24/7 SOC active — threats blocked today: 14,209

Compliance Guide 

The 101 Series

Ten guides. Each one answers three questions and nothing else: 
what this covers , why it matters to you, and what the 101 explains .

Written for owners and operators who need to make a decision this quarter — and precise enough that the person who handles your technology won’t roll their eyes.

A note on how we write these

Compliance content is full of numbers that sound authoritative and turn out to have no source. We check ours, and where a popular claim doesn’t hold up, we say so inside the guide. That habit is the point of the series.

The finding that shapes the whole series

Between 2024 and 2026, requirements from five separate regimes came into force — payment card rules, state financial regulation, federal consumer-finance safeguards, proposed health-data rules, and the underwriting standards of cyber insurers. Independently, they converged on the same short list:

01

Multi-factor authentication

02

Encryption

03

Asset inventory

04

Written risk assessment

05

Logging and monitoring

06

Vendor oversight

07

Incident response plan

08

Tested backups

Eight items. Implement them once, properly, and you have satisfied most of what every regime you touch is asking for. That is the most useful thing in these ten guides, and it is why we put it first rather than at the end.

01

1. Cyber Hygiene & Foundational Controls

What this covers. The essential safeguards every business needs: passwords and multi-factor authentication, backups, updates, device rules, and the basic operational discipline that holds them together.

Why it matters to you. These are the minimum that insurers, regulators and your larger customers now assume. Falling below them doesn’t just raise risk — it can invalidate the insurance you’re paying for.

What the 101 explains

  • The ten baseline controls, in the order worth doing them
  • What each one actually stops, with the mechanism explained rather than asserted
  • What you can put in place this week without a project

The uncomfortable one: an insurer went to court to rescind a policy outright over an alleged misstatement on the application about multi-factor authentication, and judgment was entered rescinding it. Not a reduced payout — the policy was treated as never having existed.

02

2. Regulations That Apply to You

What this covers. The laws and standards smaller organizations most often fall under — health-data rules, payment card standards, the federal Safeguards Rule, and the fast-growing patchwork of state privacy laws.

Why it matters to you. Non-compliance leads to fines, litigation, and denied insurance claims. But the more common problem is simpler: most owners don’t know which rules apply to them at all.

What the 101 explains

  • Which regulations attach to which kinds of business — the federal Safeguards Rule, for instance, reaches far past banks to auto dealers, tax preparers, mortgage brokers, collection agencies and finance companies
  • The thresholds that decide whether you’re captured — and the trap inside them: most state privacy laws use consumer-count thresholds a smaller business will never hit, but Texas and Nebraska set no numeric threshold at all, using a small-business definition instead
  • Where the smallest organizations get relief: under the federal Safeguards Rule, holding data on fewer than 5,000 consumers exempts you from four requirements — though notably not from multi-factor authentication, encryption, training or vendor oversight
  • A one-page checklist you can actually complete

03

3. AI Cybersecurity & Responsible AI Use

What this covers. How AI tools interact with your business data, and how to use them without giving away the things that make you money.

Why it matters to you. Your staff are already using these tools. One security vendor’s browser telemetry — from its own large-enterprise customers, sample size undisclosed — found that among employees using generative AI, roughly three-quarters paste data into it, and the large majority of those pastes come from personal, non-corporate accounts, outside anything you control or can audit. Treat the direction as reliable and the precise share as indicative.

What the 101 explains

  • Where the exposure actually occurs — it is the paste and the upload, not the tool
  • Safe usage patterns that don’t require banning anything
  • A starter AI usage policy you can adopt and adapt in an afternoon
  • How to find out which tools are already in use before writing rules about them

04

4. Incident Response Basics

What this covers. What to do in the hours after a breach, a ransomware event, or a fraudulent transfer.

Why it matters to you. Fast, correct action reduces both damage and legal exposure. Slow or improvised action compounds both — and some reporting deadlines run as short as seventy-two hours.

