---
title: Cybersecurity, HIPAA & AI Risk Assessments | InformaStorm
description: Executive-ready technology, cybersecurity, HIPAA, AI, and SOC 2 readiness risk assessments for mid-size companies. Led by Solomon Smith, CISSP.
---

[Skip to content](https://informastorm.com/technology-security-ai-risk-assessments#main-content)

[![](https://informastorm.com/hs-fs/hubfs/brandmark-design.png?width=3000&height=250&name=brandmark-design.png)](https://informastorm.com/?hsLang=en)

- [Services](https://informastorm.com/en-us/services)
- [Fractional CISO & CTO](https://informastorm.com/security-data-technology-strategy)
- [AI Governance](https://informastorm.com/data-privacy-ai-governance)
- [Risk Assessments](https://informastorm.com/technology-security-ai-risk-assessments)
- [About](https://informastorm.com/about)

Open main navigation

Close main navigation

- [Services](https://informastorm.com/en-us/services)
- [Fractional CISO & CTO](https://informastorm.com/security-data-technology-strategy)
- [AI Governance](https://informastorm.com/data-privacy-ai-governance)
- [Risk Assessments](https://informastorm.com/technology-security-ai-risk-assessments)
- [About](https://informastorm.com/about)
- [Start a conversation](https://informastorm.com/start-a-conversation)

[Start a conversation](https://informastorm.com/start-a-conversation?hsLang=en)

# Clear, defensible insight into technology, security, and AI risk.

## Structured risk assessments that help leadership understand exposure, prioritize action, and make informed decisions — without fear, guesswork, or unnecessary complexity.

## Technology, Security & AI Risk Assessments

InformaStorm conducts technology, cybersecurity, data, and AI risk assessments for mid-size companies, including HIPAA security risk analysis and SOC 2 readiness assessments. Each assessment is led directly by Solomon Smith (CISSP, ISO 27001, HITRUST CCSFP) and delivers a prioritized, executive-ready view of material risk: what could go wrong, why it matters to the business, and what to do about it. Rather than relying on generic checklists, assessments are grounded in your organization's goals, constraints, maturity, and risk tolerance. Frameworks such as NIST CSF, the NIST AI RMF, ISO 27001, and SOC 2 are used where they help, always in service of clear decisions leaders can stand behind.

![Leadership team reviewing risk assessment findings](https://informastorm.com/hubfs/team%20of%20successful%20business%20people%20having%20a%20meeting%20in%20executive%20sunlit%20office-1.jpeg "Leadership team reviewing risk assessment findings")

### Why risk assessments matter

Risk assessments are often treated as compliance exercises or technical checklists. When done that way, they create reports — not clarity.

This work is different.  
The purpose is to help leaders understand what could go wrong, why it matters, and what to do about it, in language that supports real decisions.

Risk assessments should reduce uncertainty — not add to it.

![Analyst explaining technology risk findings to a colleague](https://informastorm.com/hubfs/Proficient%20young%20male%20employee%20with%20eyeglasses%20and%20checkered%20shirt%2c%20explaining%20a%20business%20analysis%20displayed%20on%20the%20monitor%20of%20a%20desktop%20PC%20to%20his%20female%20colleague%2c%20in%20the%20interior%20of%20a%20modern%20office.jpeg "Analyst explaining technology risk findings to a colleague")

### What these assessments cover

Depending on your environment and concerns, assessments may include:

- Technology and infrastructure risk
- Security and cyber risk
- HIPAA security risk analysis
- Data protection and privacy risk
- AI usage, model risk, and governance gaps
- Third-party and vendor risk
- SOC 2 readiness and Trust Services Criteria alignment
- Organizational and decision-making risk

The scope is tailored to what leadership actually needs to understand, not a one-size-fits-all checklist.

![Presenting risk assessment results to leadership](https://informastorm.com/hubfs/Colleagues%20asking%20a%20question%20to%20a%20businesswoman%20during%20a%20presentation.jpeg "Presenting risk assessment results to leadership")

### The assessment process

While every engagement is customized, the assessment process typically follows a clear structure:

1. **Context and objectives**  
   Understanding the organization, its goals, constraints, and risk tolerance.
2. **Risk identification**  
   Identifying material risks across technology, security, data, and AI — including risks that are often overlooked or misunderstood.
3. **Risk analysis and prioritization**  
   Evaluating likelihood, impact, and business relevance — not just technical severity.
4. **Framework alignment**  
   Mapping risks to appropriate standards or frameworks where useful, without forcing unnecessary complexity.
5. **Findings and decision support**  
   Translating results into clear, leadership-level insight and options.

![Security framework documentation and binders](https://informastorm.com/hubfs/Midsection%20of%20businesswoman%20with%20binders%20at%20office.jpeg "Security framework documentation and binders")

### Frameworks — used intentionally

Frameworks can be valuable tools when applied thoughtfully and in context.

Depending on the situation, assessments may reference or align with:

- NIST Cybersecurity Framework (CSF)
- NIST AI Risk Management Framework (AI RMF)
- ISO/IEC 27001 and related standards
- SOC 2 Trust Services Criteria
- Privacy and regulatory requirements where applicable

Frameworks are used to support understanding, prioritization, and defensibility — not to overwhelm teams or “check boxes.”

![SOC 2 audit readiness preparation](https://informastorm.com/hubfs/Green%20Office%20Folder%20with%20Inscription%20Audit%20on%20Office%20Desktop%20with%20Office%20Supplies%20and%20Modern%20Laptop.%20Audit%20Business%20Concept%20on%20Blurred%20Background.%20Audit%20-%20Toned%20Image.%203D.jpeg "SOC 2 audit readiness preparation")

### SOC 2 readiness and preparation

For organizations pursuing SOC 2, risk assessments often serve as the foundation for readiness.

