---
title: Truvantis Blog | vCISO
description: vCISO | Insights on Cybersecurity, Privacy and Compliance best practices from our industry experts. Topics include Penetration Testing, PCI DSS v4.0.1 Compliance and Risk Management.
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

# Blog

### Subscribe For Updates

### Recent Posts

#### Related Articles By Topic

[Security Program](https://www.truvantis.com/blog/tag/security-program) [vCISO](https://www.truvantis.com/blog/tag/vciso) [CISO](https://www.truvantis.com/blog/tag/ciso) [PCI DSS](https://www.truvantis.com/blog/tag/pci-dss) [SOC2](https://www.truvantis.com/blog/tag/soc2) [Penetration Testing](https://www.truvantis.com/blog/tag/penetration-testing) [Privacy](https://www.truvantis.com/blog/tag/privacy) [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment) [CIS Controls](https://www.truvantis.com/blog/tag/cis-controls) [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming) [HIPAA](https://www.truvantis.com/blog/tag/hipaa) [Threat Intelligence](https://www.truvantis.com/blog/tag/threat-intelligence) [ISO27001](https://www.truvantis.com/blog/tag/iso27001) [CCPA](https://www.truvantis.com/blog/tag/ccpa) [CPRA](https://www.truvantis.com/blog/tag/cpra) [GDPR](https://www.truvantis.com/blog/tag/gdpr) [Ransomware](https://www.truvantis.com/blog/tag/ransomware) [Red Team](https://www.truvantis.com/blog/tag/red-team) [HITRUST](https://www.truvantis.com/blog/tag/hitrust)

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/tag/vciso#)

[SOC2](https://www.truvantis.com/blog/tag/soc2), [vCISO](https://www.truvantis.com/blog/tag/vciso)

## [What is SOC 2 and, do you need one?](https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one)

 A SOC 2 Type 2 audit is an evaluation of risk for buyers and, a vehicle for communicating trust between two parties. But is it right for your organization? 

[Read More **](https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one)

<https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant> <https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [What is a Tabletop Exercise and Why is it Valuable? – An interview with Aaron Wheeler, Truvantis Security Consultant](https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant)

 In this interview with Truvantis CEO Andy Cottrell, Aaron Wheeler discusses conducting tabletop exercises and how his clients derive value. What is a Tabletop Exercise? “It's a chance for clients to stress test environment policiesand procedures. In 

[Read More **](https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant)

<https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant> <https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Why is Cybersecurity Difficult? – An interview with Jennifer Hill, Truvantis Security Consultant](https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant)

 In this interview with Truvantis CEO Andy Cottrell, Jenny Hill discusses the challenges and evolution of security programs she sees across industries. In theory, cybersecurity should be easy. Why is it so hard? “It never stays stagnant. Every minute 

[Read More **](https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant)

<https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment> <https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [CIS Controls](https://www.truvantis.com/blog/tag/cis-controls), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy), [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming)

### [The vCISO’s Guide to Managing Risk in Your Environment](https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment)

 Cybersecurity and privacy risks remain among the top threats facing business organizations today. Increasingly, boards are leaning on the CISO role to guide investments in cybersecurity and privacy programs, emphasizing the importance of risk 

[Read More **](https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment)

<https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs> <https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [The Board vs. Security & Privacy Programs](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

 In a corporation, the board is ultimately accountable to the shareholders for managing risks, including cybersecurity and privacy risk. Therefore, the need to address cybersecurity and privacy risk is generally accepted. However, there is often a 

[Read More **](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

<https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity> <https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Finding Peace of Mind in Cybersecurity](https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity)

 Everyone is aware Cybersecurity is a necessity. And regardless of how mature or lacking your current cybersecurity program is, the constantly changing landscape makes it challenging to stay on top of. From potential concerns related to an economic 

[Read More **](https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity)

<https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance> <https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [The Three Levels of HITRUST CSF r2 Compliance](https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance)

 The Health Information Trust Alliance (HITRUST) Common Security Framework (CSF) is a widely recognized security framework that HITRUST developed in 2007 to provide a roadmap to compliance for programs like ISO/IEC 27001 and HIPAA. HITRUST CSF 

[Read More **](https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance)

<https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect> <https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Video | The Compliance Equals Security Disconnect](https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect)

 Topic: The Compliance Equals Security Disconnect “Use the tools at your disposal correctly, stay current on threats, monitor your security posture, and live a long, prosperous, secure life." A discussion between Sean Costigan, Prof, George C. 

[Read More **](https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect)

<https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security> <https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [Security Risk Assessments & Why Compliance Equals Security](https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security)

 You likely need a risk assessment for compliance. PCI DSS 4.0, SOC2, ISO 27001, NIST, HIPAA, and other standards require a risk assessment as a fundamental part of a robust security program— and they're right to make this fundamental analysis a 

[Read More **](https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security)

<https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance> <https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [Three Steps to ISO 27001 Compliance](https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance)

 ISO27001 is the certifiable ISO standard that describes how to manage an Information Security Management System (ISMS) securely. 27001 is compatible with other standards and regulations, including SOX, GLBA and other cybersecurity regulations. 