What the 101 explains

  • The first sixty minutes, in order, including what not to do (wiping the machine destroys the evidence your insurer and regulator will ask for)
  • Who to call, and in what sequence — counsel before forensics is usually right
  • What to document while it’s happening, because reconstruction later is unreliable
  • How recovery actually works, and why the restore you have never tested is a hypothesis rather than a plan

05

5. Vendor & Cloud Security

What this covers. How to evaluate the software, cloud platforms and service providers you depend on — and what to agree in writing before you sign.

Why it matters to you. Third parties were involved in nearly half of all confirmed breaches in the most recent industry analysis, a share that rose roughly sixty percent in a single year. This is the fastest-moving risk in the whole series.

A correction we’re making in public. It is widely repeated that most breaches at smaller organizations originate from vendors or cloud misconfigurations. The first half holds up. The second doesn’t — the whole error category that contains misconfiguration accounts for under ten percent of breaches. What actually leads is unpatched vulnerabilities and stolen credentials. We’d rather correct a claim that helps us sell than repeat it.

What the 101 explains

  • How to assess vendor risk in an afternoon, without a questionnaire nobody will complete
  • What to ask before signing: recovery time commitments, breach notification deadlines, data retention limits, and whether there is any remedy when they go down
  • Shared responsibility in cloud services — the line most owners assume sits somewhere it doesn’t
  • The connected-application audit almost nobody runs: authorization tokens held by third-party integrations bypass multi-factor authentication completely, which is exactly how more than seven hundred organizations were reached through a single chat widget vendor

06

6. Data Protection & Privacy

What this covers. How to classify, store, protect and — the part everyone skips — delete business data.

Why it matters to you. Regulators penalize process failures, not just incidents. Under US health-data enforcement, the most commonly cited violation is not a technical lapse at all; it is failure to conduct an accurate and thorough risk analysis. In a set of ransomware settlements announced in April 2026, that same failure was cited in every single case.

Another correction. The claim that data mishandling is the number one cause of regulatory penalties doesn’t survive checking. In Europe, the most frequent grounds for significant fines are the absence of a lawful basis for processing and breaches of core processing principles. In US healthcare, it’s the missing risk analysis. The pattern in both: regulators fine you for not having done the thinking, not only for the incident. That’s better news than it sounds, because the thinking is affordable.

What the 101 explains

  • What counts as sensitive data, including the categories owners routinely miss
  • How to organize and protect it without a classification project
  • Retention and deletion rules — and why holding old data is a live liability, demonstrated by school districts breached over students who had graduated years earlier
  • What a defensible risk analysis looks like, since that document is the one regulators ask for first

07

7. Cyber Insurance Requirements

What this covers. The controls underwriters require before they’ll issue a policy — and the reasons they reduce or refuse a claim afterwards.

Why it matters to you. Insurance is often the only financial buffer after an incident. The market has softened on price for twelve consecutive quarters, but it has not softened on controls. Carriers are competing on premium while holding the security bar.

What the 101 explains

  • The controls that come up in every underwriting conversation: multi-factor authentication, endpoint detection and response, privileged access management, tested backups, encryption
  • How claims data should shape your priorities — business email compromise and fraudulent transfer together account for the majority of incidents in the largest published claims dataset for smaller organizations, and roughly half of fraudulent transfer claims begin as a compromised mailbox
  • Why your application is a legal document: an alleged misstatement about multi-factor authentication has been enough for a carrier to litigate a policy out of existence entirely
  • The clause worth reading before you need it — contingent business interruption. Most standard policies require your systems to be affected. In a supply chain cascade, they aren’t.

We publish no claim-denial percentage. Every figure we found traces to marketing material with no disclosed methodology.

08

8. Security Awareness for Staff

What this covers. Helping your team recognize phishing, fraud and social engineering — and building the habit of reporting it.

Why it matters to you. The human element appears in around six in ten breaches.

