top of page

ARTICLES
Got questions about technology, cyber threats, or changes in compliance? We have you covered. Dissect the latest developments, guidance, and trends with our expert insights.

Search


How to Build a Defensible IT Risk Assessment for a County or City
If your IT risk assessment is a spreadsheet with three colors and no methodology, your audit committee already knows. Here's what "defensible" actually looks like. The IT risk assessment is the load-bearing wall of your multi-year IT audit plan. If it's weak, everything on top of it is weak. And in our experience, most local-government IT risk assessments have at least one of three problems: there's no real methodology behind the rankings, they're not current, or they're not
Jul 207 min read


CMMC Phase II Is Suspended. Your Compliance Obligations Are Not.
The Department of War just suspended CMMC Phase II certification requirements — but don't mistake a paused deadline for an eliminated obligation. NIST 800-171 and DFARS 7012 are still fully enforced. Here's what actually changed, and what contractors should do in the next 60 days.
Jul 143 min read


Build vs Buy vs Embed: The AI Decision Matrix
The AI decision you keep making without noticing Call it what it is: "AI strategy" is the phrase leaders reach for to put off a decision they're already making. It implies there's one big moment coming, some strategic juncture you'll schedule once the timing's right. There isn't. The decision that truly shapes your AI posture is smaller, quieter, and you're making it repeatedly. Usually without a framework — sometimes without noticing you've made it at all. It's this: when a
Jul 135 min read


The Multi-Year IT Audit Plan, Minus the Guesswork: A Playbook for Local Government Internal Audit
Your audit committee is going to ask three questions about your IT audit plan: Is it risk-based? Can you defend it? Does it cover what matters? Here's how to answer all three. Local government internal audit shops hear a consistent question from their audit committees, elected officials, and the public: How do we know this IT audit plan covers what matters? That question carries weight given local government’s mix of legacy systems, lean IT staff, and high-value personal data
Jul 74 min read
.png)