Insights

From the practice

Practical perspectives on information security, compliance frameworks, and the regulations shaping European business.

NIS 2
NIS 2 is law. What German companies need to do now.

The NIS2UmsuCG took effect in December 2025 with no transition period. Management liability is personal. Here is what being in scope actually means.

Read article
EU AI Act
EU AI Act deadlines: Is your organisation ready for August 2026?

High-risk AI system requirements apply from 2 August 2026. Most organisations have not started. Here is what conformity readiness actually requires.

Read article
ISO 27001
Why most ISO 27001 programmes fail their first surveillance audit

The certificate is not the finish line. Most programmes that collapse at surveillance were built around templates rather than the organisation's actual risk profile.

Read article
TISAX
TISAX vs ISO 27001: Which framework does your automotive supplier need?

Both cover information security but serve different purposes, different audiences, and require different evidence. The answer depends on your customers.

Read article
vCISO
The case for a vCISO: What fractional security leadership actually looks like

A virtual CISO is not a cheaper substitute for a full-time hire. It is a different kind of engagement with different scope, deliverables, and value.

Read article
SOC 2
SOC 2 for European companies: When it makes sense and how to approach it

European SaaS companies increasingly need SOC 2 to sell into American enterprise accounts. Here is when to pursue it and how to build the programme efficiently.

Read article
ISO 27001
Preparing for your ISO 27001 Stage 2 audit: What auditors actually look for

Stage 2 is where the ISMS is tested against real evidence. Most organisations underestimate what auditors are actually looking for and where the gaps tend to appear.

Read article
ISO 27001
What is a Statement of Applicability and why does it matter for ISO 27001?

The Statement of Applicability is one of the most misunderstood documents in ISO 27001. Getting it right is not optional — it is the first thing a certification auditor will review.

Read article
NIS 2
NIS 2 and supply chain security: What your third-party vendors need to know

NIS 2 does not stop at your organisation's boundary. Supply chain security is an explicit Article 21 obligation. What does that mean for how you manage vendors?

Read article
ISO 42001
ISO 42001 in practice: A first guide to building an AI Management System

ISO 42001 is the international standard for AI Management Systems. For organisations deploying AI in the EU, here is what building a compliant AIMS actually involves.

Read article
VAPT
Penetration testing for compliance: What a VAPT needs to actually deliver

A penetration test is not a compliance box to tick. When it feeds into your ISO 27001 or NIS 2 programme, scope, methodology and reporting all need to meet a higher standard.

Read article
Training
Security awareness training that actually works

The annual security awareness video is one of the most widely deployed and least effective security controls. Here is what effective awareness training looks like.

Read article