<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compliance &#8211; New England Safety Partners, LLC</title>
	<atom:link href="https://www.newenglandsp.com/category/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.newenglandsp.com</link>
	<description>New England Safety Partners, LLC</description>
	<lastBuildDate>Tue, 06 Jan 2026 16:41:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>SOC 2 Success Story: From Pressure to Proof</title>
		<link>https://www.newenglandsp.com/2026/01/soc-2-success-story-from-pressure-to-proof/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=soc-2-success-story-from-pressure-to-proof</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 16:41:11 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=19580</guid>

					<description><![CDATA[When a fast-growing call center technology company faced increasing pressure from enterprise and Fortune 500 customers, SOC 2 compliance became a business requirement rather than a nice-to-have. By partnering with New England Safety Partners, they achieved:&#x2714;&#xfe0f; SOC 2 Type I (Security &#38; Availability)&#x2714;&#xfe0f; Multiple successful SOC 2 Type II reports in subsequent years&#x2714;&#xfe0f; Stronger security [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>When a fast-growing call center technology company faced increasing pressure from enterprise and Fortune 500 customers, SOC 2 compliance became a business requirement rather than a nice-to-have.</p>



<p>By partnering with <strong>New England Safety Partners</strong>, they achieved:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> SOC 2 Type I (Security &amp; Availability)<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Multiple successful SOC 2 Type II reports in subsequent years<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Stronger security operations, training, and documentation<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Increased confidence from customers, auditors, and acquirers</p>



<p>The result? A repeatable, audit-ready security program and a smoother path through due diligence during a successful acquisition.</p>



<p>SOC 2 done right doesn’t slow growth. It enables it.</p>



<p>#SOC2 #Compliance #CyberSecurity #StartupGrowth #EnterpriseSales #Trust</p>



<p><a href="https://www.newenglandsp.com/category/compliance/" data-type="category" data-id="20">Download the Case Study</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SOC 2 Compliance: More Than a Checkbox</title>
		<link>https://www.newenglandsp.com/2026/01/soc-2-compliance-more-than-a-checkbox/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=soc-2-compliance-more-than-a-checkbox</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 16:21:41 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=19578</guid>

					<description><![CDATA[SOC 2 isn’t just about passing an audit—it’s about earning trust. For growing companies, achieving SOC 2 compliance means proving to customers, partners, and investors that security, availability, and operational discipline are built into how you operate every day, not bolted on at the last minute. Done right, SOC 2 can:&#x2705; Shorten security questionnaires&#x2705; Accelerate [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>SOC 2 isn’t just about passing an audit—it’s about earning trust.</p>



<p>For growing companies, achieving SOC 2 compliance means proving to customers, partners, and investors that security, availability, and operational discipline are built into how you operate every day, not bolted on at the last minute.</p>



<p>Done right, SOC 2 can:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Shorten security questionnaires<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Accelerate enterprise sales cycles<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Strengthen internal processes and accountability<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Demonstrate long-term commitment to protecting customer data</p>



<p>Whether you’re preparing for your first Type I or maintaining a mature Type II program, the key is treating compliance as an ongoing business process, not a one-time event.</p>



<p>Security builds trust. Trust drives growth.</p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New England Safety Partners works with Kolide on SOC2 audit</title>
		<link>https://www.newenglandsp.com/2022/06/new-england-safety-partners-works-with-kolide-on-soc2-certification/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-england-safety-partners-works-with-kolide-on-soc2-certification</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Tue, 07 Jun 2022 14:29:25 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=16358</guid>

					<description><![CDATA[For Immediate Release 7 June 2022 Kolide receives a SOC 2 Type 2 Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security and business process analysis and implementation today announced that it has helped its client, Kolide, Inc., successfully complete the Service Organization Control (SOC) [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>7 June 2022</strong></p>



<p><em>Kolide receives a SOC 2 Type 2</em></p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security and business process analysis and implementation today announced that it has helped its client, Kolide, Inc., successfully complete the Service Organization Control (SOC) 2 Type 2 audit for 2022.</p>



<p>Kolide is an endpoint security and device management company founded in 2016. Their SaaS solution helps organizations manage their employees’ devices, in order to meet their compliance objectives. Indeed, Kolide was in the somewhat unique position of using its own product to prove compliance for SOC 2 certification.</p>



<p>The audit affirms that Kolide’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security. These audits are key to demonstrating ongoing operation of critical security controls that are crucial for Kolide’s customers.</p>



<p>This marks the second time New England Safety Partners has assisted Kolide with compliance, after working on their SOC 2 Type 1 audit in 2022. Antigoni Sinanis, Director of Operations described the experience: </p>



<p>“<em>I quickly got overwhelmed by the sheer amount of evidence I had to gather and the auditors suggested <a href="https://www.newenglandsp.com/">New England Safety Partners</a> to help us get audit-ready.</em></p>



<p><em>I chose NESP over the automated compliance support products out there, because they were local and it was important to me (pre-COVID) to be able to have face-to-face interactions, and feel like I was working with people who had a personal stake in our company. I met with them every week for three months, and they worked with me to gather the evidence I needed</em>.”&nbsp;</p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<hr class="wp-block-separator has-css-opacity"/>



<p><a id="_msocom_1"></a></p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p>Kolide, Inc<br>Nick Fitzsimmons<br><a href="mailto:pr@kolide.co">pr@kolide.co</a><br><a href="https://www.kolide.com/">https://www.kolide.com/</a></p>



<p><br></p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Assembled Financial Technology’s (AFT) new banking platform, anda, has achieved PCI/DSS compliance</title>
		<link>https://www.newenglandsp.com/2022/04/assembled-financial-technologys-aft-new-banking-platform-anda-has-achieved-pci-dss-compliance/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=assembled-financial-technologys-aft-new-banking-platform-anda-has-achieved-pci-dss-compliance</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Wed, 06 Apr 2022 13:21:07 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=15960</guid>

