stops at the TPA. The headlines, lawsuits, and regulatory inquiries land on both sides of the contract. Our latest article covers the IT security, compliance, and vendor risk practices tha...
https://t.co/rCRO5yOfGk
ποΈ New Layer 8 Podcast episode: Host Patrick Laverty talks with John Bejakovic, author of "The 10 Commandments of Con Men..." Building on Robert Cialdini's work, John breaks down 10 influence techniques every social engineer should know. Tune in:
https://t.co/6Gpi0Sj8nT
Today we remember the fallen. To every service member who gave their life in defense of our country, and to the families who continue to feel that loss, we offer our heartfelt gratitude and respect.
Every SOC 2 Type 2 report tells a story, and savvy buyers are reading between the lines. Our latest post unpacks what enterprise security reviewers really want to see, and how to make sure your report sends the right signals.
https://t.co/rWRfR8K4Ue
A big thank you to the Maine Bankers Association for hosting another fantastic Bank Expo, and to everyone who stopped by our booth to chat with the Compass team. Special shoutout to our Co-Founder Jerry Hughes for sharing his insights on stage. Until next time, Augusta!
ποΈ New episode of the Layer 8 Podcast! Host Patrick Laverty sits down with John Costa & Jordan Saleh, the masterminds behind this year's social engineering CTF at the Layer 8 Conference. Tune in to hear how they built it & why you'll want to compete.
https://t.co/DkO2pCeu3U
The strongest PCI DSS programs treat Targeted Risk Analyses as living documents, not pre-audit paperwork. Our latest blog covers what TRAs require, common pitfalls, and how to build a sustainable TRA maintenance process.
https://t.co/1xPiz0XuHQ
We are live at the Augusta Civic Center today, exhibiting at the Maine Bankers Association Bank Expo, and our very own Co-Founder Jerry Hughes will be taking the stage to share his insights. Stop by our booth for some free swag if you plan to attend!
https://t.co/DFI94GSL8S
Scope is the single biggest lever defense contractors have over CMMC assessment cost and timeline. Read our new guide on the practical strategies for reducing CMMC scope, building a defensible enclave, and preparing for a cleaner C3PAO audit.
https://t.co/tOj9kM9f8u
PCI compliance doesn't have to derail a small business. Our latest blog breaks down how to reduce scope, simplify PCI DSS, and avoid the pitfalls we see most often in the field.
https://t.co/LpBaDCrU7s
ποΈ New Layer 8 Podcast episode! Patrick Laverty welcomes back Brett Redman, COO of OSINT Industries, to talk AI in OSINT investigations, how law enforcement use OSINT ahead of major events like the World Cup, & a preview of Brett's Layer 8 Conference talk.
https://t.co/o3rOMtDXra
Missed last week's webinar on transforming security from a roadblock into a business enabler? The recording is now liveβwatch on demand to learn how leading organizations are turning security into a competitive advantage.
https://t.co/TqLtNoMzoK