Compliance work should produce an evidence record that leadership and auditors can inspect. SBK provides auditor-independent guidance across regulatory scope, risk assessment, control design, incident response, and audit preparation.
Scope of work
What We Deliver
01
HIPAA Gap Assessment & Remediation
Assessment against all 54 Security Rule implementation specifications plus Privacy and Breach Notification rules. With healthcare breach costs reaching record highs year after year, investing in proper HIPAA compliance is not optional, it's a business imperative.
Administrative, physical, and technical safeguard assessment
Privacy Rule and Breach Notification Rule review
Risk-based finding prioritization from Critical to Informational
Remediation roadmap with 30/60/90/180-day milestones
Audit-ready documentation package
02
SOC 2 Readiness (Type I & Type II)
Readiness support for SOC 2 Type I and Type II examinations. We help define a defensible scope, map controls to the Trust Services Criteria, assign evidence owners, and prepare the record for an independent auditor.
All 9 Common Criteria categories assessed (CC1 through CC9)
Scope optimization, Security plus only the categories you need
Control gap identification with clear readiness levels
Policy templates and evidence collection checklists
Auditor selection guidance and coordination through certification
03
PCI DSS Assessment
Payment card data compliance validation for merchants and service providers. We guide you through the full assessment lifecycle, from scoping your cardholder data environment to maintaining annual compliance.
Cardholder data environment scoping and data flow mapping
Self-Assessment Questionnaire selection and completion guidance
Control gap analysis with prioritized remediation plan
QSA coordination for formal assessments and ROC
Annual compliance maintenance program
04
NY SHIELD Act Compliance
New York's SHIELD Act requires reasonable administrative, technical, and physical safeguards for any business holding private information of New York residents, regardless of where your company is located.
Private information inventory and data classification
Administrative, technical, and physical safeguard implementation
Employee security awareness training program
Secure data disposal procedures and documentation
Breach notification compliance procedures
05
GLBA Safeguards Rule Readiness
Readiness support for financial institutions subject to the FTC Safeguards Rule. The work centers on a written information security program, accountable governance, a written risk assessment, safeguards tied to that assessment, service provider oversight, and an inspectable evidence record.
Written Information Security Program structure and evidence map
Qualified Individual governance and reporting cadence
Written risk assessment with safeguard ownership
Service provider due diligence and monitoring procedures
FTC notification playbook for qualifying events involving at least 500 consumers
06
NYDFS Part 500 Readiness
Control and evidence readiness for covered entities under 23 NYCRR Part 500. We map regulatory obligations to accountable owners, operating controls, testing records, incident decisions, and the annual certification or acknowledgment process.
Covered-entity scope and Part 500 control gap assessment
Cybersecurity governance, policy, and senior oversight records
Risk assessment, asset inventory, access, and resilience evidence
Incident response decision tree with the 72-hour notice deadline
Annual certification or acknowledgment evidence package
07
ISO 27001 Preparation
International standard for information security management systems. ISO 27001 certification demonstrates a structured, systematic approach to managing sensitive information, increasingly required by global enterprise clients and partners.
ISMS gap assessment against all Annex A controls
Risk assessment aligned to ISO 27005 methodology
Statement of Applicability development
Internal audit program design and execution support
Certification body selection guidance and coordination
08
NIST Cybersecurity Framework Assessment
NIST Cybersecurity Framework 2.0 organizes cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. We use the framework to establish current and target profiles tied to business risk and accountable owners.
Current-state maturity assessment across all six core functions
Target-state profile development based on business risk tolerance
Gap analysis with prioritized remediation opportunities
Implementation roadmap with quick wins and long-term improvements
Framework alignment documentation for cyber insurance and contracts
Common questions
Frequently Asked Questions
How long does it take to get SOC 2 certified?
The timeline depends on scope, current control maturity, evidence quality, and the team's ability to close gaps. Type I examines control design at a point in time. Type II also examines whether controls operated during an observation period agreed with the independent auditor. Readiness begins with a scoped gap assessment and an evidence-owner plan.
What's the difference between SOC 2 Type I and Type II?
SOC 2 Type I evaluates whether controls are suitably designed at a specified date. Type II also evaluates whether those controls operated effectively throughout the examination period. The appropriate report depends on buyer requirements, contractual commitments, current maturity, and the assurance plan agreed with the independent auditor.
How much does HIPAA compliance cost?
HIPAA gap assessment cost depends on organizational size, data flows, systems, locations, and business associate relationships. Remediation cost depends on the resulting findings and the safeguards already in place. A useful estimate starts with a defined scope, a system and data inventory, and agreement on the evidence the assessment will examine.
Do I need SOC 2 if I'm a startup?
SOC 2 may be appropriate when customers, contracts, or procurement reviews require independent assurance over your controls. Start by recording the actual buyer requirement, the systems and services in scope, and the Trust Services Criteria relevant to those commitments. That record prevents an examination scope from growing beyond the business need.
What compliance framework should my business prioritize?
Start with contractual and regulatory obligations, the data you hold, the services you operate, and the evidence counterparties request. HIPAA, PCI DSS, GLBA, NYDFS Part 500, and SOC 2 serve different scopes. A unified control map can show where one operating control supports several obligations while preserving each framework's distinct reporting requirements.
What does the GLBA Safeguards Rule require?
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program led by a Qualified Individual. The program includes a written risk assessment, safeguards tied to identified risks, service provider oversight, testing or monitoring, incident response, and reporting. A qualifying notification event involving unencrypted customer information for at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
When does NYDFS require notice of a cybersecurity incident?
A covered entity must notify the New York State Department of Financial Services as promptly as possible and no later than 72 hours after determining that a reportable cybersecurity incident occurred. The incident process should preserve the facts, decision owner, determination time, affected systems, notice record, and supporting evidence.
What incident reporting clocks should financial services teams track?
The applicable clock depends on the entity and event. NYDFS Part 500 requires notice within 72 hours after a covered entity determines that a reportable cybersecurity incident occurred. SEC rules generally require a domestic registrant to disclose a material cybersecurity incident on Form 8-K within four business days after determining materiality, subject to limited delay provisions. A qualifying GLBA Safeguards Rule notification event must be reported to the FTC no later than 30 days after discovery.