					<description><![CDATA[For Immediate Release 4 April 2022 AFT’s anda is positioned to safeguard cardholder data Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security and business process analysis and implementation today is proud to announce that Assembled Financial Technology’s (AFT) new banking platform, anda, has achieved [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>For Immediate Release</p>



<p><strong>4 April 2022</strong></p>



<p><em>AFT’s anda is positioned to safeguard cardholder data</em></p>



<p>Newton, MA – New England Safety Partners (NESP), an Information Security Consulting firm specializing in compliance frameworks, cloud security and business process analysis and implementation today is proud to announce that Assembled Financial Technology’s (AFT) new banking platform, anda, has achieved PCI/DSS compliance! Compliance with the Payment Card Industry Data Security Standard (PCI/DSS) is a requirement for any merchant or processor of cardholder data.</p>



<p>The anda mission is to revolutionize banking through a crypto engagement platform that dramatically improves program economics while simultaneously delivering financial benefits to Latinos, a community in need of better financial solutions.</p>



<p>This milestone is critical to demonstrating that AFT’s anda is positioned to safeguard cardholder data, and has implemented policies and procedures to keep that data safe.</p>



<p>“NESP helped us navigate the PCI compliance minefield. We couldn’t have done it without them!” Shahin Jahromi, AFT’s Chief Product and Technology Officer.</p>



<p><strong>About New England Safety Partners</strong></p>



<p>Founded in 2013, and located in Newton, Massachusetts, New England Safety Partners has helped businesses of all sizes with comprehensive risk management services in cyber security and compliance management.</p>



<p><strong>About AFT</strong></p>



<p>Assembled Financial is a technology company that builds software products to improve the financial well-being of individuals and communities.</p>



<p><strong><em>For more information contact:</em></strong></p>



<p>New England Safety Partners<br>Edward Gardner<br><a href="mailto:edg@newenglandsp.com">edg@newenglandsp.com<br></a><a href="https://www.newenglandsp.com">https://www.newenglandsp.com</a></p>



<p><br></p>



<p>Assembled Financial Technology<br>9000 Sunset Boulevard Suite 1010<br>West Hollywood, CA 90069<br>(310) 695-1290<br><a href="mailto://hello@assembledbrands.com">hello@assembledfinancial.com</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Pitfalls in Access Control</title>
		<link>https://www.newenglandsp.com/2016/02/pitfalls-in-access-control/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pitfalls-in-access-control</link>
		
		<dc:creator><![CDATA[Ed Gardner]]></dc:creator>
		<pubDate>Thu, 25 Feb 2016 13:51:58 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Monthly Security Awareness]]></category>
		<guid isPermaLink="false">https://www.newenglandsp.com/?p=7778</guid>

					<description><![CDATA[A primary goal of Access Control is to prevent loss, be it losses of confidentiality, information integrity or information availability.  It goes without saying that in order to protect your assets and information, you must explicitly control who and what has access.  (And sometimes when, where and how.)  Ideally, Access Control is well defined as [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A primary goal of Access Control is to prevent loss, be it losses of confidentiality, information integrity or information availability.  It goes without saying that in order to protect your assets and information, you must explicitly control who and what has access.  (And sometimes when, where and how.)  Ideally, Access Control is well defined as part of a comprehensive Security Policy, one that is clearly understood by the personnel bound by it.</p>
<p>A few pitfalls in Access Control:</p>
<ul>
<li>Not adhering to a Least Privilege strategy &#8211; Simply put, personnel and workstations are granted the least privilege necessary to perform their responsibilities and no more.  A computer at a reception desk shouldn’t have access to critical organizational information.  The same is true for a vendor who may legitimately need access to some area of an organization’s resources.  Do not allow more access than is absolutely necessary.</li>
</ul>
<ul>
<li>Excessive Privileges or Creeping Privileges – This can happen when a manager moves from one role to another and, through oversight, retains access to assets of the initial role.  Another example is where personnel have risen in an organization over time.  As one gains increased privileges within the system, it may be awkward to remove access a person no longer needs to perform regular duties.  Standing policies and regular reviews of access are good ways to reduce these vulnerabilities.</li>
</ul>
<ul>
<li>Allowing personnel to access critical information in less secure environments or on less secure devices – An organization may allow a junior executive to retain access to systems and information while on vacation in a foreign country.  In all but the rarest circumstances, disabling such access reduces the risk of compromise.  Likewise, mobile devices, by definition, aren’t always protected by an organization’s firewall.  Train your personnel in what the organization requires, on site and off.</li>
</ul>
<ul>
<li>Single Factor Authentication – An Identity which attempts to access systems and information must be Authenticated.  Authentication may be as simple as providing the right password for the Identity.  This is sometimes referred to as “something you know.”  A more secure Authentication strategy is Multifactor Authentication.  This may include a small device you carry, also referred to as “something you have.”  Also, biometrics is a growing factor in Authentication, using unique aspects of an Identity or ‘something you are.”  Multifactor Authentication provides more secure Access Control than a single factor alone.</li>
</ul>
<ul>
<li>Ensuring that accounts, keys and devices assigned to personnel leaving the organization are suspended and collected before the person leaves the premises.  If the organization uses keyless entryways, change the codes at reasonable intervals and especially when someone leaves the organization.</li>
</ul>
<p>These are but a few examples of comprehensive Access Control.  NESP can help you with your policies, procedures and training.  If you have any questions about reducing your risk from improper access, give us a call or send us email today. We are here to help!</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
