Cybersecurity Audits & Assessments
Law & Forensics delivers comprehensive cybersecurity audits and assessments tailored to your organization's regulatory environment, identifying vulnerabilities, mitigating risk, and demonstrating compliance with industry-specific standards.
Cybersecurity Audits & Assessments capabilities
HIPAA Security Rule Assessment
Evaluates security measures, policies, and procedures against the HIPAA Security Rule, identifies vulnerabilities, and delivers actionable recommendations to maintain compliance with its requirements.
NY DFS Cybersecurity Assessment
Assesses your cybersecurity program and risk management practices against New York Department of Financial Services regulations, with guidance for achieving and maintaining compliance.
FFIEC Assessment
Evaluates a financial institution's security posture against Federal Financial Institutions Examination Council guidelines, identifies vulnerabilities, and recommends remediation to ensure compliance.
CFATS Assessment
Reviews adherence to the Chemical Facility Anti-Terrorism Standards, identifying and addressing potential security risks to meet CFATS cybersecurity requirements.
Third-Party Vendor Audit
Evaluates the security posture of your vendors, identifies vulnerabilities, and recommends measures to mitigate the risks associated with third-party relationships.
CCPA Privacy and Cybersecurity Audit
Examines data protection measures, privacy policies, and overall cybersecurity posture to maintain compliance with the California Consumer Privacy Act.
Cybersecurity Audits & Assessments — matters we are engaged for
A regulator's framework applies and nobody has mapped to it
HIPAA Security Rule, NY DFS Part 500, FFIEC and CFATS each impose specific, testable requirements. Mapping the existing programme to the applicable one is what turns a general security posture into a compliance position.
An assessment is required annually and has lapsed
The obligation is periodic and the last one predates a migration, an acquisition or a platform change. Reassessing against the current environment is what makes the certification honest.
Findings from the last assessment were never closed
Open items carry forward and accumulate. A regulator reading two assessments with the same finding will ask why, and the answer needs to be documented remediation rather than intent.
Diligence in a transaction requires a security opinion
A buyer, insurer or partner needs an assessment of the target's posture on a deal timetable. Scoping it to what actually affects the decision is what makes it deliverable in the window.
Cybersecurity Audits & Assessments — frequently asked questions
Which regulatory frameworks do your assessments cover?
Our assessments address a range of industry-specific frameworks, including the HIPAA Security Rule, NY DFS cybersecurity regulations, FFIEC guidelines, CFATS, and the CCPA. Each engagement is tailored to the regulations that apply to your organization.
What do we receive at the conclusion of an assessment?
Each assessment identifies vulnerabilities in your security measures and policies and provides clear, actionable recommendations for improving your security posture and achieving compliance.
Can you assess the security of our third-party vendors?
Yes. Our third-party vendor audit evaluates your vendors' security posture, identifies potential vulnerabilities, and offers recommendations for mitigating the risks associated with those relationships.
How do you tailor an assessment to our organization?
We customize each audit and assessment to your organization's specific needs and the regulatory requirements that govern your industry, ensuring a comprehensive and targeted evaluation rather than a generic checklist.
Cybersecurity Audits & Assessments — questions, terms and comparisons
Terms defined
Cybersecurity experts who testify to this work
Full expert panel →
Roland Cloutier
Expert Consultant
Board-Level Consulting · Enterprise & Corporate Security · Risk Management

Daniel B. Garrie
Founder
Board-Level Consulting · Cybersecurity Audits & Assessments · Incident Response

Gary Corn
Director, Technology, Law & Security, American University
Cyber Warfare Consulting · Cyber Warfare Training · National Security Law
Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.
Cybersecurity Audits & Assessments case results
Technology / Ride-Sharing
Cybersecurity Expert in United States v. Joseph Sullivan — the Uber CSO Prosecution
Expert Testimony
Surviving Daubert as the cybersecurity expert in a connected-device class action
Energy & Utilities / Critical Infrastructure
Nation-State OT Intrusion Contained at a Major Regional Electric Utility