[Read More **](https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance)

[Next](https://www.truvantis.com/blog/tag/vciso/page/2)

<https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one> <https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [vCISO](https://www.truvantis.com/blog/tag/vciso)

### [1 What is SOC 2 and, do you need one?](https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one)

 A SOC 2 Type 2 audit is an evaluation of risk for buyers and, a vehicle for communicating trust between two parties. But is it right for your ... 

[Read More **](https://www.truvantis.com/blog/what-is-soc-2-and-do-you-need-one)

<https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant> <https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [2 What is a Tabletop Exercise and Why is it Valuable? – An interview with Aaron Wheeler, Truvantis Security Consultant](https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant)

 In this interview with Truvantis CEO Andy Cottrell, Aaron Wheeler discusses conducting tabletop exercises and how his clients derive value. What ... 

[Read More **](https://www.truvantis.com/blog/what-is-a-tabletop-exercise-and-why-is-it-valuable-an-interview-with-aaron-wheeler-truvantis-security-consultant)

<https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant> <https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [3 Why is Cybersecurity Difficult? – An interview with Jennifer Hill, Truvantis Security Consultant](https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant)

 In this interview with Truvantis CEO Andy Cottrell, Jenny Hill discusses the challenges and evolution of security programs she sees across ... 

[Read More **](https://www.truvantis.com/blog/why-is-cybersecurity-difficult-an-interview-with-jennifer-hill-truvantis-security-consultant)

<https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment> <https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment>

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss), [SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [CIS Controls](https://www.truvantis.com/blog/tag/cis-controls), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Privacy](https://www.truvantis.com/blog/tag/privacy), [Red Teaming](https://www.truvantis.com/blog/tag/red-teaming)

### [4 The vCISO’s Guide to Managing Risk in Your Environment](https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment)

 Cybersecurity and privacy risks remain among the top threats facing business organizations today. Increasingly, boards are leaning on the CISO ... 

[Read More **](https://www.truvantis.com/blog/the-vcisos-guide-to-managing-risk-in-your-environment)

<https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs> <https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [5 The Board vs. Security & Privacy Programs](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

 In a corporation, the board is ultimately accountable to the shareholders for managing risks, including cybersecurity and privacy risk. ... 

[Read More **](https://www.truvantis.com/blog/the-board-vs.-security-privacy-programs)

<https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity> <https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [6 Finding Peace of Mind in Cybersecurity](https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity)

 Everyone is aware Cybersecurity is a necessity. And regardless of how mature or lacking your current cybersecurity program is, the constantly ... 

[Read More **](https://www.truvantis.com/blog/finding-peace-of-mind-in-cybersecurity)

<https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance> <https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [7 The Three Levels of HITRUST CSF r2 Compliance](https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance)

 The Health Information Trust Alliance (HITRUST) Common Security Framework (CSF) is a widely recognized security framework that HITRUST developed ... 

[Read More **](https://www.truvantis.com/blog/the-three-levels-of-hitrust-csf-r2-compliance)

<https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect> <https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [8 Video | The Compliance Equals Security Disconnect](https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect)

 Topic: The Compliance Equals Security Disconnect “Use the tools at your disposal correctly, stay current on threats, monitor your security ... 

[Read More **](https://www.truvantis.com/blog/video-the-compliance-equals-security-disconnect)

<https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security> <https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security>

[SOC2](https://www.truvantis.com/blog/tag/soc2), [CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program)

### [9 Security Risk Assessments & Why Compliance Equals Security](https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security)

 You likely need a risk assessment for compliance. PCI DSS 4.0, SOC2, ISO 27001, NIST, HIPAA, and other standards require a risk assessment as a ... 

[Read More **](https://www.truvantis.com/blog/security-risk-assessments-why-compliance-equals-security)

<https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance> <https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance>

[CISO](https://www.truvantis.com/blog/tag/ciso), [vCISO](https://www.truvantis.com/blog/tag/vciso), [Security Program](https://www.truvantis.com/blog/tag/security-program), [Risk Assessment](https://www.truvantis.com/blog/tag/risk-assessment), [ISO27001](https://www.truvantis.com/blog/tag/iso27001)

### [10 Three Steps to ISO 27001 Compliance](https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance)

 ISO27001 is the certifiable ISO standard that describes how to manage an Information Security Management System (ISMS) securely. 27001 is ... 

[Read More **](https://www.truvantis.com/blog/three-steps-to-iso-27001-compliance)

[All posts](https://www.truvantis.com/blog/all) [Next](https://www.truvantis.com/blog/tag/vciso/page/2)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)

```json
{
  "@context" : "https://schema.org",
  "@type" : "VideoObject",
  "caption" : {
    "@type" : "MediaObject",
    "contentUrl" : "https://www.truvantis.com/media-transcripts/83040286472/en.vtt",
    "inLanguage" : "en",
    "name" : "en Captions"
  },
  "contentUrl" : "https://4366475.fs1.hubspotusercontent-na2.net/hubfs/4366475/Podcasts%20or%20Vlogs/security=podcast.mp4",
  "dateModified" : "2026-06-03T18:46:34.203Z",
  "duration" : "PT7M55.477S",
  "height" : 1080,
  "name" : "security=podcast",
  "thumbnailUrl" : "https://api-na2.hubspot.com/filemanager/api/v3/files/thumbnail-redirect/83040286472?portalId=4366475&size=medium",
  "uploadDate" : "2022-08-25T18:42:52.305Z",
  "width" : 1920
}
```