Insights & Perspectives

Senior-practitioner writing on ISO certification, AI governance, privacy, and risk for growing companies.

CMMC Phase 2 Is Suspended: What Defense Contractors Should Do
Cybersecurity

CMMC Phase 2 Is Suspended: What Defense Contractors Should Do

The DoD suspended CMMC Phase 2 and paused all future milestones pending a 60-day task force review. A suspension is not a repeal. Here is what actually changed, what did not, and why defense contractors should keep their NIST 800-171 programs moving.

July 14, 2026 · JBW Group Team
ISO 27701:2025: What Changed and Why It Matters
PrivacyISO Compliance

ISO 27701:2025: What Changed and Why It Matters

The 2025 revision of ISO 27701 modernizes privacy certification and, for the first time, lets you certify without ISO 27001 first. Here is what changed and what to do about it.

June 26, 2026 · JBW Group Team
AI Governance Is No Longer Optional. Where to Start.
AI GovernanceISO Compliance

AI Governance Is No Longer Optional. Where to Start.

AI went from pilot to production in a year at most companies. Governance did not keep pace. Here is where growing companies should start, and how ISO 42001 and the NIST AI RMF fit.

June 10, 2026 · JBW Group Team
What First-Time ISO 27001 Certification Actually Takes
ISO Compliance

What First-Time ISO 27001 Certification Actually Takes

Most companies pursue ISO 27001 because a customer, contract, or lost deal forced the issue. Here is what first-time certification actually involves, phase by phase, and where companies stall.

May 22, 2026 · JBW Group Team
When to Hire a vCISO Instead of Building In-House
Cybersecurity

When to Hire a vCISO Instead of Building In-House

Not every company needs a full-time CISO, and most cannot hire one quickly. Here is when a virtual CISO is the right call and when you have outgrown it.

May 7, 2026 · JBW Group Team
The Statement of Applicability, Explained
ISO Compliance

The Statement of Applicability, Explained

The Statement of Applicability ties your risk assessment to your controls. It is the first document an ISO 27001 auditor reads. Here is what it is and how to get it right.

April 9, 2026 · JBW Group Team
Writing an AI Acceptable Use Policy That Holds Up
AI Governance

Writing an AI Acceptable Use Policy That Holds Up

Your team is already using AI. An acceptable use policy sets the guardrails. Here is what a policy that actually holds up includes, and what makes most of them useless.

March 19, 2026 · JBW Group Team
Data Mapping: The Unglamorous Foundation of Privacy
Privacy

Data Mapping: The Unglamorous Foundation of Privacy

Every privacy obligation depends on knowing what personal data you hold and where it goes. Data mapping is that foundation. Here is what it is and how to do it well.

March 5, 2026 · JBW Group Team
Writing an SSP and POA&M That Survive an Assessment
Cybersecurity

Writing an SSP and POA&M That Survive an Assessment

The System Security Plan and Plan of Action and Milestones are the backbone of NIST 800-171 compliance. Here is what each must contain and where they fall apart.

February 12, 2026 · JBW Group Team
Understanding Your SPRS Score
Cybersecurity

Understanding Your SPRS Score

If you handle Controlled Unclassified Information, your SPRS score is your reported NIST 800-171 posture. Here is how it is calculated and why an honest one matters.

February 5, 2026 · JBW Group Team