Guides

Practical perspectives you can use

Practical guidance on defending your business, and proving it, across NIS2, DORA, ISO 27001 and the vCISO role, written by a former CISO for boards and operators.

NIS2 · DORA · ISO 27001

One ISMS, not three audits

How ISO 27001 can serve as the backbone that satisfies NIS2 and DORA from a single set of evidence, and spares your team the cost of stacking frameworks.

Read the article →
DORA · Governance

DORA is a business issue, not just an ICT one

Why operational resilience and ICT third-party assurance need board ownership and clear accountability, not delegation to IT alone.

Read the article →
NIS2 · Getting started

From gap to roadmap without the overwhelm

A pragmatic first-90-days view for entities newly in scope of NIS2: what to assess, what to prioritise, and where to begin.

Read the article →
Frameworks · Overview

Cybersecurity controls frameworks: which one?

ISO 27001, NIST CSF, CIS, SOC 2, the SCF and more, explained in depth and mapped, with tables and graphics. What each is for and how they fit together.

Read the article →
Frameworks · SCF

The Secure Controls Framework: one control set, many regulations

Why a free metaframework that maps one control set to 200+ laws and standards is a practical shortcut to NIS2, DORA and ISO 27001.

Read the article →
vCISO · Leadership

vCISO: when (and why) you need one

The signs you need senior security leadership, what a virtual CISO actually does, and how fractional engagements work.

Read the article →
ISO 27001 · Getting started

ISO 27001 in 90 days: a realistic first quarter

What you can genuinely achieve toward certification in 90 days, and the order to do it in.

Read the article →
NIS2 · Incident reporting

NIS2 incident reporting: what to report, and when

The 24-hour, 72-hour and one-month reporting timeline, and how to be ready before the clock starts.

Read the article →