Insights
Practical writing on the regulations and frameworks we work in day to day — no vendor pitches.
NIS2 widened the net far beyond the original NIS Directive, but "in scope" doesn't mean "everything at once." We walk through how entity classification actually works, and the handful of obligations — incident reporting timelines, governance accountability, and supply-chain risk — that tend to bite first.
Read the full post →The register of information is one of the more mechanical-sounding DORA requirements — and one of the easiest to get wrong. A look at what actually needs to be captured about your ICT third parties, and how to keep it accurate as vendor relationships change.
Read the full post →The move from 114 controls across 14 clauses to 93 controls across 4 themes wasn't just reorganisation. Here's what's genuinely new — including the controls organisations most often overlook when transitioning an existing ISMS.
Read the full post →IG1, IG2 or IG3 — the group you pick determines the entire shape of your architecture roadmap. A practical framework for scoping the right one, and why "start higher than you think" is usually the wrong instinct.
Read the full post →We're happy to talk through where your organisation stands, no article required.
Get in touch