Field notes from security operations and the audit room.
Two new posts a month. Written by the people who run the platform.
Proportionality in Practice: Right-Sizing Your NIS2 Measures
Master NIS2 proportionality requirements. Learn how to assess, scale, and justify cybersecurity measures for essential and important entities.
NIS2 for the Financial Sector: Understanding the DORA Relationship
NIS2 and DORA for financial sector: understand how cybersecurity frameworks overlap for banks, payment institutions, and investment firms.
Cooperation Group, CSIRTs Network, EU-CyCLONe: EU Coordination at Scale
NIS2 cross-border coordination: Cooperation Group, EU-CyCLONe platform, and CSIRT network for collective incident response and intelligence sharing.
Cybersecurity Certification and Standards Under NIS2
NIS2 certification and standards under Articles 24-25: EU schemes, ISO 27001, and security certification requirements for designated entities.
National Cybersecurity Strategies Under NIS2: What Article 7 Requires
NIS2 Article 7 requirements for national strategies: policy framework, sectoral governance, research, and risk assessment mandates for Member States.
NIS2 for MSPs and MSSPs: From Vendor to Regulated Entity
NIS2 scope for MSPs and MSSPs: understand how managed service providers become regulated entities under Annex I, Sector 9.
NIS2 and GDPR: Where Cybersecurity Meets Data Protection
Understand NIS2-GDPR overlap: how cybersecurity obligations under NIS2 Articles 21, 35 complement GDPR Articles 32, 33-34 data protection requirements.
What Makes an Incident 'Significant'? Understanding the Reporting Threshold
Understand NIS2's significant incident threshold under Article 23(3): criteria for mandatory 24-hour reporting to authorities and CSIRTs.
NIS2 for Transport: Aviation, Rail, Maritime, and Road
NIS2 for transport sector: understand obligations for aviation, rail, maritime, and road operators under Annex I, Sector 2.