Compliance ITAR and Encryption: What You Need to Know According to the March 2020 ITAR encryption addendum, ITAR regulated data stored or transmitted in the cloud must be “end-to-end encrypted” (E2EE). Additionally, ITAR regulations state that "The means of decryption are not provided to any third party." In order to properly satisfy this rule, ITAR compliant E2E encryption requires Brendan Diaz • 2 min read
Compliance A New Year's Resolution: Low Hanging Fruit Hardly anything is predictable anymore: Covid-19, remote work, supply chain, social media vulnerabilities, data security, employee retention. It is tough doing any strategic planning these days with so many fundamental uncertainties and even tougher just managing a business day-to-day. Evan Blair • 2 min read
Compliance PHIPA, the Canadian Healthcare Compliance Regulation is More Than Just a HIPAA Clone North America has two strong healthcare compliance regulations, HIPAA (USA) and PHIPA (Canada). While the two are very similar, it’s important for Canadian healthcare companies to understand the differences - and what they are responsible for when choosing a provider that will help them communicate, collaborate, and share patient Evan Blair • 3 min read
Controlled File-Sharing The Challenge of Making Regulated Data Both Available and Secure When it comes to collaboration, the more available your data is to your employees, the less secure it is. Many organisations struggle to strike a balance between ensuring that employees have instant access to the data they need to do their jobs while shielding sensitive data from unauthorised users. With Evan Blair • 4 min read
Compliance ITAR & EAR: Think You Are Compliant? Think Again... Anyone doing business with the US government and / or producing technology or physical goods that the US considers controlled needs to spend 5 minutes here and get a refresher on ITAR and EAR. The biggest thing that scares me when I think about how folks are handling their sensitive communications Evan Blair • 4 min read
Compliance Facebook's whistleblower and what it means for your data security & GDPR program With the recent testimony in Congress on October 5 by former Facebook employee and now whistleblower, Frances Haugen, has drawn the curtain back on management’s priorities at the company, and it isn’t good. Basically, she claims profits are the top priority among Facebook’s leaders. As a result Evan Blair • 3 min read
Compliance GDPR & Collaboration: Are You Really Compliant using Slack, Box, Teams, etc...? Before we can answer that question, we need to better understand GDPR (there are a lot of false narratives out there) and what your responsibilities are, and what your providers responsibilities are. Once we understand those, we can look at some specific articles of the GDPR that will highlight (and Evan Blair • 7 min read
Compliance What you need to know about HIPAA; email, collaboration, messaging, and data sharing The need for improved HIPAA compliant technologies is becoming more apparent. The number of data breaches in the healthcare industry has increased steadily for the past four years. From 2015 to 2018 alone, healthcare breaches increased by more than 26%. And while cyber attacks are growing across all sectors, the Cecilia Clark • 7 min read
Compliance Understanding & Meeting UK MOD’s DEFCON 658 Regulatory Framework Like CMMC in the United States, The UK Ministry of Defence’s (MOD) DEFCON 658 is a cybersecurity regulatory framework that applies to any organisation doing business with the MOD. The goal of DEFCON 658 is to protect MOD Identifiable Information (MODII) across the whole of the defence supply chain Evan Blair • 2 min read
Compliance People, Process & Technology: Understanding What CMMC Means For Your Organization In Monty Python and the Holy Grail, Sir Lancelot charges guards at a castle’s gates, but abnormally. There is repeated footage of a distant charging Sir Lancelot alternated in with footage of the peaceful guards. Each time the camera cuts back to Sir Lancelot, he is charging from the Evan Blair • 4 min read