The Cyber Governance GroupSecurity · Risk · Compliance
[ Industries ]

Different missions. Same need to stay secure.

We focus on the organizations communities depend on. Each one protects different people, data and services, and we shape every engagement around what matters most to yours.

01

Credit unions

  • NCUA ISE
  • ACET
  • 12 CFR 748

Federally insured credit unions are examined on information security, and the scope grows with asset size. Examiners expect a current risk assessment, a written program, board oversight and evidence, and assembling that evidence is often the hardest part.

  • Risk assessments aligned to NCUA expectations.
  • ACET-aligned maturity and inherent risk profiling.
  • Vulnerability assessments of your network, Microsoft 365 and internet-facing systems, with findings written up for your board and examiners.
  • Exam preparation: assembling the documentation examiners request.
  • Board reporting, and incident procedures that meet the 72-hour reporting rule.
02

School districts

  • FERPA
  • Student data
  • Ed-tech vendors

Districts hold sensitive student and staff data and depend on dozens of ed-tech vendors. Pennsylvania hasn't yet adopted the K-12 cybersecurity mandates some states have, which makes now the right time to build a program on your own terms.

  • Security and privacy assessments covering FERPA obligations.
  • Data sharing agreements for ed-tech vendors.
  • Incident planning sized for district IT teams.
  • Reporting to boards and superintendents.
03

Counties, municipalities & authorities

  • NIST CSF
  • Public records

Attacks on local emergency dispatch and water systems have put local government cybersecurity in front of Pennsylvania lawmakers, and other states have begun requiring formal programs. Residents expect the services they rely on to keep running.

  • NIST CSF-based assessments that become a budget-ready roadmap.
  • Policies aligned with public records and retention obligations.
  • Incident planning for emergency services, utilities and critical operations.
  • Clear briefings for commissioners, councils and authority boards.
04

Small & mid-sized businesses

  • Cyber insurance
  • FTC Safeguards Rule
  • PCI DSS

Most businesses answer to someone on security, even if no regulator ever visits: a cyber insurer at renewal, a bank or card processor, a large customer's questionnaire, or a federal rule they didn't know applied to them.

  • Insurance renewal readiness: answers you can stand behind, with the evidence to prove them.
  • FTC Safeguards Rule programs for auto dealers, tax preparers, mortgage brokers and other non-bank financial businesses: a written program, a designated qualified individual and an annual report to the board or a senior officer.
  • PCI DSS scoping and questionnaire readiness if you take cards, including scope reduction with tokenization, P2PE and hosted payment pages.
  • A fractional CISO when you want executive-level security guidance without a full-time hire.
05

Healthcare practices

  • HIPAA
  • Breach Notification
  • PA BPINA

HIPAA applies to every practice that handles patient information, regardless of size. One of the gaps regulators cite most often is also the most fundamental: no accurate, organization-wide risk analysis.

  • Security Rule risk analysis across every administrative, physical and technical safeguard.
  • Documented decisions on "addressable" safeguards, as the rule requires.
  • Business associate agreement inventory and oversight.
  • Breach response covering HIPAA plus Pennsylvania's HIV, mental-health and patient-record confidentiality laws.
06

Vendors & service providers

  • Business associates
  • Ed-tech
  • Agency vendors

Hospitals, school districts, credit unions and Commonwealth agencies increasingly expect their vendors to prove their security, not just promise it. A billing company, software provider or IT firm can lose a contract over a questionnaire it couldn't answer well.

  • Security questionnaires answered from your actual program, with a reusable answer library for the next one.
  • Business associate and data-sharing obligations under HIPAA and FERPA, documented the way your customers expect.
  • Independent assessments where a Commonwealth agency requires one under ITP-SEC023.
Start a conversation

Don't see your sector?

Insurance agencies, professional services firms and Commonwealth vendors face many of the same requirements.