Client-Funded Advice ยท Zero Vendor Conflicts

Compliance & Regulatory Services

Compliance work should produce an evidence record that leadership and auditors can inspect. SBK provides auditor-independent guidance across regulatory scope, risk assessment, control design, incident response, and audit preparation.

Compliance & Regulatory Services

Scope of work

What We Deliver

01

HIPAA Gap Assessment & Remediation

Assessment against all 54 Security Rule implementation specifications plus Privacy and Breach Notification rules. With healthcare breach costs reaching record highs year after year, investing in proper HIPAA compliance is not optional, it's a business imperative.

  • Administrative, physical, and technical safeguard assessment
  • Privacy Rule and Breach Notification Rule review
  • Risk-based finding prioritization from Critical to Informational
  • Remediation roadmap with 30/60/90/180-day milestones
  • Audit-ready documentation package
02

SOC 2 Readiness (Type I & Type II)

Readiness support for SOC 2 Type I and Type II examinations. We help define a defensible scope, map controls to the Trust Services Criteria, assign evidence owners, and prepare the record for an independent auditor.

  • All 9 Common Criteria categories assessed (CC1 through CC9)
  • Scope optimization, Security plus only the categories you need
  • Control gap identification with clear readiness levels
  • Policy templates and evidence collection checklists
  • Auditor selection guidance and coordination through certification
03

PCI DSS Assessment

Payment card data compliance validation for merchants and service providers. We guide you through the full assessment lifecycle, from scoping your cardholder data environment to maintaining annual compliance.

  • Cardholder data environment scoping and data flow mapping
  • Self-Assessment Questionnaire selection and completion guidance
  • Control gap analysis with prioritized remediation plan
  • QSA coordination for formal assessments and ROC
  • Annual compliance maintenance program
04

NY SHIELD Act Compliance

New York's SHIELD Act requires reasonable administrative, technical, and physical safeguards for any business holding private information of New York residents, regardless of where your company is located.

  • Private information inventory and data classification
  • Administrative, technical, and physical safeguard implementation
  • Employee security awareness training program
  • Secure data disposal procedures and documentation
  • Breach notification compliance procedures
05

GLBA Safeguards Rule Readiness

Readiness support for financial institutions subject to the FTC Safeguards Rule. The work centers on a written information security program, accountable governance, a written risk assessment, safeguards tied to that assessment, service provider oversight, and an inspectable evidence record.

  • Written Information Security Program structure and evidence map
  • Qualified Individual governance and reporting cadence
  • Written risk assessment with safeguard ownership
  • Service provider due diligence and monitoring procedures
  • FTC notification playbook for qualifying events involving at least 500 consumers
06

NYDFS Part 500 Readiness

Control and evidence readiness for covered entities under 23 NYCRR Part 500. We map regulatory obligations to accountable owners, operating controls, testing records, incident decisions, and the annual certification or acknowledgment process.

  • Covered-entity scope and Part 500 control gap assessment
  • Cybersecurity governance, policy, and senior oversight records
  • Risk assessment, asset inventory, access, and resilience evidence
  • Incident response decision tree with the 72-hour notice deadline
  • Annual certification or acknowledgment evidence package
07

ISO 27001 Preparation

International standard for information security management systems. ISO 27001 certification demonstrates a structured, systematic approach to managing sensitive information, increasingly required by global enterprise clients and partners.

  • ISMS gap assessment against all Annex A controls
  • Risk assessment aligned to ISO 27005 methodology
  • Statement of Applicability development
  • Internal audit program design and execution support
  • Certification body selection guidance and coordination
08

NIST Cybersecurity Framework Assessment

NIST Cybersecurity Framework 2.0 organizes cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. We use the framework to establish current and target profiles tied to business risk and accountable owners.

  • Current-state maturity assessment across all six core functions
  • Target-state profile development based on business risk tolerance
  • Gap analysis with prioritized remediation opportunities
  • Implementation roadmap with quick wins and long-term improvements
  • Framework alignment documentation for cyber insurance and contracts

Common questions

Frequently Asked Questions

How long does it take to get SOC 2 certified?
The timeline depends on scope, current control maturity, evidence quality, and the team's ability to close gaps. Type I examines control design at a point in time. Type II also examines whether controls operated during an observation period agreed with the independent auditor. Readiness begins with a scoped gap assessment and an evidence-owner plan.
What's the difference between SOC 2 Type I and Type II?
SOC 2 Type I evaluates whether controls are suitably designed at a specified date. Type II also evaluates whether those controls operated effectively throughout the examination period. The appropriate report depends on buyer requirements, contractual commitments, current maturity, and the assurance plan agreed with the independent auditor.
How much does HIPAA compliance cost?
HIPAA gap assessment cost depends on organizational size, data flows, systems, locations, and business associate relationships. Remediation cost depends on the resulting findings and the safeguards already in place. A useful estimate starts with a defined scope, a system and data inventory, and agreement on the evidence the assessment will examine.
Do I need SOC 2 if I'm a startup?
SOC 2 may be appropriate when customers, contracts, or procurement reviews require independent assurance over your controls. Start by recording the actual buyer requirement, the systems and services in scope, and the Trust Services Criteria relevant to those commitments. That record prevents an examination scope from growing beyond the business need.
What compliance framework should my business prioritize?
Start with contractual and regulatory obligations, the data you hold, the services you operate, and the evidence counterparties request. HIPAA, PCI DSS, GLBA, NYDFS Part 500, and SOC 2 serve different scopes. A unified control map can show where one operating control supports several obligations while preserving each framework's distinct reporting requirements.
What does the GLBA Safeguards Rule require?
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program led by a Qualified Individual. The program includes a written risk assessment, safeguards tied to identified risks, service provider oversight, testing or monitoring, incident response, and reporting. A qualifying notification event involving unencrypted customer information for at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
When does NYDFS require notice of a cybersecurity incident?
A covered entity must notify the New York State Department of Financial Services as promptly as possible and no later than 72 hours after determining that a reportable cybersecurity incident occurred. The incident process should preserve the facts, decision owner, determination time, affected systems, notice record, and supporting evidence.
What incident reporting clocks should financial services teams track?
The applicable clock depends on the entity and event. NYDFS Part 500 requires notice within 72 hours after a covered entity determines that a reportable cybersecurity incident occurred. SEC rules generally require a domestic registrant to disclose a material cybersecurity incident on Form 8-K within four business days after determining materiality, subject to limited delay provisions. A qualifying GLBA Safeguards Rule notification event must be reported to the FTC no later than 30 days after discovery.

The next step

Know What Your Evidence Can Prove

Schedule a strategy session to map the obligations, control gaps, owners, and evidence that matter in your environment.

(718) 407-4169
contact@sbkconsultants.com