New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Knowledge base
Privacy & Security Answers
Privacy & security, answered. Clear, expert-reviewed answers to the questions teams actually ask — from SOC 2 and PIAs to breach response and AI governance. Every answer links to the next, so one question leads naturally to the rest.
42 answers · 9 topics
Prefer something shorter? Browse our FAQs or talk to our team.
Browse answers by topic
42 answers
SOC 2 & ISO 27001
7 answersHow much does SOC 2 cost and how long does it take?
How much does SOC 2 cost and how long does it take? Learn the real cost drivers — readiness vs audit fees, scope, Type I vs Type II — and a realistic timeline.
ReadWhat documents and evidence do you need for a SOC 2 audit?
What documents and evidence do you need for a SOC 2 audit? A plain-language checklist of policies, system descriptions, and proof your controls operate.
ReadWhat are the most common gaps found in a SOC 2 readiness assessment?
The most common gaps found in a SOC 2 readiness assessment — missing policies, access controls, evidence, vendor reviews, and monitoring — and how to close them.
ReadCan you get ISO 27001 certified without an internal security team?
Can you get ISO 27001 certified without an internal security team? Yes. Learn what the standard requires, how to fill the gap, and what a vCISO does.
ReadWhat is SOC 2, and does my business need it?
SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.
ReadWhat is the difference between SOC 2 Type I and Type II?
SOC 2 Type I assesses control design at a point in time; Type II tests operating effectiveness over months. Compare the two, plus typical timeline and cost drivers.
ReadSOC 2 vs ISO 27001 — which should we pursue first?
SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.
ReadPrivacy & security assessments
7 answersWhat's involved in a Privacy Impact Assessment: inputs, timeline, and cost?
What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.
ReadWhen should you do a Privacy Impact Assessment in the product development lifecycle?
When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.
ReadDoes a SaaS company need a PIA before selling to healthcare?
Does a SaaS company need a PIA before selling to healthcare? Usually yes - hospitals and clinics typically require one. Here's when, why, and what's involved.
ReadWhat privacy and security assessments are required before selling to government?
What privacy and security assessments are required before selling to government? A plain-language guide to PIAs, TRAs, SOC 2/ISO 27001, and pen tests in Canada.
ReadDo you need a TRA before moving sensitive data to a new cloud provider?
Do you need a TRA before moving sensitive data to a new cloud provider? When it's required, what it covers, and how it differs from a PIA — explained plainly.
ReadHow much does a penetration test cost (and what affects the price)?
How much does a penetration test cost and what affects the price? Understand the scope, depth, and methodology factors that drive pen test pricing in Canada.
ReadPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadCompliance & regulations
6 answersWhat is a HIPAA security risk assessment, and do you need one?
What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it.
ReadWhat is PIPEDA, and does it apply to my business?
What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.
ReadDoes HIPAA apply to my software or business?
HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business.
ReadDoes GDPR apply to my business if we're outside Europe?
The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do.
ReadHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadWhat is a cybersecurity risk assessment, and how often should we do one?
A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.
ReadVirtual Privacy Officer & vCISO
6 answersWhat is a vCISO, and when do you need one?
What is a vCISO, and when do you need one? A vCISO is a part-time, outsourced security leader. Learn what they do and the signs your organization needs one.
ReadHow much does a Virtual Privacy Officer (VPO) cost?
How much does a Virtual Privacy Officer (VPO) cost? Privacy Horizon's VPO starts at CAD $2,200/month. Learn the cost drivers and how to get a tailored quote.
ReadVirtual Privacy Officer vs privacy lawyer: which do you need?
Virtual Privacy Officer vs privacy lawyer: which do you need? Compare what each role does, when to use one or both, and how they work together on compliance.
ReadHow much does a vCISO cost?
How much does a vCISO cost? Learn the pricing models (retainer, project, fractional), what drives the price, and how a virtual CISO compares to a full-time hire.
ReadvCISO vs a managed IT security provider: what's the difference?
vCISO vs a managed IT security provider: a vCISO leads security strategy and owns risk; an MSSP runs tools and monitoring. Learn the difference and which you need.
ReadVPO vs vCISO: do you need one, the other, or both?
VPO vs vCISO: do you need one, the other, or both? Compare what each role owns, where they overlap, and how to decide based on your data, risks, and obligations.
ReadAI privacy & governance
4 answersDo you need an AI policy before employees use ChatGPT?
Do you need an AI policy before employees use ChatGPT? Yes — here's why, what the policy must cover, and how to roll it out without blocking productivity.
ReadWhen do you need an AI Privacy Impact Assessment (AI-PIA)?
When do you need an AI Privacy Impact Assessment (AI-PIA)? The triggers, timing, and how an AI-PIA differs from a standard PIA — explained in plain language.
ReadCan you use AI scribes in healthcare while protecting PHI?
Can you use AI scribes in healthcare while protecting PHI? Yes, with patient consent, vendor due diligence, an AI-PIA, and the right safeguards. Here's how.
ReadDoes a small business need an AI governance framework?
Does a small business need an AI governance framework? Yes if it uses or builds AI. Learn what to put in place, when, and how to keep it proportionate.
ReadCybersecurity basics
4 answersHow can I protect my personal and business information from cyberattacks?
A practical, layered approach to protecting personal and business information from cyberattacks: MFA, patching, backups, training, and a tested incident plan.
ReadHow can I protect my business from ransomware and phishing?
Defend against ransomware and phishing with immutable backups, patching, MFA, email filtering, least privilege, network segmentation, and staff training.
ReadWhat is multi-factor authentication, and do I need it?
Multi-factor authentication (MFA) adds a second proof of identity beyond your password. Learn how it works, the strongest types, and why every business should use it.
ReadWhat's the difference between data privacy and cybersecurity?
Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.
ReadPrivacy breach & incident response
3 answersWhen should you hire a privacy breach response consultant?
When should you hire a privacy breach response consultant? Hire one the moment you suspect a breach, lack in-house expertise, or want a retainer ready first.
ReadDo you need an incident response plan, and what should it include?
Do you need an incident response plan, and what should it include? Yes — here are the six core components every plan needs and why regulators and buyers expect one.
ReadWhat should I do after a data breach?
The steps to take after a data breach: contain it, investigate scope, meet your legal notification obligations (PIPEDA, GDPR, HIPAA), remediate, and document everything.
ReadEnterprise sales & vendor reviews
3 answersHow does a startup pass an enterprise vendor security review?
How does a startup pass an enterprise vendor security review? Map the buyer's requirements, close real gaps, gather evidence, and lead with a SOC 2 or ISO 27001 report.
ReadHow do you prepare for a hospital or healthcare vendor security and privacy review?
How to prepare for a hospital or healthcare vendor security and privacy review: data mapping, PHIPA safeguards, evidence, PIA support, and the documents reviewers expect.
ReadHow do you assess the privacy and security risk of an AI vendor?
How do you assess the privacy and security risk of an AI vendor? A framework covering data use, training, hosting, contracts, and security evidence.
ReadMergers & acquisitions
2 answersWhat is privacy and security due diligence in an acquisition?
What is privacy and security due diligence in an acquisition? It is the review of a target's data practices, compliance, and cyber risk before you buy.
ReadIs a SOC 2 report enough to prove an acquisition target is secure?
Is a SOC 2 report enough to prove an acquisition target is secure? No — here is what a SOC 2 covers, what it misses, and how to fill the gaps in M&A.
ReadWhat's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.