Orion Secure

Industries

Regulated isour comfort zone.

The harder your regulator is to please, the more useful we are. The sectors where our work goes deepest:

Financial services

NYS DFS 500GLBAFFIECOSFI B-13PIPEDACCSPACCCS

Banks, credit unions, insurers, and advisors answer to examiners who read every certification you sign. We keep the program continuously examination-ready — annual risk assessments, board reporting, and the evidence trail behind every attestation — so exam season is a review, not a scramble.

DoD suppliers

CMMC 2.0NIST 800-171DFARSCMMC 2.0NIST 800-171DFARSCPCSC (Canada)

CMMC decides whether you keep the contract. We take manufacturers and suppliers from SPRS self-assessment to assessment-ready — scoping, gap remediation, SSP and POA&M ownership — without stopping production to do it.

Healthcare

HIPAAHITECHNIST 800-66

Providers, payers, and the vendors handling their records carry obligations that survive every outsourcing decision you make. We run the security risk analysis regulators actually ask for, keep business associate agreements honest, and make the breach clock something you start on time rather than reconstruct afterwards.

Municipal & local government

NIST CSFCJISGrant compliance

Ransomware crews target towns and counties precisely because budgets are tight and IT is stretched. We bring security leadership sized for public budgets — grant-eligible assessments, practical policies, and a plan your board and your residents can stand behind.

Healthcare

PHIPAQuebec Law 25PIPEDA

Clinics, diagnostic providers, and the vendors serving them hold the most sensitive records a person has, under privacy rules that change at every provincial border. We run one program that answers PHIPA, Quebec’s Law 25, and PIPEDA together — breach assessment you can actually execute, vendor agreements that hold up, and an evidence trail ready before anyone asks for it.

Not highlighted, still coveredPCI DSSSOC 2ISO 27001GLBAFFIECNIST 800-53CIS Controls
Not highlighted, still coveredPCI DSSSOC 2ISO 27001NIST 800-53CIS Controls

Your regulator has expectations. Meet them ahead of schedule.

Request your Snapshot