Reefscan is a free tool from Lionfish Cyber Security — Empower. Lead. Defend.
Reefscanby Lionfish
Honest Compliance Crosswalk

What Reefscan does — and what it doesn't.

Most "compliance tools" oversell. We won't. Below is exactly which controls Reefscan supports across 16 mapped controls in 16 frameworks — including the honest limitations your auditor will absolutely ask about.

Privacy & Data-Subject Rights

GDPR, CCPA, and state-level deletion laws

GDPRArt. 17

Right to Erasure ("Right to be Forgotten")

Supports:

Operationalizes the data-subject right by automating broker opt-out workflows and tracking removal status as audit evidence.

Doesn't:

Does not prove broker compliance. Does not satisfy a controller's own erasure obligations toward its data subjects.

broker erase
GDPRArt. 32

Security of Processing

Supports:

Credential-exposure monitoring (HIBP) supports the obligation to detect known compromise of personal data.

Doesn't:

Not a substitute for technical & organizational measures (TOMs) on the controller's own systems.

breach checkpassword check
CCPA§ 1798.105

Right to Delete Personal Information

Supports:

Helps consumers exercise the right against data brokers, with timestamped opt-out evidence.

Doesn't:

Does not satisfy a business's own duty to honor consumer deletion requests it receives.

broker erase
SB 362DROP

Data Broker Single-Mechanism Deletion

Supports:

Educates clients on the broker ecosystem and provides interim deletion tracking ahead of DROP go-live.

Doesn't:

Once DROP is operational, CA residents will use the official CPPA mechanism. Reefscan complements, does not replace.

broker erase

Security & Awareness Frameworks

NIST CSF, NIST 800-53, SOC 2, ISO 27001

CSFID.RA

Risk Assessment

Supports:

Surfaces credential-exposure threat data that feeds enterprise risk register & threat-model inputs.

Doesn't:

One-shot scans are not a substitute for continuous threat-intelligence feeds.

breach checkcontinuous monitoring
CSFPR.AT

Awareness & Training

Supports:

Personal, visceral exposure reports drive workforce security awareness — far more effective than slides.

Doesn't:

Not a formal LMS. Should accompany, not replace, structured awareness programs.

breach checkpassword check
800-53AT-2

Literacy Training & Awareness

Supports:

Quarterly exposure scans on workforce email domains produce evidence of ongoing awareness activities.

Doesn't:

Must be paired with documented training records to satisfy auditor requirements.

breach checkcontinuous monitoring
800-53IR-4

Incident Handling

Supports:

Breach hits can trigger IR procedures — flagged credentials feed incident workflows.

Doesn't:

No SIEM integration, no chain-of-custody preservation, not a full IR platform.

breach check
SOC 2CC7.3

Security Event Monitoring

Supports:

Credential breach monitoring referenced in service-organization narratives as supporting control.

Doesn't:

Not a standalone SOC 2 control. Must be wrapped in documented procedures.

breach checkcontinuous monitoring
ISOA.6.3

Information Security Awareness

Supports:

Personal exposure scans feed awareness program effectiveness metrics.

Doesn't:

Must be paired with documented training & assessment records.

breach checkpassword check

Sector & Regulator-Specific

HIPAA, PCI-DSS, NYDFS, SEC, Executive Privacy laws

HIPAA§ 164.308(a)(6)

Security Incident Procedures

Supports:

Detects exposed credentials of workforce members handling ePHI.

Doesn't:

Not BAA-eligible by default. Do not feed actual ePHI into the tool.

breach check
PCI8.3.7

Authentication Requirements — Password Policy

Supports:

k-anonymity password check flags credentials known to be in breach corpora — supports "compromised passwords" policy.

Doesn't:

Not a substitute for an enterprise password manager or IAM control.

password check
NYDFS§ 500.14

Cybersecurity Awareness Training

Supports:

Exec/employee breach exposure reports operationalize awareness for covered entities.

Doesn't:

Not a substitute for written awareness program documentation.

breach checkpassword check
NYDFS§ 500.11

Third-Party Service Provider Security Policy

Supports:

Domain-level breach checks across vendor lists provide TPRM evidence.

Doesn't:

Does not perform full vendor assessments — supplements them.

breach check
EXECState Statutes

Executive / Public-Official Data Removal

Supports:

Operationalizes broker removal for protected persons (judges, LEO, healthcare workers) in NJ, FL, TX, and ~15 other states.

Doesn't:

State programs (e.g., NJ OIPP) are the authoritative channel; Reefscan handles non-program brokers.

broker erase
SECItem 106 / 1.05

Material Cybersecurity Incident Disclosure

Supports:

Early surfacing of credential exposure supports incident materiality assessment for public companies.

Doesn't:

Not a determination of materiality — assists, does not decide.

breach check

Need an audit-ready crosswalk for your client?

Lionfish produces a branded PDF crosswalk that maps Reefscan evidence to your client's specific framework (ISO 27001, SOC 2, NIST 800-53, etc.) — ready to drop into an audit binder.

Request a Crosswalk PDF
Reefscan is a privacy-awareness tool. It supports — but does not replace — formal compliance programs. Lionfish Cyber Security provides advisory services for full compliance attestations.