Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
Surveillance audits: what year two and year three actually involve
Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.
The security questionnaire you cannot answer, and what it is really asking
A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.
Evidence that assembles itself, and evidence you assemble the month before
Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.