Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
Surveillance audits: what year two and year three actually involve
Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.
Adding ISO 27001 when you already hold ISO 9001
If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.
The risk register that survives an audit, and the one that does not
ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.
EASA Part-IS: what it means if you supply the aviation industry
Part-IS has applied to aerodromes and production organisations since 16 October 2025, and to airlines, MROs and air navigation providers since 22 February 2026. If you supply any of them, it reaches you by contract. Here is how far it actually goes.
Stage 1 and Stage 2: what the auditor asks for, and what they accept
Stage 1 reads your documents. Stage 2 tests whether the documented system actually ran. Most projects prepare hard for the first and get caught by the second. Here is what each one looks at and what a finding costs you.
Internal audit and management review, the two steps everyone underestimates
Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.
ISO 27001 for a company without a security team: what it actually involves
What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.