| 1 minute read

Avalon Achieves SOC 2 Type 1 Compliance

compliance graphic

Avalon is proud to announce that we have successfully completed the SOC 2 Type 1 information security audit as of July 2021. The scope of the audit included our cybersecurity, eDiscovery, and secure print and mail services.

A system and organization controls (SOC) 2 report is administered by an independent accounting and auditing firm and is based on the AICPA’s Trust Services Criteria. The resulting report verifies whether a third-party service provider that holds, stores, and/or processes private data – such as Avalon – complies with a variety of requirements, including security and availability. In short, it indicates that a vendor is a trustworthy partner with rigorous policies and procedures in place.

SOC 2 Logo 21972-312_SOC_NonCPAThere are two types of audits, SOC 2 Type 1, which assesses the design of security processes at a specific point in time, and SOC 2 Type 2, which evaluates how effective security processes are by observing a company’s operations over a period of time. Avalon is currently preparing for a SOC 2 Type 2 audit.

While Avalon has been a trusted vendor to tens of thousands of clients since 2000, achieving SOC 2 Type 1 compliance is a significant achievement that demonstrates our dedication to the highest standards of security and service.

“Avalon has always made the confidentiality, integrity, and availability of our systems and client data a paramount priority for our entire team,” says Kyle Cavalieri, president of Avalon Cyber. “Every day, we work hard building and maintaining resilient systems and applications that allow us to provide the very best professional service possible for our clients. We are proud to have completed the SOC 2 audit to validate that our company’s policies, procedures, and technical controls meet the expectations of the relevant trust principles."

Contact our team if you need assistance or have any questions about our cybersecurity services.

Blog Articles

The CDK Incident and Recommended Actions from Avalon Cyber

Thousands of car dealerships’ operations slowed to a halt last Wednesday as their core dealer management system, CDK, shut down. CDK Global announced that they were investigating a cyber incident and “Out of an abundance of caution and concern for our customers, we have shut down most of our systems and are working diligently to get everything up and running as quickly as possible” according to spokesperson, Lisa Finney. The company said later that day that most of their critical systems were back online, but the next day they announced that another incident had happened.

Get Ready for the New 36-Hour Cyber Breach Notification Rule for Financial Institutions

If you’re in the financial sector, no doubt you’ve already heard, and hopefully, are prepared or preparing for, the new federal banking rule regarding cyber breach notifications. This new rule, which took effect April 1, 2022, with full compliance required by May 1, 2022, requires banking organizations and bank service providers to notify banking regulators within 36 hours after a notification event, which is the tightest timeframe in U.S. history.

Cybercriminals Never Sleep (And Neither Do We)

According to the latest cybersecurity industry research, market demand for Managed Detection and Response (MDR) services continues to climb. In fact, experts forecast that by 2024, 40% of midsize enterprises will use MDR as their only managed security service. That might sound like a large percentage, but because of the continued escalation of cyberattacks, more and more companies are realizing the importance of hiring experts to boost their cybersecurity posture.