Media & insights

Practical, not promotional.

Perspectives from our consulting practice on governance, cyber risk, regulation, and resilience — written for the executives, security teams, and auditors who have to make them work.

Perspectives

The archive.

GOVERNANCEISO/IEC 27001 · COBIT

Security in the language of the Board

Executive reporting that answers the three questions a Board actually asks: what could stop us trading, what are we doing about it, and is it working. Metrics, committee structures, and an oversight model that survives a change of CISO.

Read the perspective →
CYBER RISKISO/IEC 27005 · NIST CSF

Ranking risk you can act on

Enterprise risk assessment and business impact analysis produce a lot of paper and not much prioritisation. How to get from a control-gap list to a treatment plan that survives a budget conversation.

Read the perspective →
REGULATIONDORA · NIS2 · SWIFT CSCF

Reading a directive like an engineer

What DORA and NIS2 actually require of your architecture, incident reporting, and supplier arrangements — mapped to the controls most organisations already run under ISO/IEC 27001, so the gap is smaller than it first looks.

Read the perspective →
THIRD PARTYISO/IEC 27001 · GDPR

The suppliers you cannot audit

Cloud and third-party dependency now carries more residual risk than most internal estates. A proportionate third-party risk model: tiering by business impact, evidence you can realistically obtain, and contractual fallbacks.

Read the perspective →
RESILIENCEISO 22301 · DORA

From recovery plan to recovery proof

Business impact analysis, continuity and disaster recovery planning, crisis management, and the resilience testing that turns a documented RTO into an evidenced one. Where exercises usually fail, and how to design one that finds something.

Read the perspective →
HUMAN RISKISO/IEC 27001 Annex A

Awareness that changes behaviour

Annual e-learning is a compliance artefact, not a control. Building differentiated programmes for executives, developers, technical teams, and general staff — and measuring the behaviour, not the completion rate.

Read the perspective →