Insights

From the practice

Practical perspectives on information security, compliance frameworks, and the regulations shaping European business.

NIS 2
NIS 2 is law. What German companies need to do now.

The NIS2UmsuCG took effect in December 2025 with no transition period. Management liability is personal. Here is what being in scope actually means.

Read article
Internal Audit
ISO 27001 internal audit: what defensible actually looks like

What defensible internal audit looks like: the six dimensions of audit depth, ISO 19011 competence, and ISO/IEC 17021-1 impartiality discipline.

Read article
EU AI Act
From ISO 27001 to EU AI Act: how to extend your ISMS into an AI Management System

If you are already ISO/IEC 27001 certified, here is the practical pathway to EU AI Act compliance. How ISO/IEC 42001 builds on your existing ISMS, what to integrate, what to add.

Read article
ISO 27001
Why most ISO 27001 programmes fail their first surveillance audit

The certificate is not the finish line. Most programmes that collapse at surveillance were built around templates rather than the organisation's actual risk profile.

Read article
TISAX
TISAX vs ISO 27001: Which framework does your automotive supplier need?

Both cover information security but serve different purposes, different audiences, and require different evidence. The answer depends on your customers.

Read article
vCISO
The case for a vCISO: What fractional security leadership actually looks like

A virtual CISO is not a cheaper substitute for a full-time hire. It is a different kind of engagement with different scope, deliverables, and value.

Read article
SOC 2
SOC 2 for European companies: When it makes sense and how to approach it

European SaaS companies increasingly need SOC 2 to sell into American enterprise accounts. Here is when to pursue it and how to build the programme efficiently.

Read article
ISO 27001
Preparing for your ISO 27001 Stage 2 audit: What auditors actually look for

Stage 2 is where the ISMS is tested against real evidence. Most organisations underestimate what auditors are actually looking for and where the gaps tend to appear.

Read article
ISO 27001
What is a Statement of Applicability and why does it matter for ISO 27001?

The Statement of Applicability is one of the most misunderstood documents in ISO 27001. Getting it right is not optional, it is the first thing a certification auditor will review.

Read article
NIS 2
NIS 2 and supply chain security: What your third-party vendors need to know

NIS 2 does not stop at your organisation's boundary. Supply chain security is an explicit Article 21 obligation. What does that mean for how you manage vendors?

Read article
ISO 42001
ISO 42001 in practice: A first guide to building an AI Management System

ISO 42001 is the international standard for AI Management Systems. For organisations deploying AI in the EU, here is what building a compliant AIMS actually involves.

Read article
Training
Information security awareness training: purpose, requirements, and common gaps

Information security awareness training is a control that every ISMS relies on. Here is what it is for, what the regulations require, and where programmes commonly fall short.

Read article
Contact

Based in Düsseldorf. Working across Germany and the EU.

Address

Breite Str. 27
40213 Düsseldorf
Germany

Start here

Get in Touch

Connect

Registered office, Düsseldorf