This work helps leadership teams:

- Understand how SOC 2 expectations map to real operational risk
- Identify gaps across people, process, and technology
- Prioritize remediation efforts based on impact and feasibility
- Avoid over-engineering controls that don’t meaningfully reduce risk
- Establish governance and ownership that auditors expect to see

The focus is on preparation and decision support — helping organizations enter the SOC 2 process with clarity, confidence, and realistic expectations.

This work is independent of any audit firm and does not replace a formal SOC 2 examination.

![Team aligned on prioritized risk decisions](https://informastorm.com/hubfs/Group%20of%20happy%20young%20%20business%20people%20in%20a%20meeting%20at%20office.jpeg "Team aligned on prioritized risk decisions")

### Outcomes leaders care about

A successful assessment does not end with a technical report. Leaders walk away with:

- A clear view of material technology, security, and AI risk
- Prioritized issues that matter to the business
- Practical options for addressing risk, with the trade-offs explained
- Shared understanding across leadership and technical teams
- Clear direction entering SOC 2 readiness or examination efforts
- The ability to explain decisions to boards, customers, and regulators

The goal is informed action, not perfect scores.

### Frequently asked questions

**How long does a risk assessment take?**  
Most assessments for mid-size companies take a few weeks, depending on scope, the number of systems and locations, and how quickly information is available.

**Is this the same as a penetration test?**  
No. A penetration test probes systems for technical weaknesses. A risk assessment looks at the whole picture, including people, process, vendors, data, and AI use, and tells leadership what matters most.

**Does HIPAA require a risk assessment?**  
Yes. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough risk analysis and to keep it current.

**Do you perform the SOC 2 audit?**  
No. SOC 2 examinations are performed by independent CPA firms. We prepare you for the audit and help you build a program that holds up after it.

Related: [Fractional CISO & CTO](https://informastorm.com/security-data-technology-strategy?hsLang=en) · [AI Governance](https://informastorm.com/data-privacy-ai-governance?hsLang=en) · [About InformaStorm](https://informastorm.com/about?hsLang=en) · [Start a Conversation](https://informastorm.com/start-a-conversation?hsLang=en)

![Executives discussing risk assessment scope](https://informastorm.com/hubfs/Employees%20having%20a%20business%20meeting%20in%20a%20conference%20room.jpeg "Executives discussing risk assessment scope")

### What this is — and what it isn’t

**This is:**

- A structured, leadership-focused risk assessment
- Grounded in real-world experience
- Designed to support executive and board decisions
- A strong foundation for SOC 2 readiness and governance maturity

**This is not:**

- A penetration test
- A vendor-driven maturity scorecard
- A fear-based audit exercise
- A compliance-only report

![brandmark-design](https://informastorm.com/hubfs/brandmark-design.png "brandmark-design")

Supporting executive teams and boards with clear, business-focused risk guidance.

[![\<p\>Start a conversation\</p\>](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/47398377/interactive-292035561150.png)](https://informastorm.com/hs/cta/wi/redirect?encryptedPayload=AVxigLJVstZz5qSFXN0WXK8MRkw789T02aBv8udLvuCAuJpoAWRFpF0pyj%2BtAikmAbmAzfDdaClpsjqugMfQ9Vj0eA1hsG2uJ%2BO2uEA0tuVt3nsE62scHS1bZhR7wCL9OLYzMPe7fOlHLDXI9MSFSmY5htf9XLk8cyr3qBsZADuWX%2FuL2%2FrWGkVDTPB3UEARRdBMxnnjmVA0EBRH0twjp63xYZMUzhaB&webInteractiveContentId=292035561150&portalId=47398377&hsLang=en)

###### Initial conversations are exploratory and focused on understanding your situation.

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://informastorm.com/technology-security-ai-risk-assessments#service",
  "@type" : "Service",
  "areaServed" : [ {
    "@type" : "State",
    "name" : "Iowa"
  }, {
    "@type" : "Country",
    "name" : "United States"
  } ],
  "description" : "Executive-ready technology, cybersecurity, data, AI, HIPAA, and SOC 2 readiness risk assessments for mid-size companies, using NIST CSF, NIST AI RMF, ISO 27001, and SOC 2 where they help.",
  "name" : "Technology, Security & AI Risk Assessments",
  "provider" : {
    "@id" : "https://informastorm.com/#org",
    "@type" : "ProfessionalService",
    "name" : "InformaStorm LLC",
    "url" : "https://informastorm.com/"
  },
  "serviceType" : [ "Cybersecurity risk assessment", "HIPAA security risk analysis", "AI risk assessment", "SOC 2 readiness assessment" ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Most assessments for mid-size companies take a few weeks, depending on scope, the number of systems and locations, and how quickly information is available."
    },
    "name" : "How long does a risk assessment take?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. A penetration test probes systems for technical weaknesses. A risk assessment looks at the whole picture, including people, process, vendors, data, and AI use, and tells leadership what matters most."
    },
    "name" : "Is this the same as a penetration test?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough risk analysis and to keep it current."
    },
    "name" : "Does HIPAA require a risk assessment?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. SOC 2 examinations are performed by independent CPA firms. We prepare you for the audit and help you build a program that holds up after it."
    },
    "name" : "Do you perform the SOC 2 audit?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://informastorm.com/",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://informastorm.com/en-us/services",
    "name" : "Services",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "item" : "https://informastorm.com/technology-security-ai-risk-assessments",
    "name" : "Risk Assessments",
    "position" : 3
  } ]
}
```