Insights

Notes from the engagements.

Practical writing on the regulations and frameworks we work in day to day — no vendor pitches.

Who actually falls in scope, and what changes first

NIS2 widened the net far beyond the original NIS Directive, but "in scope" doesn't mean "everything at once." We walk through how entity classification actually works, and the handful of obligations — incident reporting timelines, governance accountability, and supply-chain risk — that tend to bite first.

Read the full post →

What belongs in your register of information

The register of information is one of the more mechanical-sounding DORA requirements — and one of the easiest to get wrong. A look at what actually needs to be captured about your ICT third parties, and how to keep it accurate as vendor relationships change.

Read the full post →

What actually changed in the 2022 Annex A controls

The move from 114 controls across 14 clauses to 93 controls across 4 themes wasn't just reorganisation. Here's what's genuinely new — including the controls organisations most often overlook when transitioning an existing ISMS.

Read the full post →

CIS Controls v8: choosing the right Implementation Group

IG1, IG2 or IG3 — the group you pick determines the entire shape of your architecture roadmap. A practical framework for scoping the right one, and why "start higher than you think" is usually the wrong instinct.

Read the full post →

Have a specific question?

We're happy to talk through where your organisation stands, no article required.

Get in touch