Risk visibility. Practical controls. Clear decisions.
Explore five practical, simulated governance, risk, and compliance engagements illustrating how VeriGate approaches evidence review, risk identification, control gaps, remediation planning, and executive reporting.
Assessment case studies
NIST CSF 2.0 Gap Assessment
Assess governance, inventory, access protection, incident response, and recovery against selected CSF 2.0 outcomes.
View case study →02HIPAA Security Risk Assessment
Evaluate safeguards for electronic protected health information using selected HIPAA Security Rule standards.
View case study →03Third-Party Vendor Risk Assessment
Assess the proposed healthcare billing vendor before onboarding and handling ePHI.
View case study →04SOC 2 Readiness Review
Perform a limited readiness review of selected security-related Trust Services Criteria.
View case study →05Access Governance and RBAC Review
Review fictional employee roles, privileged access, and least-privilege exceptions.
View case study →NIST CSF 2.0 Gap Assessment
Assess governance, inventory, access protection, incident response, and recovery against selected CSF 2.0 outcomes.
ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.
Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.
Unclear accountability; No approved cybersecurity RACI.
Approve security RACI and annual review. Action: Assign CISO delegate; approve matrix.
Findings snapshot
| ID | Reference | Control gap | Severity | Remediation |
|---|---|---|---|---|
| VG-01-01 | GV.RR | No approved cybersecurity RACI | High | Assign CISO delegate; approve matrix |
| VG-01-02 | ID.AM | Incomplete SaaS asset inventory | High | Reconcile monthly |
| VG-01-03 | PR.AA | MFA missing on 8 privileged accounts | Critical | Enroll admins and verify logs |
| VG-01-04 | DE.CM | No centralized alert triage | High | Enable logging and weekly review |
| VG-01-05 | RS.MA | Incident playbook untested | Medium | Document findings and retest |
Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.
Download synthetic findings CSV ↗HIPAA Security Risk Assessment
Evaluate safeguards for electronic protected health information using selected HIPAA Security Rule standards.
ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.
Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.
Undetected threats to ePHI; No documented enterprise ePHI risk analysis.
Perform thorough risk analysis. Action: Assign owners and track treatment.
Findings snapshot
| ID | Reference | Control gap | Severity | Remediation |
|---|---|---|---|---|
| VG-02-01 | 164.308(a)(1)(ii)(A) | No documented enterprise ePHI risk analysis | Critical | Assign owners and track treatment |
| VG-02-02 | 164.312(a)(1) | Shared EHR account in billing team | High | Remove shared account; provision named users |
| VG-02-03 | 164.312(b) | EHR audit log retention unverified | High | Test audit reporting monthly |
| VG-02-04 | 164.308(a)(7) | Restore testing not evidenced | High | Record RTO/RPO and test results |
| VG-02-05 | 164.312(e)(1) | Vendor file transfer not assessed | Medium | Obtain technical evidence |
Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.
Download synthetic findings CSV ↗Third-Party Vendor Risk Assessment
Assess the proposed healthcare billing vendor before onboarding and handling ePHI.
ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.
Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.
Unverified control environment; Vendor cannot supply current assurance report.
Request SOC 2 report or alternative evidence. Action: Conditional approval pending review.
Findings snapshot
| ID | Reference | Control gap | Severity | Remediation |
|---|---|---|---|---|
| VG-03-01 | SOC 2 report | Vendor cannot supply current assurance report | High | Conditional approval pending review |
| VG-03-02 | BAA | Healthcare data processor has no executed BAA | Critical | Legal review and signature |
| VG-03-03 | SSO/MFA | Admin access lacks enforced MFA | High | Obtain configuration evidence |
| VG-03-04 | BCP/DR | No recovery test results | Medium | Add remediation deadline |
| VG-03-05 | Vendor inventory | Subprocessor list missing | Medium | Update vendor inventory |
Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.
Download synthetic findings CSV ↗SOC 2 Readiness Review
Perform a limited readiness review of selected security-related Trust Services Criteria.
ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.
Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.
Unauthorized access persists; Quarterly access reviews not documented.
Institute documented access certification. Action: Run and sign quarterly reviews.
Findings snapshot
| ID | Reference | Control gap | Severity | Remediation |
|---|---|---|---|---|
| VG-04-01 | CC6.1 | Quarterly access reviews not documented | High | Run and sign quarterly reviews |
| VG-04-02 | CC8.1 | Emergency changes lack approval trail | High | Sample tickets monthly |
| VG-04-03 | CC7.2 | Security alerts not assigned | High | Measure response SLAs |
| VG-04-04 | CC3.2 | Risk register not approved | Medium | Quarterly governance meeting |
| VG-04-05 | CC9.2 | Critical vendors not reviewed | Medium | Collect evidence and track gaps |
Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.
Download synthetic findings CSV ↗Access Governance and RBAC Review
Review fictional employee roles, privileged access, and least-privilege exceptions.
ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.
Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.
Bulk data disclosure; Billing analyst can export full patient dataset.
Limit export to approved roles. Action: Remove permission; test access.
Findings snapshot
| ID | Reference | Control gap | Severity | Remediation |
|---|---|---|---|---|
| VG-05-01 | Least privilege | Billing analyst can export full patient dataset | Critical | Remove permission; test access |
| VG-05-02 | Privileged access | Help desk has permanent global admin | Critical | Remove standing privilege |
| VG-05-03 | Deprovisioning | Former contractor account active for 21 days | High | Disable account; reconcile HR feed |
| VG-05-04 | Segregation of duties | Clinical user can edit billing rates | High | Reassign role and validate |
| VG-05-05 | Credential governance | Service credential has no rotation owner | Medium | Vault secret and rotate |
Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.
Download synthetic findings CSV ↗How to interpret these demonstrations
Each case study is an educational, limited-scope simulation. A real engagement requires written scope, authorized access, interviews, verified evidence, applicable control criteria, risk acceptance decisions, and independent validation of remediation. SOC 2 readiness is not a SOC 2 examination; HIPAA risk analysis examples do not establish legal compliance.
VeriGate IT & Compliance, LLC | Governance, Risk & Compliance | Cybersecurity advisory