This is an article I have been meaning to write ever since we performed an IT audit for a large law firm a year or so ago. The firm was responding to the HIPAA law that requires all third-party vendors working with healthcare organizations to have a Risk Assessment.
This further proves my point that most businesses won’t do much in the area of cyber security or compliance, not even an IT risk assessment unless required by law.
Leave a reply