
Pillar
Compliance Playbooks
CJIS, CMMC, HIPAA, SLED, cyber-insurance and SMB security baselines.
In this pillar
Briefings on the desk.
- 01Cyber Insurance Readiness · Jul 24, 2026The cyber-insurance questionnaire, decodedCarriers stopped taking your word for it. Here's the control-by-control reality of what they now verify — and how to answer each with evidence instead of a promise.2 min
- 02CMMC & CUI · Jul 24, 2026CMMC 2.0 before the 2026 deadline: the DIB contractor's runwayPhase 2 makes a third-party assessment mandatory for Level 2, and prep takes 9–12 months. If you touch CUI and hold DoD contracts, the clock is already running.2 min
- 03CJIS · Jul 24, 2026CJIS MFA is now mandatory: the practical checklistAdvanced authentication for anyone touching Criminal Justice Information is no longer optional. Here's what the policy requires versus what an underfunded agency can actually deploy this quarter.2 min
- 04HIPAA · Jul 24, 2026The 2025 HIPAA Security Rule update, decodedThe proposed update turns 'addressable' into 'required' — mandatory MFA, encryption, and annual testing. What's changing, and what it will cost a small practice.2 min
- 05SMB Security Baseline · Jul 24, 2026Do we actually need a SOC? An honest answer for the 50-person businessThe real math on building an in-house security operations center versus running on a managed one — for a business too small to staff 24/7 but too exposed to ignore it.2 min

Not sure where you stand? Run the 3-minute insurability self-check.
Answer the same questions your carrier asks. Or talk through cybersecurity and vCISO work with the Hickman team.
15 minutes. NIST-aligned report. No obligation.
