Arkadian protects sensitive data from leaks, theft and unauthorised access — and keeps you
compliant with the NY SHIELD Act, HIPAA, PCI-DSS and CMMC.
Most of this work is documentation, evidence and honest gap analysis. Very little of it is
buying products, whatever anyone selling products tells you.
If you hold patient records, card data, or personal information about New York residents,
you are required to protect it and to be able to show that you do. The names differ by
industry; the obligation does not.
NY SHIELD Act
Any business holding private information about New York residents
Requires reasonable administrative, technical and physical safeguards — a security programme, not a published policy. Small businesses are held to a standard proportionate to their size and to the sensitivity of what they hold. Failures are treated as deceptive business practices, with civil penalties per violation.
PCI-DSS
Any business that accepts card payments
Requires specific controls around cardholder data. Falling short can mean fines, raised transaction fees, and in the worst case losing the ability to take card payments at all — which for most retailers is the penalty that actually matters.
HIPAA
Healthcare providers and their business associates
Requires defined security controls around patient health information, plus the documentation to show they are in place. Annual penalty caps run into seven figures per violation category and are adjusted each year, with criminal liability possible in the worst cases.
CMMC
Businesses in the defense supply chain
Required to hold or win Department of Defense contracts. Level 1 is achievable for a small business without rebuilding everything — the hard part is usually working out which level actually applies to you before spending anything.
Penalty figures are adjusted over time and the detail depends on your circumstances. We can
tell you what the requirements mean technically; what they mean legally for your business is
a question for an attorney, and we will say so rather than guess.
The work
How Arkadian Protects Your Data
01
Compliance assessment — we find out where you stand
We assess your current situation against the requirements that genuinely apply. Most businesses find gaps they did not know about, and a few find they are closer than they feared. You get a plain-English picture of what is missing and what closing it involves.
02
Data loss prevention — stopping leaks before they happen
Monitoring and controlling how sensitive information moves through the organisation: controls against unauthorised sharing, accidental exposure and deliberate exfiltration.
03
Encryption and secure storage — at rest and in transit
Encryption means that intercepted or stolen data cannot be read without the key. We cover stored data, email and data in transit — the scenarios most likely to turn into a reportable breach.
04
Monitoring and audit logging — proving it over time
Compliance is a state, not an event. Monitoring tracks access to sensitive data, flags anomalies and maintains the audit records regulators and insurers ask for as evidence of due diligence.
Is Your Business Required to Comply?
These obligations reach further than most owners expect. If your sector is here, at least
one of them almost certainly applies to you.
PCI-DSS, protection of financial records and client data
Financial services and accounting firms
PCI-DSS for card payments, protection of customer data
Retailers and e-commerce
CMMC, handling of controlled unclassified information
Defense supply chain
NY SHIELD Act
Any NYC business holding data on New York residents
Why Businesses Choose Arkadian for Data Protection
We speak compliance in plain English
These frameworks are written in language that paralyses a business owner. We translate
them into actions: what you need, why you need it, and what order to do it in.
We make your position defensible, not just protected
If a breach happens despite precautions, documentation is often what separates a
manageable situation from a catastrophic one. Monitoring and audit records give you
evidence of due diligence to show regulators and insurers.
We tell you what you don't need
Compliance is a market full of expensive answers to questions nobody asked. A large part
of the assessment is establishing which requirements genuinely apply at your size — and
which are being sold to you.
What We Won't Promise You
Compliance is sold with more certainty than it can carry. Here is where the line sits.
That we can give you a legal opinion
We are security practitioners, not attorneys. We can tell you what a requirement means
technically and what implementing it involves. Whether your specific obligations are met
is a legal determination, and it belongs to your counsel.
That compliance prevents breaches
It reduces the likelihood and limits the damage. Its other function is to put you in a
defensible position afterwards, which is worth having but is not the same as prevention.
That we issue certifications
Formal certification and audit are carried out by accredited assessors. We prepare you
for that process and close the gaps beforehand, which is the part where the work
actually is.
That it is finished when the project is
Compliance is a state that decays. Staff change, systems change, requirements change.
Anyone presenting this as a one-off purchase is describing the sale, not the obligation.
Find Out What Actually Applies to You.
Tell us what your business does, roughly how many people you have, and what kind of data
you hold. That is usually enough for a straight answer about which requirements are in
scope — and often the list is shorter than you were told.