Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
The security questionnaire you cannot answer, and what it is really asking
A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.
The Cyber Resilience Act reporting duty starts on 11 September
From 11 September 2026, anyone who places a product with digital elements on the EU market has 24 hours to report an actively exploited vulnerability. Not the company using the product. The company that made it.
EASA Part-IS: what it means if you supply the aviation industry
Part-IS has applied to aerodromes and production organisations since 16 October 2025, and to airlines, MROs and air navigation providers since 22 February 2026. If you supply any of them, it reaches you by contract. Here is how far it actually goes.
Certified is not secure: what a certificate leaves open
An ISO 27001 certificate is a real achievement and a genuine commercial asset. It is also silent on the four questions that decide whether you get breached. Here is exactly where the standard stops.
Doing ISO 27001 and NIS2 once instead of twice
Roughly 70 to 80 per cent of what NIS2 Article 21 asks for is already covered by an ISO 27001 ISMS. The remaining fifth is where the work is, and it is not the part anyone budgets for.
Evidence that assembles itself, and evidence you assemble the month before
Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.
Stage 1 and Stage 2: what the auditor asks for, and what they accept
Stage 1 reads your documents. Stage 2 tests whether the documented system actually ran. Most projects prepare hard for the first and get caught by the second. Here is what each one looks at and what a finding costs you.
Internal audit and management review, the two steps everyone underestimates
Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.
What ISO 27001 actually costs an SME, including the lines nobody quotes
The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.