compliance

Category

On July 13, 2026, the Department of War (DoW) announced a pause of the planned CMMC Phase II implementation while it conducts a 60-day review of the program. The DoW chief information officer (CIO) has suspended CMMC Phase II requirements and directed a…

Sharon Nichols, Sr GRC Consultant, and Rolando Torres, VP Cyber Consulting and GRC Services 
July 14, 2026 4 Min Read

This guide breaks down how to identify the right time to outsource, what services to prioritize, and how to choose a provider that fits your business.

January 27, 2026 < 1 Min Read

For organizations working with the Department of Defense (DoD), achieving Cybersecurity Maturity Model Certification (CMMC) compliance is a regulatory obligation, as well as a strategic requirement that impacts your ability to win contracts and protect…

Andrew Archibald, VP, Cybersecurity Advisory Services
October 1, 2025 2 Min Read
Subscribe Via Email

In today’s business environment, demonstrating strong cybersecurity practices is essential for regulatory compliance and earning the trust of customers, partners, and investors. For service organizations, achieving SOC 2 compliance is a way to show that…

Chip Gibbons, SVP of IT and Security
September 19, 2025 2 Min Read

When talking about security or real-life attacks, the focus naturally tends to be on the things that went wrong. Security reports look at the most common “ways in” or new potential exploits. In a sense,…

Christopher Clark, Cybersecurity Incident Responder and Threat Hunter
July 28, 2025 3 Min Read

For small and medium-sized businesses (SMBs), achieving a robust cybersecurity posture is no longer optional in today’s fast-paced digital world. For organisations in the UK, the National Cyber Security Centre’s (NCSC) Cyber Essentials control framework…

Rusty King, VP, Consulting Services
December 2, 2024 2 Min Read

If your organization is using Microsoft 365 for digital collaboration, you may face challenges with managing your SharePoint storage and its associated costs. As your organization grows and generates more content, you may find yourself…

Matt Tabor, Director, Microsoft Platform Services
September 6, 2024 2 Min Read

Just a year ago, the U.S. Security and Exchange Commission (SEC) adopted rules requiring registrants to provide annual enhanced and standardized disclosures regarding “cybersecurity risk management, strategy, governance, and incidents.” This ruling aims to bring…

Scot Guido, Managing Partner, Financial Services
July 24, 2024 3 Min Read

As you may remember from our first blog post on strengthening financial IT resilience, the Digital Operational Resilience Act (DORA) was enacted on January 16, 2023, and will be enforced soon, with supervision starting January…

Ian Bowell, vCISO
July 23, 2024 5 Min Read

Thrive is continuously monitoring changes in the regulatory environment to ensure we are prepared to help our clients achieve and maintain compliance. The U.S. Securities and Exchange Commission (SEC) adopted updates to Regulation S-P (Reg…

Alexander Byrne, Director of Compliance
May 24, 2024 7 Min Read

The financial sector is bracing for a significant shift with the U.S. Securities and Exchange Commission (SEC) “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure” rule taking effect on December 18, 2023. As the deadline…

Thrive
December 13, 2023 3 Min Read