Library

    Everything published here, newest first.

    Working methods and regulatory briefings for security governance, risk and compliance practitioners.

    Type
    Pillar
    Track
    Framework

    31 of 31

    Template

    AI use-case triage form

    A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.

    Compliance5 Sept 20263 min read

    AI governance
    Briefing

    EU AI Act for security governance

    The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.

    Compliance5 Sept 20269 min read

    AI governance
    Template

    Findings-to-closure tracker template

    A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.

    Compliance5 Sept 20263 min read

    Playbook

    Running the external audit

    A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.

    Compliance5 Sept 202622 min read

    Insight

    The board question is not the CVE count

    A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.

    Security practice5 Sept 20263 min read

    Briefing

    CRA obligations by product class

    Regulation (EU) 2024/2847 by product class: the scope test, the obligations by article, the conformity route, and what starts on 11 September 2026.

    Compliance4 Sept 20269 min read

    Product & OT
    Playbook

    From regulation to controls

    A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.

    Compliance4 Sept 202622 min read

    Engagement pattern

    AI governance stand-up under the EU AI Act

    Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.

    Governance3 Sept 20265 min read

    AI governance
    Playbook

    Building an ISMS people actually use

    A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.

    Governance3 Sept 202623 min read

    Engagement pattern

    ISO 27001 first certification

    The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.

    Compliance3 Sept 20265 min read

    Briefing

    NIS2 for the security officer

    Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.

    Compliance3 Sept 20269 min read

    Engagement pattern

    NIS2 readiness for an important entity

    How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.

    Compliance3 Sept 20265 min read

    Engagement pattern

    Product cybersecurity under R155, ISO 21434 and the CRA

    One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.

    Compliance3 Sept 20265 min read

    Product & OT
    Template

    Risk register template

    A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.

    Risk3 Sept 20265 min read

    Playbook

    The risk register other people trust

    Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.

    Risk3 Sept 202622 min read

    Briefing

    The 90-day SOC 2 Type 1 plan

    A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.

    Compliance10 Jul 20268 min read

    SaaS