Cybersecurity

Privacy and compliance readiness

Privacy laws, sector rules, client contracts and cyber insurers all expect you to protect information properly and prove it. We help organizations understand the technical and operational side of those expectations, close the gaps and prepare the evidence. We work alongside your legal counsel; we do not give legal advice or certify compliance.

Who this service is for

A good fit if

  • You collect personal information and are not confident your practices would stand up to a complaint or a breach investigation.
  • You do business in California, Texas or another state with a comprehensive privacy law, or serve its residents, and need to prepare for its requirements.
  • You are a HIPAA covered entity, or a business associate handling protected health information for one.
  • You are a bank, credit union or non-bank financial company, or supply one, and need to meet GLBA Safeguards Rule, FFIEC or NYDFS Part 500 expectations.
  • A client, insurer or auditor has sent a security questionnaire, or you are preparing for SOC 2, ISO/IEC 27001 or a CMMC 2.0 assessment.

Another approach may suit you better if

  • You need a legal opinion on your obligations. That must come from a lawyer; we can work with yours.
  • You need someone to certify or attest that you comply. That is done by independent, accredited bodies; we prepare you for them.
  • You want policies written only to file away. We focus on practices that actually operate.

What this service is

Compliance readiness means getting your privacy and security practices to the point where they meet the requirements that apply to you, and being able to show it. Promatics handles the technical and operational side: what data you hold, how it is protected, how breaches are handled, and what evidence exists. Your legal counsel interprets the law; independent bodies certify. We sit between the two and do the practical work.

US requirements we commonly prepare for

The United States has no single federal privacy law, so requirements usually come from several sources at once.

  • State comprehensive privacy laws, such as the California Consumer Privacy Act as amended by the CPRA, the Texas Data Privacy and Security Act, and laws in Virginia, Colorado and a growing number of other states. They cover privacy notices, consumer rights (access, deletion, correction, and opting out of sale, sharing and targeted advertising), data protection assessments for high-risk processing, and contracts with service providers.
  • State breach notification laws, which every state has, each with its own definition of personal information, triggers and timelines, alongside state laws that expect reasonable security safeguards.
  • HIPAA, whose Privacy, Security and Breach Notification Rules apply to covered entities such as healthcare providers and health plans, and to business associates that handle protected health information for them under business associate agreements (BAAs).
  • The GLBA Safeguards Rule for financial institutions, enforced by the FTC for non-bank financial companies, together with the FFIEC IT Examination Handbook and the 2023 interagency guidance on third-party risk management for banks, NYDFS Part 500 for New York-regulated financial companies, and NCUA expectations for credit unions.
  • The FTC Act, under which the FTC treats misleading privacy promises and unreasonable data security as unfair or deceptive practices.
  • CAN-SPAM and the TCPA, where email marketing, calls, texts and consent practices are part of the review.

These summaries are general and not legal advice. Your counsel should confirm what applies to you.

Frameworks, audits and insurers

Many organizations need to satisfy someone other than a regulator. We prepare you for:

  • The NIST Cybersecurity Framework 2.0 and the CIS Controls, common baselines for organizations of any size, and CMMC 2.0 for defense contractors handling federal contract information or controlled unclassified information, where higher levels require an assessment by an authorized third-party assessment organization.
  • SOC 2 and ISO/IEC 27001, often requested by enterprise clients. Reports and certificates come from independent auditors and registrars.
  • Cyber insurance questionnaires, which commonly ask about MFA, EDR, backups, email security and training.
  • Client security questionnaires and contract clauses on data location, breach notification and subcontractors.

Breach readiness

The first days after a breach are stressful, and decisions made then are hard to undo. A breach response plan sets out how an incident is contained, who assesses which notification laws are triggered and by when, who decides on reporting and notification, who speaks to your insurer and counsel, and how the incident record is kept. We build the plan with you and rehearse it in a tabletop exercise.

How we work with your counsel and auditors

Readiness work goes faster when roles are clear. Your legal counsel decides which obligations apply and how to read them. Your auditor or certification body decides whether you meet a standard. We translate their requirements into systems, procedures and evidence, flag questions that need a legal answer instead of guessing, and keep a traceable list showing each requirement, the control that meets it, its owner and where the evidence lives. That list becomes the working document for everyone involved, and it stays with you after we finish.

