Blog
Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
What ISO 27001 actually costs an SME, including the lines nobody quotes
The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.
How long ISO 27001 really takes, and what makes it slower
Nine to twelve months is the honest answer for a company starting from scratch. Here is where every month goes, which parts can be compressed, and the one constraint that cannot be.