Latest Insights

Compliance & Security Briefings

Deep dives on the regulations, attack paths, and standard-of-care shifts shaping secure document transport, written for security leaders, compliance officers, CIOs, and MSP partners.

Recent posts

Secure Print vs Secure Scan: Why You Need Both

Secure print stops documents in the output tray. Secure scan stops scan-to-email from leaving the building unencrypted. Two paths, two tools, one common confusion that creates an audit gap.

What FFIEC Examiners Are Flagging on Scan-to-Email in 2026

Five examiner-cycle patterns from the 2026 exam season. None named scan-to-email. All flagged it. The five-minute self-test for community banks and credit unions.

Three Centralized MFTs. Same Crew. 8,000 Organizations.

Between Dec 2020 and May 2023, the same ransomware crew breached three managed-file-transfer products. The CVE differed each time. The architecture didn't. What community-bank IT directors should take from this in 2026.

The Audit Gap That Cost Morgan Stanley $35M

Why scan-to-email never made the FFIEC IT examination handbook, the four-part structural gap behind it, and what is changing in 2024 to 2026 audit checklists.

$35M for Hard Drives: Five Lessons for Bank CFOs

Five concrete lessons from the Morgan Stanley SEC settlement for community-bank and regional-bank CFOs in 2026, with the breach-cost math and renewal angle.

Five MFP CVEs Every Bank CISO Should Know in 2026

The technical post for the CISO chair. CVE-by-CVE breakdown with attack chains and verification steps. Active exploitation through Q1 2026.

What "Secure Print" Actually Solves

Copier OEMs sell Secure Pull Print, HP Wolf Pro Security, and similar features. Those work. They cover the print path. Here is what they do not cover, and the three follow-up questions to ask your copier-vendor rep.

Scan-to-Email Is a FERPA Time Bomb in K-12

How district-wide scan workflows quietly create FERPA violations, and what superintendents and CTOs can do before the next audit.

Why Zero-Trust Document Transport Matters for MFPs

Legacy MFP trust models assume the network is safe. Zero-trust doesn't. Here's how that reshapes scan-to-delivery architecture.

The HIPAA-Compliant Scanning Checklist

A practical checklist covering the PHI transmission, retention, and access-control gaps that auditors are most likely to flag.