⚡ Limited Availability — Accepting 3–4 New Clients This Quarter  |  Schedule Your Free Risk Review →

Research & Publications

Thought Leadership &
Original Research

Peer-reviewed articles, applied research, and substantive analysis across IT leadership, cybersecurity governance, and human performance — by Wlad Pierre-François, Ph.D.

01
Leadership & Human Development  ·  Theoretical Review

Toward an Integrated Architecture of Human Greatness

A rigorous cross-framework synthesis of seven foundational models on human flourishing, effectiveness, and meaning — proposing the IAHG, a five-layer integrative model.

March 2025∼8,200 words18 references
02
Cybersecurity  ·  Compliance  ·  Healthcare IT

HIPAA Security Rule Compliance in Small Medical Practices: A Risk-Based Framework

A theoretical synthesis advancing the Integrated Risk-Behavioral Compliance Framework (IRBCF) — mapping HIPAA Security Rule modernization requirements to organizational capacity variables in resource-constrained small practice environments. Addresses the 2024–2025 HHS proposed rulemaking.

April 2026∼7,400 wordsIRBCF FrameworkPeer-reviewed synthesis
03
IT Leadership  ·  Governance  ·  Professional Development

The CISO-Ready IT Director: Positioning Technical Leadership for the Governance Era

How IT leadership must evolve from operations management to security governance. Examines the 2023–2025 regulatory convergence, the five-dimension competency delta separating operational from governance posture, credential pathways and their actual signaling value, and the translation problem at board level.

July 2026∼3,300 words7 referencesPractitioner analysis
04
Healthcare IT  ·  AI Governance  ·  HIPAA

Governing Shadow AI in Clinical Environments: A Pre-Deployment Control Framework

Clinical staff are adopting AI faster than practices are governing it. Locates the exposure within existing HIPAA obligations rather than anticipated AI regulation, maps it to the NIST AI Risk Management Framework, and specifies a six-step control sequence for practices without dedicated compliance staff.

June 2026∼2,400 words7 referencesNIST AI RMF
05
Regulatory Compliance  ·  Risk  ·  Small Firms

The Compliance Convergence Problem: Enterprise Obligations at Small-Firm Scale

Five independent regulatory regimes — HIPAA, the FTC Safeguards Rule, SEC Regulation S-P, New York’s SHIELD Act and Part 500 — have converged on the same nine controls. Argues that small firms should build one program mapped to a neutral framework, and that the binding constraint is the decision record rather than budget.

May 2026∼2,100 words9 referencesComparative analysis
06
Regulatory Compliance  ·  Financial Services  ·  New York

NYDFS 23 NYCRR 500 Second Amendment: What Covered Entities Must Implement

A practitioner walkthrough of the Second Amendment to New York’s cybersecurity regulation — expanded governance obligations, MFA requirements, asset inventory mandates, and the phased compliance deadlines covered entities are measured against.

Practitioner analysisFinancial services
07
Cybersecurity  ·  Legal  ·  Microsoft 365

Microsoft 365 Security Hardening for Law Firms

The configuration gap between a default Microsoft 365 tenant and one that actually satisfies client-confidentiality obligations under NY Rules of Professional Conduct Rule 1.6 — covering conditional access, retention, audit logging, and the settings most firms never change.

Practitioner analysisLegal sector
08
Cyber Insurance  ·  Risk  ·  Small Business

Cyber Insurance Requirements for NYC Small Businesses

What underwriters now require before binding a policy, why attestations are being verified at claim time rather than at application, and the controls a small NY business needs in place to remain insurable at a defensible premium.

Practitioner analysisSmall business

Get new research in your inbox

Occasional, substantive updates when new work is published — no marketing filler. Unsubscribe anytime.

Stay Updated →
Is your NYC business protected? Get a free IT Risk Assessment — written report within 24 hours.