Skip to content

Ignoring It Doesn’t Help Anyone: What Happens When Cybersecurity Compliance Gets Left on the Shelf

At industry conferences this year, SmartVault's CISO Luke Kiely talked with hundreds of tax professionals and found something surprising: roughly half had never heard of the compliance rules they were required to follow. The other half knew the rules existed but weren't sure where to start. Both groups ended up in the same place: nothing got done.
Published: October 8, 2026

Compliance wasn’t going away just because firms would rather not think about it.

In this session, Luke, a former cybercrime investigator, talked through what the laws require, what insurance companies look for after a breach, and how strong cybersecurity practices naturally produce the compliance firms need, instead of the other way around. Attendees walked away with a clear, practical picture of what compliance looks like, and how to get there.

Key Takeaways:

  • Why so many firms are stuck at square one — some don’t know these requirements exist, others know but don’t know where to begin.
  • Why insurers treat a compliance “plan” and a compliance “program” very differently — and what separates the two in practice.
  • What’s required, explained in plain language — the practical steps that matter.
  • Why cybersecurity became table stakes, and where it still earns you trust — it’s no longer a selling point on its own, but it’s what clients (and insurers) look for the moment something goes wrong.