You Have ISO 42001 Certification. Now the Real Work Begins.
ISO 42001 certification is a significant achievement. It represents independent, third-party verified evidence that your organisation has a functioning …
Guides, articles, and analysis on ISO compliance, GRC, offensive security, and emerging cyber risk — written by our practitioners.
ISO 42001 certification is a significant achievement. It represents independent, third-party verified evidence that your organisation has a functioning …
As of 31 March 2025, all PCI DSS v4.0 requirements are mandatory. The twelve “future-dated” requirements that were flagged as best practices in 2024 are…
ISO 42001 is fifteen months old. Enough organisations have now moved through implementation — or stalled partway through — that the failure patterns are…
ISO/IEC 27701:2025 has been published. After years of development and months of anticipation from the privacy management community, the revised standard…
As of 17 January 2025, DORA is fully enforceable. Competent authorities across EU member states — the ECB, national central banks, financial regulators …
DORA’s compliance deadline of 17 January 2025 has arrived. For financial entities operating under EU regulation — banks, insurers, investment firms, pay…
NIS2 Article 21 includes supply chain security among the mandatory cybersecurity risk management measures that all essential and important entities must…
On 2 February 2025 — six weeks from today — the EU AI Act’s first enforcement provisions become active. From that date, deploying AI systems that fall i…
Certification day feels like the end of the journey. The Stage 2 audit is done. The certificate is issued. The news goes on the website, the LinkedIn an…
There is a significant difference between organisations that reference the NIST Cybersecurity Framework and organisations that build their security prog…
A pattern we are seeing more frequently this year: organisations that hold ISO 27001 certification, have recently added ISO 27701, and are now asking wh…
There are twelve months left. On 31 October 2025, every ISO 27001:2013 certificate in the world becomes invalid. Certification bodies will not issue tra…
17 October 2024 is the deadline by which EU member states were required to transpose NIS2 into national law. As of this date, not every member state has…
If you have implemented ISO 27001, you know how to do a risk assessment. You identify assets, enumerate threats and vulnerabilities, assess likelihood a…
The next version of ISO 27701 is in its final development stages and expected to publish in early 2025. For privacy professionals and organisations curr…
Of all the ISO 27001 requirements, the internal audit is the one most frequently misunderstood — and most frequently misused. Some organisations treat i…
On 1 August 2024, the EU AI Act entered into force. The world’s first comprehensive legal framework for artificial intelligence is no longer a proposal …
If you have been researching AI governance frameworks, you have almost certainly encountered two names repeatedly: NIST AI RMF and ISO 42001. Both are c…
Here is a problem that does not get enough attention in AI governance discussions. When a legal team, a data science team, an information security team,…
If your organisation builds software, manufactures connected hardware, or supplies products with digital components into the EU market, you need to be p…
One of the most common points of confusion in PCI DSS compliance is the assessment process itself. Do you need a Qualified Security Assessor to conduct …
ISO 42001:2023 has been on the shelf for three months and the number one question we hear from organisations is the same one every time: “What does it a…
NIST published the final Cybersecurity Framework 2.0 on 26 February 2024. It is the first major revision of the framework since its initial publication …
Cyber resilience testing is moving from best practice to regulatory mandate. Across EU financial services under DORA, critical infrastructure operators …
The typical security journey for a fast-growing technology company looks like this. Security in the early stages is handled informally — a developer who…
Today is 17 January 2024. DORA’s compliance deadline — 17 January 2025 — is exactly twelve months away. The regulatory technical standards that define t…
On 18 December 2023, ISO published ISO/IEC 42001:2023. It is the world’s first international standard for Artificial Intelligence Management Systems — a…
The honest answer is yes — but only if you stop approaching it like a large organisation would. ISO 27001 has a persistent reputation as a framework for…
One of the most common misconceptions in IT governance is that internal IT audit and external IT audit serve the same purpose. They do not. They provide…
NIST is finalising version 2.0 of the Cybersecurity Framework, expected to be published in early 2024. The update is the most significant revision since…
Receiving your first SOC 2 Type II report is a significant milestone. It demonstrates to clients and prospects that your security programme has been ind…
NIS2’s incident reporting requirements introduce the tightest regulatory notification timeline in EU cybersecurity law to date. Article 23 requires in-s…
PCI DSS v3.2.1 retires on 31 March 2024. From that date, QSA assessments, self-assessment questionnaires, and all PCI DSS compliance processes will be c…
DORA’s ICT-related incident reporting requirements are among the most operationally demanding elements of the regulation. The 4-hour window for initial …
ISO 27001 certifications do not fail because the standard is too hard. They fail because of a predictable set of mistakes that show up across organisati…
NIS2 creates something that did not exist in EU cybersecurity regulation before: personal liability for board members and senior executives for cybersec…
If you are currently certified to ISO 27001:2013, you have a hard deadline coming. On 31 October 2025, all ISO 27001:2013 certificates will cease to be …
In the first half of 2023, generative AI adoption in organisations went from a curiosity to a mainstream reality. Employees are using ChatGPT, Copilot, …
Of all DORA’s requirements, the ICT third-party risk management obligations are generating the most operational complexity for financial entities. The r…
Article 25 of GDPR has been on the books since 2018. It requires organisations to implement data protection by design and by default — building privacy …
One of the most predictable conversations in IT GRC goes like this. An organisation asks what GRC platform they should invest in. After some discussion,…
NIS2 divides in-scope organisations into two categories: essential entities and important entities. The distinction is not cosmetic — it determines the …
Most frameworks that require tabletop exercises — DORA, NIS2, ISO 27001 recommendations, NCSC guidance — specify periodic testing without defining a pre…
