Before the Breach: What a Cybersecurity Assessment Reveals About Your Security Program
A joint session with Myna Partners and Morgan, Lewis & Bockius LLP
For years, formal cybersecurity risk assessments were mainly a concern for regulated industries like healthcare and financial services. HIPAA has required them since 2003, and NYDFS has made them the backbone of its Part 500 cybersecurity regulation since 2017. That era of sector-specific obligations is coming to an end.
New CCPA regulations now require annual cybersecurity audits and risk assessments for businesses whose processing presents significant risk. The first audit period begins January 1, 2027 for companies with more than $100 million in 2026 revenue. Executives must attest that the work is complete, and regulators can ask for the underlying reports at any time, with 30 calendar days to produce them.
That turns the assessment into a document with real consequences. Regulators already use past assessments to rebuild a timeline after an incident, looking at which findings were known, when they were known, and whether anyone fixed them. Organizations that find their gaps before a breach are in a far stronger position than those who learn about them from an incident, a regulator, or opposing counsel.
What This Session Covers
Dave Cohen, Hannah Levin, and Corey Gant draw on hands-on experience leading cybersecurity assessments and guiding companies through incident response and regulatory enforcement. They walk through what a formal assessment involves, what it usually uncovers, and how to structure the process so the findings strengthen your program without creating new liability.
The session covers the growing list of regulatory requirements, why weaknesses stay hidden even at organizations that assess regularly, Myna’s four-phase assessment methodology, and the practical steps to take once the results are in.
Topics covered include:
- What the new CCPA cybersecurity audit and risk assessment requirements under Articles 9 and 10 demand, including tiered deadlines, the independent auditor requirement, and executive attestation.
- How NYDFS uses risk assessments as an enforcement tool after an incident, and what that suggests about how California regulators may treat the same documents.
- Why cybersecurity weaknesses stay hidden. Some gaps come from missing coverage in scanning, monitoring, and audits. Others come from infrequent assessment while threats, systems, asset inventories, and roles keep changing.
- The compliance, customer, cyber insurance, supply chain, and financial reporting pressures behind formal security assessments.
- How NIST CSF 2.0 is structured, why the CCPA regulations point to it, and what extra work it takes to adapt an existing NIST assessment for a CCPA audit.
- A behind-the-scenes look at Myna’s process across Planning, Discovery, Assessment, and Reporting, including typical timelines and what each phase delivers.
- How findings are scored, prioritized, and presented through maturity tiers, year-over-year comparisons, and risk-ranked reporting built for leadership and boards.
- How to use a risk register to assign ownership, measure inherent and residual risk against your risk tolerance, and decide what to fix first.
- How to involve legal and outside counsel, including running readiness assessments under attorney-client privilege, so the final report doesn’t create more liability.
Key Takeaways
- Start planning now. A typical assessment takes eight to twelve weeks, and CCPA audits need clean evidence from the first day of the audit period. Organizations in the first tier should complete a readiness assessment before January 2027 so they have time to fix what it finds.
- Treat every assessment report as discoverable. Regulators and litigants may read it someday, so review its language, findings, and commitments from an adversary’s point of view before you finalize it.
- Only commit to remediation deadlines you can meet. A missed deadline for a critical finding that later contributes to an incident creates serious exposure. If a date has to move, have compensating controls and a clear explanation ready.
- Use privilege strategically. A gap assessment under attorney-client privilege ahead of ISO 27001 certification, a SOC 2 audit, or a CCPA audit lets you find and fix issues before an independent auditor sees them.
- Plan for assessments to repeat. Threats, systems, vendors, and regulations change quickly, and AI is speeding up how fast vulnerabilities get exploited. A regular cadence lets you show leadership measurable progress from year to year.
- Bring IT into the process early. Technical teams often answer assessment questions with a literal yes or no, so privacy and legal teams should help them bring forward compensating controls and supporting evidence that give assessors the full picture.
- Being proactive costs far less than a breach. Hannah Levin noted that the average cost of a U.S. incident is nearing $9 to $10 million, which makes early assessment and remediation the cheaper path by a wide margin.