top of page

ARTICLES
Got questions about technology, cyber threats, or changes in compliance? We have you covered. Dissect the latest developments, guidance, and trends with our expert insights.

Search


The Multi-Year IT Audit Plan, Minus the Guesswork: A Playbook for Local Government Internal Audit
Your audit committee is going to ask three questions about your IT audit plan: Is it risk-based? Can you defend it? Does it cover what matters? Here's how to answer all three. Local government internal audit shops hear a consistent question from their audit committees, elected officials, and the public: How do we know this IT audit plan covers what matters? That question carries weight given local government’s mix of legacy systems, lean IT staff, and high-value personal data
Jul 74 min read


Privileged Access: Too Many Keys, Too Little Control
Pick a critical system in your environment. Now ask yourself: how many accounts have administrative access to it? How many of those were provisioned in the last 90 days? How many belong to people who no longer work with your organization? How many belong to automated processes whose original purpose no one could explain from memory? If you can answer these questions quickly and confidently, you’re ahead of most organizations. If you can’t, you’re in good company — with real r
Jun 34 min read


What Every BEAD Subgrantee Needs to Know About the Cybersecurity Attestation Requirement
By Gillian Tedeschi, Vice President, Securance Consulting. Gillian drives Securance's go-to-market strategy for BEAD cybersecurity technical assistance, working with state broadband offices and subgrantees across the country to connect them with the compliance support they need. If you have received a Broadband Equity, Access, and Deployment (BEAD) grant award, you are likely focused on what comes next: finalizing your network design, securing equipment, coordinating with you
May 207 min read


When the Breach Hits: What Only Executive Leaders Can Do
Cyberattacks arrive without warning, escalate within hours, and demand a kind of leadership most executives have never been trained for. When an incident strikes, the decisions that define outcomes aren't made by the technical team alone — and the organizations that weather crises best are the ones whose executive leaders were already prepared."
Apr 94 min read
.png)