GOVERNANCEISO/IEC 27001 · COBIT
Security in the language of the Board
Executive reporting that answers the three questions a Board actually asks: what could stop us trading, what are we doing about it, and is it working. Metrics, committee structures, and an oversight model that survives a change of CISO.
Read the perspective →
CYBER RISKISO/IEC 27005 · NIST CSF
Ranking risk you can act on
Enterprise risk assessment and business impact analysis produce a lot of paper and not much prioritisation. How to get from a control-gap list to a treatment plan that survives a budget conversation.
Read the perspective →
REGULATIONDORA · NIS2 · SWIFT CSCF
Reading a directive like an engineer
What DORA and NIS2 actually require of your architecture, incident reporting, and supplier arrangements — mapped to the controls most organisations already run under ISO/IEC 27001, so the gap is smaller than it first looks.
Read the perspective →
THIRD PARTYISO/IEC 27001 · GDPR
The suppliers you cannot audit
Cloud and third-party dependency now carries more residual risk than most internal estates. A proportionate third-party risk model: tiering by business impact, evidence you can realistically obtain, and contractual fallbacks.
Read the perspective →
RESILIENCEISO 22301 · DORA
From recovery plan to recovery proof
Business impact analysis, continuity and disaster recovery planning, crisis management, and the resilience testing that turns a documented RTO into an evidenced one. Where exercises usually fail, and how to design one that finds something.
Read the perspective →
HUMAN RISKISO/IEC 27001 Annex A
Awareness that changes behaviour
Annual e-learning is a compliance artefact, not a control. Building differentiated programmes for executives, developers, technical teams, and general staff — and measuring the behaviour, not the completion rate.
Read the perspective →