Data + Compliance

Compliance is an architecture problem

Controls written into a policy document fail audits. We build them into the architecture, so the evidence is a byproduct of how the environment runs.

Built for the strictest standards, from SMB to enterprise.

Our view

Four principles behind every environment

Data security is not a product you buy at the end. It is a set of decisions made at the architecture stage, where they are cheap, rather than at audit, where they are not.

Data does not belong on the endpoint

Virtualized delivery keeps regulated data in the datacenter or cloud. A lost laptop becomes an inventory problem instead of a breach notification.

Identity is the perimeter

Least privilege, MFA, and conditional access decide who reaches what. Network location stopped being a meaningful control years ago.

Controls have to be enforceable

If a control depends on someone remembering to follow it, it will fail at the worst moment. We enforce in the platform, not in the handbook.

Evidence beats assertion

Auditors do not accept intent. Continuous scoring, logging, and reporting mean you can show the control was working on the date in question.

The LKMethod reference architecture

Six layers, each carrying its share of the control set

The same architecture scales from a small practice to a multi-site enterprise. What changes is depth, not shape.

Identity + Access — MFA, conditional access, privileged account separation, and joiner-mover-leaver discipline
Device — Compliance policy, encryption, patch state, and posture checks before access is granted
Network Access — Segmentation, gateway enforcement, WAF in front of exposed applications, and inspected paths
Application Delivery — Published apps and desktops that keep data server-side, with session controls and recording where required
Host Infrastructure — Hardened images, patch cadence, backup and recovery testing, and change control on defined windows
Data + Compliance — Classification, sensitivity labels, retention, sharing controls, and continuous posture scoring

Plain language

The regulations, and what they actually require

Most organizations are subject to more than one, and the overlap is larger than the difference. Nearly all come down to the same five things.

HIPAA

Health data. Requires safeguards, access controls, audit logging, and breach notification for protected health information. Applies to providers, plans, and their business associates.

PCI DSS

Payment cards. A contractual standard requiring segmentation, encryption, access control, and quarterly scanning wherever cardholder data is stored, processed, or transmitted.

SOX

Public company financial reporting. Requires controls over the systems producing financial statements, including change management, access review, and segregation of duties.

SOC 2

A voluntary audit report, not a law. An independent auditor tests your controls against five trust criteria. Frequently requested by enterprise customers during procurement.

FERPA

Student education records. Restricts disclosure and requires institutions to control access to records held by schools, districts, colleges, and their service providers.

GLBA

Financial institutions. The Safeguards Rule requires a written security program, risk assessment, access controls, encryption, and vendor oversight for customer financial data.

NIST CSF & 800-53

U.S. federal frameworks. CSF organizes security into Identify, Protect, Detect, Respond, and Recover. 800-53 is the detailed control catalog federal systems are assessed against.

CMMC

Defense contractors. Tiered certification proving protection of federal contract information and controlled unclassified information. Required to hold certain DoD contracts.

FedRAMP

Cloud services sold to U.S. federal agencies. A standardized authorization process; a service must be authorized before agencies may use it.

ISO 27001

International standard for an information security management system. Certification demonstrates a documented, audited, continuously improved security program.

GDPR

EU and UK personal data. Requires a lawful basis for processing, data subject rights, breach notification within 72 hours, and controls on international transfers.

CCPA / CPRA

California consumer data. Grants rights to know, delete, correct, and opt out of sale or sharing, with obligations that extend to service providers.

Summaries for orientation, not legal advice. Scope and obligations depend on your data, contracts, and jurisdiction, so confirm applicability with counsel or your auditor.

Cyber insurance

The five controls carriers ask about first

Cyber insurance applications have turned into technical questionnaires. These five come up on nearly every one, and they are the same controls that reduce the odds you ever file a claim.

01

MFA everywhere that matters

Remote access, email, VPN, and every administrative account. This is the single most common reason an application is declined or a premium is loaded, and carriers now verify it rather than take your word.

02

Monitored EDR or MDR

EDR or managed detection with someone actually watching the alerts. Traditional antivirus alone no longer satisfies most carriers.

03

Tested, isolated backups

Immutable or offline copies that ransomware cannot reach, plus a documented recovery time you have proven rather than estimated.

04

Privileged access control

Separate admin accounts, no shared local administrator passwords, least privilege enforced, and periodic access review with evidence.

05

Patch and vulnerability cadence

A documented schedule, a record of what was patched and when, and a defined process for the exceptions you cannot patch.

Requirements vary by carrier, industry, and revenue, and they tighten most years. Answer the application accurately: a control you claimed but cannot evidence can be grounds to deny a claim or rescind the policy.

What you get

Audit-ready, without the fire drill

The work that makes an audit painless is the same work that makes the environment run well. We do it continuously rather than in the six weeks before an assessment.

A control map, not a checklist

Every requirement traced to the layer and the technology enforcing it, so you know which control covers which clause, and where the gaps genuinely are.

Evidence generated continuously

LK Vision scores posture and captures the reporting auditors ask for, so producing evidence is an export rather than a project.

Included in every engagement

  • Documented architecture and current-state configuration baseline
  • Gap analysis against the standards that actually apply to you
  • Remediation sequenced by risk, with the cheap wins first
  • Reporting your auditor and your carrier will both accept

Why LKMethod

We work where the consequences are real

Healthcare, credit unions, financial services, government, and education. Environments where an outage, a breach, or a failed audit carries a cost beyond inconvenience.

Architecture-first controls

  • Requirements mapped to the layer that enforces them
  • Controls built into the platform rather than bolted on after
  • The same design pattern whether you are 30 people or 3,000

Continuous evidence

  • Posture scoring and reporting that runs all year
  • Configuration baselines and change history you can show
  • Findings ranked by real exposure, not by scanner severity

Senior engineering

  • The engineer who designs the control is the one who runs it
  • Straight answers about what a standard does and does not require
  • Documentation and knowledge transfer as part of the work

Thirty minutes with a senior engineer

No obligation and no sales script. Just a clear read on which standards apply to you and which controls are genuinely in place.