
Featured Insights
ISO 27001 A.5.24: Information Security Incident Management Planning and Preparation
ISO 27001 A.5.24 requires an organization to plan and prepare for security incidents before they happen: define the roles, the response process, the ...
Filter by Tag
SOC 2 CC7.5: Recovering From Identified Security Incidents
SOC 2 CC7.5 requires a company to identify, develop, and implement the activities that recover the environment after a security incident, and to...
SOC 2 CC7.4: Responding to Security Incidents
SOC 2 CC7.4 requires a company to respond to security incidents through a defined incident-response program that understands, contains, remediates,...
The Canadian Ransomware Paradox: Why Two Surveys Disagree on Payment
Two of the most-cited Canadian ransomware statistics flatly contradict each other.
Statistics Canada, reporting on 2023 data released in October...
SOC 2 Ticketing & SLAs: Vulnerability Patching & Incident Response
TL;DR: SOC 2 compliance requires a formal, trackable process for all security-relevant activities. Under the Trust Services Criteria, this means...