The most misquoted statistic in security. That figure is the human element — which includes phishing, social engineering, stolen credentials and mistakes. It is not “human error.” Simple error is a much smaller slice. The distinction matters, because it changes what you should do: the dominant human factor is credentials, which show up somewhere in roughly four in ten breaches. Training helps. Multi-factor authentication helps more.

What the 101 explains

  • The handful of mistakes that account for most real losses, by role
  • How to train people in a way that raises reporting rates — the metric that actually predicts fast containment
  • Deepfakes and voice cloning: a single deepfaked video call cost one engineering firm around twenty-five million dollars. Two comparable attempts against other major firms failed — one because an executive asked a question only the real chief executive could have answered, the other because the employee targeted did not act on the request.
  • Why the fix for the sophisticated fake is procedural, not technical

09

9. AI-Driven Threats

What this covers. Attacks that use AI — synthetic voice and video, generated phishing at scale, automated credential attacks — and the new attack surface created by the AI features your own vendors are switching on.

Why it matters to you. Roughly one in four malicious breaches now involves AI somewhere in the attack, up more than half year over year, and those breaches cost measurably more. Separately, attackers have discovered AI branding as bait: malware disguised as popular AI services and aimed at small-business users rose nearly fivefold in early 2026.

What we won’t claim. You’ll read that AI attacks specifically target smaller organizations. We looked for the evidence and couldn’t find it — the honest statement is that AI has lowered the cost of a convincing attack, which removes the protection that being small and uninteresting used to provide. That’s a different and more useful point.

What the 101 explains

  • How AI changes attacker economics — and why “we’re too small to bother with” stopped working
  • The recognized failure modes for AI systems, in plain language: prompt injection, sensitive information disclosure, excessive agency, unbounded consumption
  • Cost-exhaustion attacks — the emerging tactic of running up a victim’s AI consumption bill rather than stealing anything
  • What defenses matter, and what you can do with no technical staff at all

10

10. Compliance Roadmaps

What this covers. Time-boxed plans you can hand to someone and have them executed.

Why it matters to you. You need structure, not complexity. Most compliance failures are sequencing failures, not effort failures.

What the 101 explains

  • The 30-day starter plan — multi-factor authentication everywhere, a written asset and data inventory, one tested restore, and a risk analysis on file
  • The 90-day uplift plan — vendor register with recovery commitments, logging and monitoring in place, incident response plan rehearsed once, access review completed
  • The annual governance plan — reassessment, penetration testing, policy refresh, insurance renewal preparation, and the board or owner report that closes the loop
  • The sequencing traps. Some things cannot be accelerated with money: a SOC 2 Type II attests to controls operating over a period — typically three months at minimum, six for a first report — and no budget compresses elapsed time. If a customer needs proof in thirty days, the honest answer is a Type I now and a Type II window that starts today.

No prep needed

Two live situations these guides track

Compliance content ages badly. Two items are moving right now, and any guide that states them flatly is already wrong:

Health data rules

A major proposed overhaul of the US health security rule — mandatory multi-factor authentication, encryption, asset inventory, annual audits — remains proposed, not final, with final action now targeted for 2027. The existing rule is what binds you today. But the proposed baseline is already what enforcement assumes, and the compliance clock after any final rule is short. Build to it now; don’t claim it’s law yet.

Defense contracting

The phased certification programme for defense suppliers had its second phase suspended in July 2026, with third-party assessment barred as an award condition during the review. Read that carefully: the certification gate slipped; the security obligation did not. The underlying control requirements, the scored self-assessment and the annual senior-official affirmation are contractual today — and a false affirmation carries federal false-claims exposure regardless of any pause.

Defending small & mid-sized businesses across the USA and U.S. territories. Eleven walls. One way through.

Industries

Healthcare

Legal

Manufacturing

Retail

Credit Unions

Gov Contractors

Blogs

Explainers

Frontiers

Citizen Awareness

Threat Reports

Newsletter

Company

Careers

Trust Center

Partners

Report an Incident

© 2026 way11.io · All rights reserved · Serving the USA & U.S. Territories

Privacy · Terms · Accessibility · Responsible Disclosure