Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

The 93 Annex A controls, grouped the way you will actually work through them
ISO 27001 · 7 min read · 3 Sept 2026

The 93 Annex A controls, grouped the way you will actually work through them

ISO groups the 93 controls into four themes. That is a filing system, not a work plan. Here is the grouping that matches how a company without a security team actually gets through them.

Daniel Grigorovich
Daniel Grigorovich · Founder
How long ISO 27001 really takes, and what makes it slower
ISO 27001 · 6 min read · 3 Sept 2026

How long ISO 27001 really takes, and what makes it slower

Nine to twelve months is the honest answer for a company starting from scratch. Here is where every month goes, which parts can be compressed, and the one constraint that cannot be.

Daniel Grigorovich
Daniel Grigorovich · Founder
Scope and Statement of Applicability, explained without the jargon
ISO 27001 · 8 min read · 2 Sept 2026

Scope and Statement of Applicability, explained without the jargon

Two documents decide how much ISO 27001 costs you and whether the certificate answers your customer's question. Here is what scope and the Statement of Applicability actually are, and how small companies get them wrong.

Daniel Grigorovich
Daniel Grigorovich · Founder
ISO 27001 for a company without a security team
ISO 27001 · 8 min read · 2 Sept 2026

ISO 27001 for a company without a security team: what it actually involves

What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.

Daniel Grigorovich
Daniel Grigorovich · Founder
The Ransomware Dimension of NIS2
NIS2 · 10 min read · 29 Jun 2026

The Ransomware Dimension of NIS2

NIS2 Recital 54 addresses ransomware as a strategic threat. Learn how the Directive tackles this persistent risk and what it means for your organisation.

Daniel Grigorovich
Daniel Grigorovich · Founder
National Cybersecurity Strategies: The 10 Mandatory Policy Areas
NIS2 · 10 min read · 26 Jun 2026

National Cybersecurity Strategies: The 10 Mandatory Policy Areas

NIS2 Article 7 mandates 10 policy areas in national cybersecurity strategies. Understand what Member States must address and why it matters.

Daniel Grigorovich
Daniel Grigorovich · Founder
Coordinated Supply Chain Risk Assessments: EU Evaluating ICT Dependencies
NIS2 · 8 min read · 24 Jun 2026

Coordinated Supply Chain Risk Assessments: EU Evaluating ICT Dependencies

NIS2 Article 22 establishes coordinated supply chain risk assessments. Learn how EU evaluates critical ICT dependencies and what it means for your sector.

Daniel Grigorovich
Daniel Grigorovich · Founder
Cyber Threat Notification: When and How to Warn Service Recipients
NIS2 · 9 min read · 22 Jun 2026

Cyber Threat Notification: When and How to Warn Service Recipients

NIS2 requires entities to warn service recipients of significant cyber threats. Learn when notification is required and how to do it effectively.

Daniel Grigorovich
Daniel Grigorovich · Founder
The DNS Under NIS2: Why Domain Name System Security Is Foundational
NIS2 · 9 min read · 19 Jun 2026

The DNS Under NIS2: Why Domain Name System Security Is Foundational

NIS2 treats DNS as critical infrastructure. Understand why domain name system security matters and what NIS2 requires of DNS providers.

Daniel Grigorovich
Daniel Grigorovich · Founder