Compliance has to survive real scrutiny. Controls, evidence, ownership, and remediation should make sense to the people operating the environment and the people examining it.

Cybersecurity Audits Built for Regulatory Scrutiny.

TorchLight helps regulated organizations assess cybersecurity risk, validate controls, map evidence to the requirements they answer to, and turn findings into prioritized remediation. The result is clearer risk, defensible documentation, and a compliance program leadership can stand behind.

NIST CSF 2.0 GLBA NCUA HIPAA SEC Reg S-P ISO 27001

Why TorchLight for Compliance.

Compliance gets more useful when the people assessing the environment understand both sides of the equation: how technology and cybersecurity controls actually operate, and how risk, governance, evidence, and accountability are evaluated under scrutiny.

TorchLight was built around environments where IT, cybersecurity, risk, and regulation cannot be separated.

That perspective runs deeper than a framework mapping exercise. It influences how we evaluate controls, document evidence, communicate risk to leadership, prioritize remediation, and determine whether the organization can defend the decisions it has made.

Nolan Garrett

Founder & CEO · TorchLight Secured & Managed IT
Nolan Garrett, Founder and CEO of TorchLight

Nolan has spent more than two decades working across technology, cybersecurity, business risk, regulation, compliance, strategy, and executive leadership. His experience as an IT regulatory examiner gives TorchLight something unusually valuable: first-hand perspective on how an organization looks from the other side of the examination table.

Former IT Regulatory Examiner Direct experience with how risk, governance, controls, evidence, and technology decisions are evaluated.
Security-Focused Education Eastern Washington University studies emphasizing information warfare, network security, and network design.
Founder Since 2007 Built TorchLight around regulated organizations where technical outcomes, risk management, and defensible evidence have to work together.

Gary Blosser

Executive Consultant & Principal Security Architect · TorchLight
Gary Blosser, Executive Consultant and Principal Security Architect at TorchLight

Gary brings the complementary side of defensible compliance: deep technical security experience combined with executive security leadership. His background spans CISO and vCISO-level responsibilities, architecture, penetration testing, offensive security, incident response, digital forensics, threat intelligence, and complex enterprise environments.

Carnegie Mellon Master of Science in Information Technology – Information Security, combining security technology, management, and policy.
CISO-Level Leadership Executive security leadership across large government and higher-education environments, including complex programs spanning more than 100 academic entities.
Technical Validation Experience in penetration testing, red-team operations, vulnerability assessment, incident response, forensics, and security architecture.

Compliance should connect the boardroom to the environment. TorchLight brings regulatory perspective, executive security leadership, and technical depth together so findings can become decisions, remediation, and evidence that holds up later.

Why Organizations Choose TorchLight

What We Assess Before It Becomes a Finding.

A cybersecurity assessment should do more than identify missing controls. TorchLight looks at how security actually operates: what is in place, whether it works, who owns it, how it is documented, and whether the evidence tells the same story as the environment.

That matters in regulated organizations because technical risk and compliance risk rarely stay separate for long. A weak control can become an operational problem, an audit exception, an insurance issue, or a question the board has to answer.

The goal is not to create a longer findings list. It is to identify the gaps that matter, establish the evidence behind them, and make the next decision clearer.

The assessment follows the risk, not just the checklist.

Scope is tailored to the organization, its regulatory obligations, its technology, and the questions leadership needs answered.

01

Security Risk Assessment

Evaluate threats, vulnerabilities, safeguards, likelihood, and business impact against the requirements and risk profile of the organization.

02

Compliance Gap Analysis

Compare current controls and practices against applicable framework or regulatory requirements to identify what is satisfied, partially met, or still open.

03

Control Effectiveness

Determine whether controls operate as intended in practice, not merely whether a policy, tool, or configuration exists on paper.

04

Audit Readiness & Evidence

Review documentation, control mapping, evidence collection, ownership, and reporting so the organization can answer questions consistently when scrutiny arrives.

05

Ransomware Readiness

Examine prevention, detection, response, backup, recovery, and resilience to identify gaps that could materially change the outcome of a ransomware event.

06

Technical Validation

Where appropriate, use vulnerability assessment and penetration testing to validate whether weaknesses are actually exploitable and how an attacker could move through the environment.