Ask most IT security managers to describe their experience presenting to the board, and you will hear a version of the same story. A slide deck was prep…
SOC 2 exceptions — findings in the audit report that indicate a control was not suitably designed or not operating effectively — are more common than mo…
Ask any lead auditor what separates an ISMS that passes from one that doesn’t, and the answer will almost always come back to the same place: the risk a…
A compliance-led security programme — one built to satisfy ISO 27001, Cyber Essentials, or PCI DSS — provides a set of controls that represent good base…
“Does DORA apply to us?” This question is generating significant uncertainty across the financial services industry — and understandably so. DORA’s scop…
The shift of financial and operational workloads to cloud platforms has not eliminated IT audit obligations — it has changed where the controls live and…
The number 93 stops a lot of people in their tracks. Ninety-three security controls. That is what ISO 27001:2022’s revised Annex A presents to any organ…
The EU’s NIS2 Directive entered into force on 16 January 2023. It replaces the original Network and Information Security (NIS) Directive, which has gove…
The EU’s Digital Operational Resilience Act — DORA — was published in the Official Journal of the European Union on 27 December 2022. It entered into fo…
Certification audits are not random sampling exercises. Experienced lead auditors for ISO 27701 follow a consistent logic: they look for evidence that y…
The wait is over. On 25 October 2022, ISO published ISO/IEC 27001:2022 — the first major revision to the information security management standard in nea…
The most significant cybersecurity incidents of the past several years have had one thing in common: they did not start with a direct attack on the orga…
Ransomware is the scenario that concentrates minds most effectively. When organisations run ransomware tabletop exercises — particularly when executive …
Before a single PCI DSS control is implemented, before a policy is written, before a QSA is engaged — there is one decision that determines the size, co…
If you are a technology or cloud service provider deciding on your security assurance programme, you will face this question at some point: SOC 2 or ISO…
When organisations decide they need to “do more on security,” two options frequently appear in the same conversation: engaging a vCISO or contracting an…
Section 404 of the Sarbanes-Oxley Act requires listed companies to assess, document, and report on the effectiveness of their internal controls over fin…
NIST CSF’s four implementation tiers are one of the most misused elements of the framework. Organisations that self-assess their security programme ofte…
The security team has identified a critical capability gap. The investment required is significant. The board needs to approve it. And when the request …
The standard IT risk assessment produces a risk matrix. Risks are rated high, medium, or low — or red, amber, or green — based on a combination of likel…
Ransomware is the dominant cyber threat facing most organisations. It is the threat most likely to trigger a DR plan. And for most organisations, the DR…
PCI DSS v4.0 was published on 31 March 2022. After four years of development, stakeholder feedback rounds, and two draft versions, the Payment Card Indu…
It is the question that comes up in almost every initial conversation we have about ISO 27701. An organisation wants to certify its privacy management p…
Most organisations understand what a CISO does. The Chief Information Security Officer is the senior executive responsible for the organisation’s cybers…
Ask most organisations whether they are prepared for a significant cybersecurity incident and you will get a confident answer: “Yes, we have an incident…
The traditional image of an IT audit involves a team of auditors arriving on-site, booking a conference room, and spending weeks walking the floor, cond…
Almost every organisation we engage with has an information security policy framework. They have a set of documents — an information security policy, an…
“How long does SOC 2 take?” It is consistently the first practical question organisations ask when they begin their SOC 2 journey, and it is consistentl…
The question comes up in almost every strategy engagement: “We are pursuing ISO 27001 certification — do we still need to reference the NIST CSF? Or are…
One of the most common mistakes in cybersecurity strategy development is building the strategy before understanding the current state. Organisations set…
Every year, your external financial auditors spend time reviewing your IT systems. Not because they are cybersecurity specialists, and not because they …
Ask any privacy professional what separates a PIMS that holds up under audit from one that falls apart, and the answer will almost always involve data f…
Almost every organisation we work with has a risk appetite statement. It is in the annual report, or the risk management policy, or the board papers. It…
SOC 2 is built on the Trust Services Criteria (TSC) — a framework developed by the AICPA that defines the control requirements that your SOC 2 audit wil…
Most organisations have a disaster recovery plan. It documents the recovery procedures for critical systems, the RTO and RPO targets, the escalation con…
IT GRC — Governance, Risk, and Compliance — is one of those terms that everyone in the technology and security industry uses but relatively few organisa…
Ask ten people in a technology organisation what an IT audit is, and you will get at least four different answers. Some will describe a penetration test…
The NIST Cybersecurity Framework (CSF) is one of the most widely referenced security frameworks globally — and one of the most inconsistently understood…
In most organisations, IT risk and enterprise risk are managed in parallel universes. The IT team maintains a risk register full of technical vulnerabil…
Ask a security manager to describe their organisation’s cybersecurity strategy, and you will typically get one of three responses. A list of the securit…
SOC 2 is the assurance standard that technology and cloud service providers use to demonstrate their security controls to the enterprise clients who tru…
Disaster recovery and business continuity are used interchangeably in many organisations. The IT team owns “DR.” The business continuity plan is a docum…
Eighteen months after ISO 27701 launched, patterns are emerging in how organisations approach PIMS implementation — and which approaches lead to certifi…
The first question every ISO 27701 implementation must answer is also the one most organisations get wrong. Are you a PII Controller, a PII Processor, o…
The fines are no longer hypothetical. In July 2019, the UK Information Commissioner’s Office announced its intention to fine British Airways £183 millio…
GDPR gave organisations an obligation but not a blueprint. It told you to implement “appropriate technical and organisational measures” for privacy. It …