Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

The security questionnaire you cannot answer, and what it is really asking
GRC · 6 min read · 10 Sept 2026

The security questionnaire you cannot answer, and what it is really asking

A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.

Daniel Grigorovich
Daniel Grigorovich · Founder
The Cyber Resilience Act reporting duty starts on 11 September
CRA · 6 min read · 9 Sept 2026

The Cyber Resilience Act reporting duty starts on 11 September

From 11 September 2026, anyone who places a product with digital elements on the EU market has 24 hours to report an actively exploited vulnerability. Not the company using the product. The company that made it.

Daniel Grigorovich
Daniel Grigorovich · Founder
EASA Part-IS: what it means if you supply the aviation industry
Aviation · 6 min read · 9 Sept 2026

EASA Part-IS: what it means if you supply the aviation industry

Part-IS has applied to aerodromes and production organisations since 16 October 2025, and to airlines, MROs and air navigation providers since 22 February 2026. If you supply any of them, it reaches you by contract. Here is how far it actually goes.

Daniel Grigorovich
Daniel Grigorovich · Founder
Certified is not secure: what a certificate leaves open
ISO 27001 · 5 min read · 8 Sept 2026

Certified is not secure: what a certificate leaves open

An ISO 27001 certificate is a real achievement and a genuine commercial asset. It is also silent on the four questions that decide whether you get breached. Here is exactly where the standard stops.

Daniel Grigorovich
Daniel Grigorovich · Founder
Doing ISO 27001 and NIS2 once instead of twice
ISO 27001 · 6 min read · 8 Sept 2026

Doing ISO 27001 and NIS2 once instead of twice

Roughly 70 to 80 per cent of what NIS2 Article 21 asks for is already covered by an ISO 27001 ISMS. The remaining fifth is where the work is, and it is not the part anyone budgets for.

Daniel Grigorovich
Daniel Grigorovich · Founder
Evidence that assembles itself, and evidence you assemble the month before
ISO 27001 · 6 min read · 7 Sept 2026

Evidence that assembles itself, and evidence you assemble the month before

Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.

Daniel Grigorovich
Daniel Grigorovich · Founder
Stage 1 and Stage 2: what the auditor asks for, and what they accept
ISO 27001 · 6 min read · 7 Sept 2026

Stage 1 and Stage 2: what the auditor asks for, and what they accept

Stage 1 reads your documents. Stage 2 tests whether the documented system actually ran. Most projects prepare hard for the first and get caught by the second. Here is what each one looks at and what a finding costs you.

Daniel Grigorovich
Daniel Grigorovich · Founder
Internal audit and management review, the two steps everyone underestimates
ISO 27001 · 8 min read · 4 Sept 2026

Internal audit and management review, the two steps everyone underestimates

Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.

Daniel Grigorovich
Daniel Grigorovich · Founder
What ISO 27001 actually costs an SME, including the lines nobody quotes
ISO 27001 · 8 min read · 4 Sept 2026

What ISO 27001 actually costs an SME, including the lines nobody quotes

The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.

Daniel Grigorovich
Daniel Grigorovich · Founder