Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
The first ninety days of a part-time security owner
Someone has just been handed security on top of their existing job. Ninety days is enough to know what you have, what is already decided badly, and what the board has to sign. It is not enough to write forty policies, and the attempt is what usually fails.
The security annex, clause by clause: what a prime contractor is really asking for
The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.
Ground segment access: what a satellite operator checks before letting you in
The satellite is the hard target. The ground station sits on a network reachable from an office. That is why the access review a space operator runs on a supplier is stricter than anything in the directive, and why it arrives years before the EU Space Act does.
Surveillance audits: what year two and year three actually involve
Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.
Adding ISO 27001 when you already hold ISO 9001
If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.
The risk register that survives an audit, and the one that does not
ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.
Space suppliers: the four regimes you actually sit under
A company selling into satellite operators sits under four separate regimes at once: NIS2, the proposed EU Space Act, national space authorisation, and whatever the prime contractor writes into the contract. Only one of them will reach you this year.
Who owns security when nobody owns it
NIS2 makes the management body approve and oversee security measures. ISO 27001 requires the roles to be assigned. Neither says hire a CISO. In a company of forty, security lands on whoever is nearest, and nothing that is everyone's job gets done.
Telecom suppliers: the two ways NIS2 reaches you, and the one people miss
Most suppliers to telecom operators assume NIS2 reaches them only through their customer's contract. For managed service providers, cloud, data centre, DNS and trust services, there is a second route, and it is more prescriptive than the first.