top of page

ARTICLES
Got questions about technology, cyber threats, or changes in compliance? We have you covered. Dissect the latest developments, guidance, and trends with our expert insights.

Search


Everyone Published a Position on AI. Almost Nobody Scored on It.
Most public sector and higher ed organizations have now published something about AI. A statement of principles. A page on the IT site. A paragraph in the strategic plan about responsible use. Almost none of them can evidence it. In our Securance 11 Peer Benchmark — eight organizations assessed against the standard — Domain 11, Ethics and External Positioning, scored 0.0 out of 9 in state and local government and 3.0 out of 9 in higher education. The higher education figure c
Jul 284 min read


HHS Just Gave You An Extra Year On The HIPAA Security Rule. Here's What To Do With It.
The HIPAA Security Rule Delay Isn’t a Pause. It’s a Head Start. The Department of Health and Human Services (HHS) just handed the healthcare industry something it rarely gets: more time. The Office of Management and Budget’s regulatory agenda now shows a final action date of July 2027 for the updated HIPAA Security Rule, a full year later than the May 2026 target HHS had originally set. For compliance teams staring down a 125-page proposed rule with mandatory encryption, mult
Jul 274 min read


Remediation Tracking: Why Spreadsheets Aren't Enough
Every cybersecurity assessment ends the same way: a report is delivered, findings are documented, and the consulting team moves on to the next engagement. What happens next is largely up to you. For most security teams, the answer is a spreadsheet. It starts reasonably enough — a tab for each finding, columns for owner, status, target date. But within a few weeks, the limitations become clear. Evidence gets attached to emails. Status updates happen in Slack threads that no on
Jul 233 min read


How to Build a Defensible IT Risk Assessment for a County or City
If your IT risk assessment is a spreadsheet with three colors and no methodology, your audit committee already knows. Here's what "defensible" actually looks like. The IT risk assessment is the load-bearing wall of your multi-year IT audit plan. If it's weak, everything on top of it is weak. And in our experience, most local-government IT risk assessments have at least one of three problems: there's no real methodology behind the rankings, they're not current, or they're not
Jul 207 min read


CMMC Phase II Is Suspended. Your Compliance Obligations Are Not.
The Department of War just suspended CMMC Phase II certification requirements — but don't mistake a paused deadline for an eliminated obligation. NIST 800-171 and DFARS 7012 are still fully enforced. Here's what actually changed, and what contractors should do in the next 60 days.
Jul 143 min read


Build vs Buy vs Embed: The AI Decision Matrix
The AI decision you keep making without noticing Call it what it is: "AI strategy" is the phrase leaders reach for to put off a decision they're already making. It implies there's one big moment coming, some strategic juncture you'll schedule once the timing's right. There isn't. The decision that truly shapes your AI posture is smaller, quieter, and you're making it repeatedly. Usually without a framework — sometimes without noticing you've made it at all. It's this: when a
Jul 135 min read


The Multi-Year IT Audit Plan, Minus the Guesswork: A Playbook for Local Government Internal Audit
Your audit committee is going to ask three questions about your IT audit plan: Is it risk-based? Can you defend it? Does it cover what matters? Here's how to answer all three. Local government internal audit shops hear a consistent question from their audit committees, elected officials, and the public: How do we know this IT audit plan covers what matters? That question carries weight given local government’s mix of legacy systems, lean IT staff, and high-value personal data
Jul 74 min read


Privileged Access: Too Many Keys, Too Little Control
Pick a critical system in your environment. Now ask yourself: how many accounts have administrative access to it? How many of those were provisioned in the last 90 days? How many belong to people who no longer work with your organization? How many belong to automated processes whose original purpose no one could explain from memory? If you can answer these questions quickly and confidently, you’re ahead of most organizations. If you can’t, you’re in good company — with real r
Jun 34 min read


What Every BEAD Subgrantee Needs to Know About the Cybersecurity Attestation Requirement
By Gillian Tedeschi, Vice President, Securance Consulting. Gillian drives Securance's go-to-market strategy for BEAD cybersecurity technical assistance, working with state broadband offices and subgrantees across the country to connect them with the compliance support they need. If you have received a Broadband Equity, Access, and Deployment (BEAD) grant award, you are likely focused on what comes next: finalizing your network design, securing equipment, coordinating with you
May 207 min read
.png)