Field notes from security operations and the audit room.
Two new posts a month. Written by the people who run the platform.
The Ransomware Dimension of NIS2
NIS2 Recital 54 addresses ransomware as a strategic threat. Learn how the Directive tackles this persistent risk and what it means for your organisation.
National Cybersecurity Strategies: The 10 Mandatory Policy Areas
NIS2 Article 7 mandates 10 policy areas in national cybersecurity strategies. Understand what Member States must address and why it matters.
Coordinated Supply Chain Risk Assessments: EU Evaluating ICT Dependencies
NIS2 Article 22 establishes coordinated supply chain risk assessments. Learn how EU evaluates critical ICT dependencies and what it means for your sector.
Cyber Threat Notification: When and How to Warn Service Recipients
NIS2 requires entities to warn service recipients of significant cyber threats. Learn when notification is required and how to do it effectively.
The DNS Under NIS2: Why Domain Name System Security Is Foundational
NIS2 treats DNS as critical infrastructure. Understand why domain name system security matters and what NIS2 requires of DNS providers.
SMEs and NIS2: Preparing Even If Not Directly In Scope
SMEs not directly in NIS2 scope should prepare now. Learn how supply chain, partner networks and indirect obligations affect your business.
Encryption Under NIS2: Mandatory for Some, Encouraged for All
NIS2 encryption guidance for telecom providers. Understand when end-to-end encryption is mandatory and why it matters for communications security.
NIS2 for the Food Sector: Wholesale and Industrial Processing
Understand NIS2 requirements for food businesses. Learn how wholesale and industrial processing entities must implement cybersecurity under Annex II Sector 4.
Peer Reviews Under NIS2: How Member States Will Be Assessed
Understand NIS2 Article 19 peer review process. Learn how Member States evaluate each other's cybersecurity capabilities and NIS2 implementation.