Insights

Analysis from the people running the programmes

Practical commentary on standards, regulation and the operational realities of security assurance.

AI Governance

ISO 42001: the five questions every board should ask about AI

Certification is becoming a procurement requirement. Here is how directors can test whether their AI management system is real.

12 June 2026 · 6 min read

Resilience

From DORA paperwork to genuine operational resilience

Most financial institutions have the register. Far fewer can evidence recovery under stress. A practical closing plan.

28 May 2026 · 8 min read

ISO 27001

Four scoping mistakes that derail ISO 27001 certification

Scope decisions made in week one determine audit cost in month nine. The traps we see most often.

9 May 2026 · 5 min read

Cloud Security

Reducing identity blast radius in multi-cloud estates

Standing privileges remain the single largest driver of cloud incident severity. A pragmatic reduction programme.

21 April 2026 · 7 min read

Privacy

Making privacy by design operational with ISO 27701

How to convert a privacy policy shelf-ware library into controls engineers actually execute.

3 April 2026 · 6 min read

Leadership

The virtual CISO's first 90 days

A structured plan for establishing credibility, baselining risk and delivering visible wins in one quarter.

18 March 2026 · 9 min read