
Most compliance failures we are called in to clean up did not begin with an attack. They began with a reasonable-sounding assumption that never got verified: that backups were running, that the old admin account was disabled, that the vendor handling card payments was doing the part everyone thought they were doing.
Not knowing has a price
The cost shows up in three places. Remediation under time pressure always costs more than planned work. Insurance and client contracts increasingly require evidence, not assurances. And the deals you quietly lose because you cannot answer a security questionnaire never appear on any invoice.
Where to start
You do not need a full audit to get out of the dark. A gap analysis against whichever framework actually applies to you, whether that is PCI DSS, HIPAA or NIST, will tell you in a couple of weeks what you are actually carrying. From there it is a prioritised list rather than a crisis.
If you are not sure which framework applies, that is a fine place to start the conversation.



