Resources

Guides, Data, and Answers
for Risk Decisions

Reference guides built the way we build risk intelligence: concrete numbers, sourced claims, and honest ranges. No gated PDFs.

Topic

CMMC Compliance

Topic

Cyber Risk Quantification

Topic

Compliance by Vertical

Healthcare · HIPAA

The HIPAA Risk Analysis OCR Actually Requires

The most-cited deficiency in OCR enforcement — what “accurate and thorough” means, the 2026 expansion into risk management, and the documentation chain that survives an investigation.

8 min read
Healthcare · Crosswalk

HIPAA + HITRUST: Assess Once, Satisfy Both

One is a law with no certificate; the other is the certificate health systems demand. How they relate, the e1/i1/r2 tiers, and how to stop collecting the same evidence twice.

8 min read
Technology · Decision Guide

SOC 2 vs ISO 27001: What Buyers Actually Want

An attestation report versus a certificate, a US default versus an international one — and an 80% overlap that makes either/or the wrong frame.

8 min read
Technology · Sales Velocity

Surviving Enterprise Security Questionnaires

SIG, CAIQ, or the customer’s own 400-row spreadsheet. The response strategies ranked — from artisanal suffering to evidence that maps itself.

8 min read
Financial Services · NYDFS

NYDFS Part 500: The Full Regulation, In Force

Dual-signature certification, Class A audits, the 24-hour ransom payment notice — what 23 NYCRR 500 demands now that the phased deadlines are done.

8 min read
Financial Services · DORA

DORA for US Firms: The Regulation in Your Contracts

You won’t hear from an EU regulator — you’ll get a redlined contract. How DORA reaches US providers and what it asks for, recurringly.

8 min read
Manufacturing & Energy · OT

IEC 62443, Explained Without the Priesthood

Zones, conduits, Security Levels 1–4, and seven foundational requirements — the industrial security standard decoded into the four ideas that do the work.

8 min read
Cross-Industry · Insurance

What Cyber Insurance Underwriters Actually Check

The seven control gates, the attestation gap that voids claims, and the limits question almost nobody quantifies before signing.

8 min read
Also from Risk Aperture

The Cybersecurity Poverty Line

Every enterprise has a minimum viable security posture. The essay that defines how much security is enough — and how to find your line.

Read the Essay

Numbers for Your
Specific Enterprise

These guides give you the industry ranges. PRISM and Foundations give you YOUR numbers—risk in dollars, compliance status by control, investment optimized to your reality.