Compliance Does Not Start With the Framework.

Frameworks give the assessment structure. They do not replace judgment. TorchLight starts with the organization, its regulatory obligations, its actual technology, and the risks leadership is accountable for managing.

The result is a control and evidence model tied to the requirements that matter without losing sight of how those controls have to operate in the real environment.

Credit Unions & Financial Institutions

Security governance, risk assessment, access controls, vendor oversight, incident readiness, evidence, and board accountability all have to work together in a regulated financial environment.

NCUA GLBA FTC Safeguards NIST CSF 2.0

Wealth Management & Investment Firms

Information protection, incident response, third-party oversight, access governance, and documented accountability increasingly sit alongside the traditional cybersecurity program.

SEC Regulation S-P GLBA NIST CSF 2.0

Healthcare & Life Sciences

Protecting sensitive health information requires more than policy language. Risk analysis, technical safeguards, access controls, resilience, documentation, and response planning all have to tell the same story.

HIPAA Security Rule NIST Risk Analysis

Education & Public-Sector Environments

Distributed systems, identity sprawl, sensitive student and institutional data, constrained resources, and public accountability make cybersecurity readiness a governance issue as much as a technical one.

FERPA NIST CSF 2.0 State Requirements

Enterprise Security Programs

Where a specific regulator is not driving the program, TorchLight can map controls and evidence to recognized security frameworks to establish a defensible baseline and measurable maturity.

NIST CSF 2.0 ISO 27001 Control Maturity

Cyber Insurance & Third-Party Scrutiny

Regulators are not the only parties asking for evidence. Insurers, clients, boards, vendors, and business partners increasingly expect organizations to demonstrate that security controls actually exist and operate.

Evidence Control Validation Risk Documentation

Findings Matter When Someone Owns What Happens Next.

An audit can identify risk. It cannot reduce that risk by itself. TorchLight can carry the work from assessment through remediation, operations, security monitoring, executive oversight, and ongoing validation so compliance becomes part of how the environment is managed instead of a recurring fire drill.

Understand the Finding.

Establish what was observed, which controls or requirements are affected, what evidence supports the conclusion, and how the weakness changes business or regulatory risk.

Clarify

Remediate the Risk.

Assign ownership, prioritize the work, change configurations, improve processes, address technical weaknesses, and document the actions taken instead of leaving the finding in a spreadsheet.

Remediate

Operate & Prove.

Keep the control working, monitor what matters, preserve evidence, validate remediation, and give leadership a clearer record of how identified risk is being managed over time.

Sustain

The goal is an operating state, not an audit event.

For regulated organizations, the strongest compliance position is usually the one that can be demonstrated continuously: controls are owned, systems are managed, security is monitored, findings are remediated, and evidence already exists when the next examiner, auditor, insurer, client, or board member asks for it.

2007 Today

Trust Is Built Before the Audit Ends.

In 2007, PrimeSource Credit Union came to TorchLight for a security assessment and gap analysis. The engagement started with a straightforward question: where were the risks, and what needed to change?

That initial assessment became the beginning of a long-term strategic technology and cybersecurity relationship spanning compliance, operations, security, and planning. It is a good example of what TorchLight believes assessment work should accomplish: create clarity, earn trust, and lead to better decisions long after the report is delivered.

2007 Security assessment and gap analysis became the starting point for an enduring technology and cybersecurity partnership.
TorchLight has been more than a vendor to our multi-branch credit union; they’re a partner. We started with a security assessment and gap analysis in 2007 and have continued to grow with their guidance across strategy, compliance, and operations.
Annettee Babb CEO · PrimeSource Credit Union
More About TorchLight

Let’s Make the Next Audit Easier.

Whether you need a formal cybersecurity risk assessment, a compliance gap analysis before an examination, help closing existing findings, or simply a clearer picture of where your program stands, start with the problem. TorchLight will help determine the right next step.

Start With
The Risk, Finding, or Requirement
Next Step
A Real Conversation

Start the Conversation

Give us a little context about the audit, assessment, regulatory requirement, or finding you’re working through. We’ll connect you with the right person at TorchLight.

Name