David Zetoony, Chair of Bryan Cave LLPs data privacy and security team, and Art Ehuan, Managing Director of A&Ms Global Cyber Risk Services practice, discuss various methods for auditing an organization's compliance with the data security laws. Additionally, they discuss the use of the NIST CyberSecurity Framework (CSF) to define the cyber risk profile of a company and how to minimize the identified risk throughout the organization.