Which rules apply to you?
Almost every business answers to at least one of these. Here's what each one is, in plain English, and how we help.
You take card payments
The Payment Card Industry Data Security Standard applies to every merchant that accepts cards — the corner shop and the five-location chain alike. We handle scoping, SAQ selection, segmentation, remediation, and the annual attestation cycle. Full PCI DSS services →
You handle health information
Medical and dental practices, behavioral health, and their business associates must protect patient data with a documented security program. We deliver the required risk analysis, policies, training, and technical safeguards — sized for independent practices, not hospital systems.
You hold New Yorkers' private data
New York's SHIELD Act requires "reasonable" administrative, technical, and physical safeguards from virtually every business holding private information of NY residents — employees count. We translate "reasonable" into a concrete, documented program.
You serve Canadian customers
Twenty minutes from the border, cross-border commerce is everyday business — and it comes with Canadian obligations. PIPEDA, Canada's federal private-sector privacy law, governs how you collect, use, and safeguard Canadians' personal information, including mandatory breach reporting. Québec's Law 25 layers on stricter consent and privacy-impact requirements for Québec residents' data, and CASL regulates commercial email and texts to Canadian recipients. We fold these into your privacy program so one set of policies covers both sides of the river.
You want a real security program — or you sell to the DoD
NIST CSF 2.0 is the backbone we anchor every governance program to. For defense contractors and suppliers near Fort Drum, we support NIST 800-171 alignment and CMMC readiness, with certified practitioner expertise in-house.
Build once, comply many times
These frameworks overlap heavily. A single well-built program — risk assessment, policy suite, access control, backup, incident response, training — satisfies the core of all of them, on both sides of the border: PIPEDA's safeguarding and breach-notification duties map cleanly onto the same controls SHIELD and HIPAA already demand. That's why we anchor everything to NIST CSF 2.0 and map outward, instead of building a separate binder for each acronym.