Acquisition-Ready Security, Without the CISO Hire

How Ansel Health, a 50-person insurtech with no internal CISO, achieved enterprise-grade compliance, maintaining clean SOC 2 Type 2 and HIPAA Security Design assessments all the way through acquisition with RISCPoint's embedded vCISO team.

Client:
Ansel Health
INDUSTRY:
Insurtech / Healthtech
FRAMEWORKS:
SOC 2 Type 2 + HIPAA
160
+
SOC 2 evidence and control validation handled, cycle after cycle
0
Exceptions identified across repeated Type 2 audits
16
Security ceremonies conducted and maintained as part of governed compliance calendar
1
Successful exit where Security was a strength, not a diligence blocker

The Challenge

  • A customer-driven SOC 2 deadline and HIPAA obligations landed on a fast-growing company with no formal security leadership.
  • Security maturity was partial and ad-hoc, lacking a repeatable and defensible risk and compliance program.
  • Engineering was absorbing customer security questionnaires and audit evidence requests on top of the product roadmap.
  • Dual-framework complexity and sustainable coordination was required across departments.

The RISCPoint Approach

  • Embedded a dedicated vCISO from week one: a single accountable owner for security, backed by RISCPoint's specialist bench.
  • Ran a security and engineering hygiene gap analysis to baseline against SOC 2, HIPAA, and NIST best practice, prioritizing corrective actions.
  • Operated the program, not just advised: audit evidence, policy refreshes, vendor reviews, customer questionnaires.
  • Deployed a 16-ceremony compliance calendar that enhanced audit-readiness to an ongoing state, not a scramble.
ansel health logo
Ansel HEALTH

"RISCPoint has been a pillar of our cybersecurity posture. Their team is highly responsive and took charge in leading our security initiatives, enabling us to focus on our core business operations."

Justin Johnson
VP, Engineering, Ansel Health

Inside the Engagement

Enterprise-grade security. 50 employees. Zero dedicated security hires. Here’s how.

WHAT THE vCISO TEAM OWNED

Audit defense, end to end

Readiness analysis, prep, and fieldwork support to a successful final report. Evidence gathering and review provided by RISCPoint, not your engineering team.

The policy program

Enterprise InfoSec policies reviewed, remediated, and refreshed annually, expanded to changing HIPAA regulation and PCI as the business grew.

The human layer

KnowBe4 security awareness training and monthly phishing simulations, driven to zero clicks company-wide.

Annual pen-test cadence

Application, network, enterprise, and dedicated environment penetration testing every year of the engagement: 2024, 2025, and 2026.

FOUR WORKSTREAMS FROM MONTH ONE

Security Advisory

Senior GRC leadership from Big 4 alumni, military cyber professionals, and CPA-licensed advisors.

Security Champion

Embedded across teams to build awareness and accountability, from engineering to leadership.

Strategy & Roadmapping

Business priorities translated into sequenced initiatives with clear ownership and milestones.

Security Governance

The policies, controls, and oversight that form the foundation of an audit-ready program.

THE OUTCOME

A security program that survived due diligence

When Renaissance Life & Health acquired Ansel Health, the program RISCPoint built and operated held up under buyer scrutiny: repeated clean SOC 2 Type 2 reports, a live HIPAA program, and a running compliance calendar that continues through 2026.

Why teams pick RISCPoint

Embedded leadership

A dedicated vCISO and delivery team inside your business, live in week one, not after a 6-month search.

Operators, not advisors

We run audit submissions, after-action reviews, and the questionnaires stalling your deals.

Audit-ready by design

A compliance calendar scoped to your frameworks spreads the work across the year. No scrambles.

Credentialed to the core

CPA-licensed advisory firm and accredited FedRAMP & GovRAMP 3PAO, with Big 4 and military cyber alumni.

Book a 30-minute VCISO scoping call

Engagements are scoped and flexible to your program's maturity, size, and objectives. We'll give you a clear picture in the first conversation.

Book a scoping call

Stay Informed, Stay Secure

Subscribe to our newsletter and get the latest cybersecurity insights, updates, and event invitations delivered straight to your inbox. Join our community and empower your security journey with RISCPoint's expert knowledge.

Thank you! We'll keep you up to date!
Oops! Something went wrong while submitting the form.

Join our newsletter for updates. Terms.