“demonstrates that the organization has invested time, talent and infrastructure to minimize, not eliminate, cybersecurity risk” - always a point to stress. We manage risk, never eliminate it.
Christina Ayiotis“Last year, the California Privacy Protection Agency adopted a major new rule requiring certain businesses to conduct an annual cybersecurity audit. The rule went into effect 1 Jan. 2026.” iapp.org/news/a/calif... @iapp.bsky.social