There is an increasingly prescriptive set of security requirements that must be met by businesses and organizations operating online. The U.S. Department of Defense started the ball rolling in 2013 requiring businesses and contractors to implement 110 specific security requirements described in NIST Special Publication 800-171. The right cybersecurity posture may also result in competitive advantage for businesses seeking to grow. Many organizations will face tough decisions on how best to comply with these new requirements and regulations. The challenge is not the regulations or the compliance itself, but the manner in which compliance has been assessed and overseen.”]