INSIGHTS
What we think, and what the numbers say
Articles are an argument with a date on them. Guides are something you work through. Reports are figures, cited to their source. We publish none of the three unless there is something in it you could act on.
ARTICLES
Articles
NIS2: what has to be true on the day
Not what the directive says — what an inspector can ask you to show, and what most organisations will not have.
Read ArticlesDORA: the register is the exam
Firms prepare for DORA by buying tooling. The supervisor asks for a list — and the list is where it falls apart.
Read ArticlesThe CRA turns a product into a support commitment
Manufacturers read the Cyber Resilience Act as a certification hurdle. It is closer to a warranty — one that runs for years after the sale.
ReadGUIDES
Guides
Are you in scope? A ten-minute self-check
Four questions that settle which of the European regimes apply to you, and one common way organisations get caught without being named anywhere.
Read GuidesThe first hour of a ransomware incident
What to do, in order, before anyone who knows what they are doing has arrived — and the two instincts that destroy the evidence.
Read GuidesHow to answer a client security questionnaire
Your client is in scope, so now you are. How to answer honestly, once, in a way you can reuse — and why the confident lie is the expensive option.
Read