Connected services

Readiness often reveals technical work. Security assessments measure your controls in depth, and our wider cybersecurity services close the gaps, including EDR, email security and awareness training.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A map of the laws, rules, contracts and frameworks that likely apply, confirmed with your counsel.
  • An inventory of the personal information you hold, where it is stored, who can access it and how long it is kept.
  • A gap review of technical and organizational safeguards against the applicable requirements.
  • A prioritized remediation plan, with owners and effort estimates.
  • A breach response plan, including how incidents are assessed against state notification laws and sector rules, who decides on notification, and how records are kept.
  • An incident and breach log recording each incident, how it was assessed and what was decided, which regulators and insurers commonly ask to see.
  • Review of vendor and cloud contracts for security, data location, breach notification and service-provider terms, including business associate agreements.
  • Support for data protection assessments, which several state privacy laws require for high-risk processing such as targeted advertising, selling personal data or processing sensitive data.
  • Evidence packs and help answering client, insurer and auditor questionnaires.

Not included unless agreed separately

  • Legal advice or legal opinions.
  • Certification, attestation or audit reports.
  • Filing breach reports or notifying individuals on your behalf.
  • Fixing technical findings, unless included in the scope or delivered under a separate agreement.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • A named person accountable for privacy and security in your organization (HIPAA and the FTC Safeguards Rule, for example, require one).
  • Access to your legal counsel for questions of interpretation.
  • Existing policies, contracts, insurer questionnaires and past incident records.
  • Time with the people who manage IT, HR, finance and client records.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Scope the requirements

    Identify which laws, sector rules, contracts and frameworks are likely to apply, and confirm them with your counsel.

    Output: Requirements map.

  2. Understand your data

    Inventory what personal information you collect, why, where it lives, who can see it and how long it is kept.

    Output: Data inventory and flow diagram.

  3. Review the gaps

    Compare your technical and organizational safeguards with the requirements and rank the gaps by risk.

    Output: Gap report and remediation plan.

  4. Close the gaps

    Update controls, procedures, contracts and training, and build the breach response plan and log.

    Output: Updated safeguards and breach plan.

  5. Prepare the evidence

    Assemble the documents and records an auditor, insurer or regulator would ask for, and rehearse a breach scenario.

    Output: Evidence pack and tabletop results.

Testing and handover

  • Every requirement in scope is traced to a control, an owner and evidence.
  • Gaps that remain open are listed with an owner and target date, not hidden.
  • The breach response plan is rehearsed with the people who would use it.
  • Legal interpretations are marked as questions for your counsel, not answered by us.
  • Documents are written for your staff to maintain after we finish.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in US dollars, with taxes shown separately. These are the things that move the number most:

  • The number of laws, rules and frameworks in scope.
  • The amount and sensitivity of personal information you hold.
  • The number of systems, vendors and locations.
  • How much evidence and documentation already exists.
  • Whether remediation is included or handled separately.

Questions buyers usually ask

Is this legal advice?

No. We explain the technical and operational side of privacy and security requirements and help you put them into practice. Your legal counsel should confirm which obligations apply and how to interpret them, and we are happy to work with them.

What do US laws require after a breach?

It depends on the data and where the affected people live. Every state has a breach notification law with its own triggers and timelines; Texas, for example, requires notice to individuals within 60 days and to the Texas Attorney General within 30 days when 250 or more Texans are affected. Health data falls under the HIPAA Breach Notification Rule, non-bank financial institutions may owe notice to the FTC under the Safeguards Rule, and public companies may need to file an SEC Form 8-K. Read more in our breach reporting overview.

Can you certify that we comply?

No. Certification and attestation, such as SOC 2 reports, ISO/IEC 27001 certificates or CMMC 2.0 assessments, come from independent auditors, accredited registrars and authorized assessment organizations. We help you get ready for them and gather the evidence they will ask for.

Does storing data in a US cloud region make us compliant?

Not on its own. Choosing a US region, such as AWS US East in Northern Virginia or Azure South Central US in Texas, supports data residency, but compliance also depends on access controls, contracts, support access and how data is backed up and transferred. We review the whole picture.

We are a small organization. Does this apply to us?

Some obligations, such as state breach notification laws, the FTC Act and HIPAA, apply regardless of size, while many state comprehensive privacy laws apply only above revenue or data-volume thresholds. Your counsel can confirm which apply to you. The work scales down, and a small organization usually needs a focused data inventory, a breach plan and a handful of well-run controls.

Has a client, insurer or regulator started asking questions?

Tell us what has been asked and what information you handle. We will reply to arrange a conversation about getting ready.