Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

The first ninety days of a part-time security owner
vCISO · 9 min read · 16 Sept 2026

The first ninety days of a part-time security owner

Someone has just been handed security on top of their existing job. Ninety days is enough to know what you have, what is already decided badly, and what the board has to sign. It is not enough to write forty policies, and the attempt is what usually fails.

Daniel Grigorovich
Daniel Grigorovich · Founder
The security annex, clause by clause
Space · 9 min read · 16 Sept 2026

The security annex, clause by clause: what a prime contractor is really asking for

The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.

Daniel Grigorovich
Daniel Grigorovich · Founder
Ground segment access: what a satellite operator checks before letting you in
Space · 7 min read · 15 Sept 2026

Ground segment access: what a satellite operator checks before letting you in

The satellite is the hard target. The ground station sits on a network reachable from an office. That is why the access review a space operator runs on a supplier is stricter than anything in the directive, and why it arrives years before the EU Space Act does.

Daniel Grigorovich
Daniel Grigorovich · Founder
Surveillance audits: what year two and year three actually involve
ISO 27001 · 6 min read · 15 Sept 2026

Surveillance audits: what year two and year three actually involve

Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.

Daniel Grigorovich
Daniel Grigorovich · Founder
Adding ISO 27001 when you already hold ISO 9001
ISO 27001 · 6 min read · 14 Sept 2026

Adding ISO 27001 when you already hold ISO 9001

If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.

Daniel Grigorovich
Daniel Grigorovich · Founder
The risk register that survives an audit, and the one that does not
GRC · 7 min read · 14 Sept 2026

The risk register that survives an audit, and the one that does not

ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.

Daniel Grigorovich
Daniel Grigorovich · Founder
Space suppliers: the four regimes you actually sit under
Space · 8 min read · 11 Sept 2026

Space suppliers: the four regimes you actually sit under

A company selling into satellite operators sits under four separate regimes at once: NIS2, the proposed EU Space Act, national space authorisation, and whatever the prime contractor writes into the contract. Only one of them will reach you this year.

Daniel Grigorovich
Daniel Grigorovich · Founder
Who owns security when nobody owns it
vCISO · 7 min read · 11 Sept 2026

Who owns security when nobody owns it

NIS2 makes the management body approve and oversee security measures. ISO 27001 requires the roles to be assigned. Neither says hire a CISO. In a company of forty, security lands on whoever is nearest, and nothing that is everyone's job gets done.

Daniel Grigorovich
Daniel Grigorovich · Founder
Telecom suppliers: the two ways NIS2 reaches you, and the one people miss
Telecom · 6 min read · 10 Sept 2026

Telecom suppliers: the two ways NIS2 reaches you, and the one people miss

Most suppliers to telecom operators assume NIS2 reaches them only through their customer's contract. For managed service providers, cloud, data centre, DNS and trust services, there is a second route, and it is more prescriptive than the first.

Daniel Grigorovich
Daniel Grigorovich · Founder