Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

The security annex, clause by clause
Space · 9 min read · 16 Sept 2026

The security annex, clause by clause: what a prime contractor is really asking for

The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.

Daniel Grigorovich
Daniel Grigorovich · Founder
The risk register that survives an audit, and the one that does not
GRC · 7 min read · 14 Sept 2026

The risk register that survives an audit, and the one that does not

ENISA sets out seven things a risk treatment entry has to carry. Most registers written by an SME carry three. The gap is not paperwork, it is the part an auditor reads first and the part that decides whether the rest of your evidence is believed.

Daniel Grigorovich
Daniel Grigorovich · Founder
The security questionnaire you cannot answer, and what it is really asking
GRC · 6 min read · 10 Sept 2026

The security questionnaire you cannot answer, and what it is really asking

A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.

Daniel Grigorovich
Daniel Grigorovich · Founder
Doing ISO 27001 and NIS2 once instead of twice
ISO 27001 · 6 min read · 8 Sept 2026

Doing ISO 27001 and NIS2 once instead of twice

Roughly 70 to 80 per cent of what NIS2 Article 21 asks for is already covered by an ISO 27001 ISMS. The remaining fifth is where the work is, and it is not the part anyone budgets for.

Daniel Grigorovich
Daniel Grigorovich · Founder
Evidence that assembles itself, and evidence you assemble the month before
ISO 27001 · 6 min read · 7 Sept 2026

Evidence that assembles itself, and evidence you assemble the month before

Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.

Daniel Grigorovich
Daniel Grigorovich · Founder
Internal audit and management review, the two steps everyone underestimates
ISO 27001 · 8 min read · 4 Sept 2026

Internal audit and management review, the two steps everyone underestimates

Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.

Daniel Grigorovich
Daniel Grigorovich · Founder
The 93 Annex A controls, grouped the way you will actually work through them
ISO 27001 · 7 min read · 3 Sept 2026

The 93 Annex A controls, grouped the way you will actually work through them

ISO groups the 93 controls into four themes. That is a filing system, not a work plan. Here is the grouping that matches how a company without a security team actually gets through them.

Daniel Grigorovich
Daniel Grigorovich · Founder
Scope and Statement of Applicability, explained without the jargon
ISO 27001 · 8 min read · 2 Sept 2026

Scope and Statement of Applicability, explained without the jargon

Two documents decide how much ISO 27001 costs you and whether the certificate answers your customer's question. Here is what scope and the Statement of Applicability actually are, and how small companies get them wrong.

Daniel Grigorovich
Daniel Grigorovich · Founder