Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

Surveillance audits: what year two and year three actually involve
ISO 27001 · 6 min read · 15 Sept 2026

Surveillance audits: what year two and year three actually involve

Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.

Daniel Grigorovich
Daniel Grigorovich · Founder
Adding ISO 27001 when you already hold ISO 9001
ISO 27001 · 6 min read · 14 Sept 2026

Adding ISO 27001 when you already hold ISO 9001

If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.

Daniel Grigorovich
Daniel Grigorovich · Founder
The risk register that survives an audit, and the one that does not
GRC · 7 min read · 14 Sept 2026

The risk register that survives an audit, and the one that does not

ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.

Daniel Grigorovich
Daniel Grigorovich · Founder
EASA Part-IS: what it means if you supply the aviation industry
Aviation · 6 min read · 9 Sept 2026

EASA Part-IS: what it means if you supply the aviation industry

Part-IS has applied to aerodromes and production organisations since 16 October 2025, and to airlines, MROs and air navigation providers since 22 February 2026. If you supply any of them, it reaches you by contract. Here is how far it actually goes.

Daniel Grigorovich
Daniel Grigorovich · Founder
Stage 1 and Stage 2: what the auditor asks for, and what they accept
ISO 27001 · 6 min read · 7 Sept 2026

Stage 1 and Stage 2: what the auditor asks for, and what they accept

Stage 1 reads your documents. Stage 2 tests whether the documented system actually ran. Most projects prepare hard for the first and get caught by the second. Here is what each one looks at and what a finding costs you.

Daniel Grigorovich
Daniel Grigorovich · Founder
Internal audit and management review, the two steps everyone underestimates
ISO 27001 · 8 min read · 4 Sept 2026

Internal audit and management review, the two steps everyone underestimates

Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.

Daniel Grigorovich
Daniel Grigorovich · Founder
ISO 27001 for a company without a security team
ISO 27001 · 8 min read · 2 Sept 2026

ISO 27001 for a company without a security team: what it actually involves

What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.

Daniel Grigorovich
Daniel Grigorovich · Founder