Skip to content

Cybersecurity Audits & Assessments

Law & Forensics delivers comprehensive cybersecurity audits and assessments tailored to your organization's regulatory environment, identifying vulnerabilities, mitigating risk, and demonstrating compliance with industry-specific standards.

Cybersecurity Audits & Assessments capabilities

  • HIPAA Security Rule Assessment

    Evaluates security measures, policies, and procedures against the HIPAA Security Rule, identifies vulnerabilities, and delivers actionable recommendations to maintain compliance with its requirements.

  • NY DFS Cybersecurity Assessment

    Assesses your cybersecurity program and risk management practices against New York Department of Financial Services regulations, with guidance for achieving and maintaining compliance.

  • FFIEC Assessment

    Evaluates a financial institution's security posture against Federal Financial Institutions Examination Council guidelines, identifies vulnerabilities, and recommends remediation to ensure compliance.

  • CFATS Assessment

    Reviews adherence to the Chemical Facility Anti-Terrorism Standards, identifying and addressing potential security risks to meet CFATS cybersecurity requirements.

  • Third-Party Vendor Audit

    Evaluates the security posture of your vendors, identifies vulnerabilities, and recommends measures to mitigate the risks associated with third-party relationships.

  • CCPA Privacy and Cybersecurity Audit

    Examines data protection measures, privacy policies, and overall cybersecurity posture to maintain compliance with the California Consumer Privacy Act.

Cybersecurity Audits & Assessments — matters we are engaged for

  • A regulator's framework applies and nobody has mapped to it

    HIPAA Security Rule, NY DFS Part 500, FFIEC and CFATS each impose specific, testable requirements. Mapping the existing programme to the applicable one is what turns a general security posture into a compliance position.

  • An assessment is required annually and has lapsed

    The obligation is periodic and the last one predates a migration, an acquisition or a platform change. Reassessing against the current environment is what makes the certification honest.

  • Findings from the last assessment were never closed

    Open items carry forward and accumulate. A regulator reading two assessments with the same finding will ask why, and the answer needs to be documented remediation rather than intent.

  • Diligence in a transaction requires a security opinion

    A buyer, insurer or partner needs an assessment of the target's posture on a deal timetable. Scoping it to what actually affects the decision is what makes it deliverable in the window.

Cybersecurity Audits & Assessments — frequently asked questions

Which regulatory frameworks do your assessments cover?

Our assessments address a range of industry-specific frameworks, including the HIPAA Security Rule, NY DFS cybersecurity regulations, FFIEC guidelines, CFATS, and the CCPA. Each engagement is tailored to the regulations that apply to your organization.

What do we receive at the conclusion of an assessment?

Each assessment identifies vulnerabilities in your security measures and policies and provides clear, actionable recommendations for improving your security posture and achieving compliance.

Can you assess the security of our third-party vendors?

Yes. Our third-party vendor audit evaluates your vendors' security posture, identifies potential vulnerabilities, and offers recommendations for mitigating the risks associated with those relationships.

How do you tailor an assessment to our organization?

We customize each audit and assessment to your organization's specific needs and the regulatory requirements that govern your industry, ensuring a comprehensive and targeted evaluation rather than a generic checklist.

More Cybersecurity questions answered →

Cybersecurity Audits & Assessments — questions, terms and comparisons

Cybersecurity experts who testify to this work

Full expert panel →
  • Roland Cloutier, Expert Consultant, Law & Forensics

    Roland Cloutier

    Expert Consultant

    Board-Level Consulting · Enterprise & Corporate Security · Risk Management

  • Board-Level Consulting · Cybersecurity Audits & Assessments · Incident Response

  • Gary Corn, Director, Technology, Law & Security, American University, Law & Forensics

    Gary Corn

    Director, Technology, Law & Security, American University

    Cyber Warfare Consulting · Cyber Warfare Training · National Security Law

Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.

Ready to discuss your matter?

Submit a case