Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

Surveillance audits: what year two and year three actually involve
ISO 27001 · 6 min read · 15 Sept 2026

Surveillance audits: what year two and year three actually involve

Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.

Daniel Grigorovich
Daniel Grigorovich · Founder
Adding ISO 27001 when you already hold ISO 9001
ISO 27001 · 6 min read · 14 Sept 2026

Adding ISO 27001 when you already hold ISO 9001

If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.

Daniel Grigorovich
Daniel Grigorovich · Founder
Certified is not secure: what a certificate leaves open
ISO 27001 · 5 min read · 8 Sept 2026

Certified is not secure: what a certificate leaves open

An ISO 27001 certificate is a real achievement and a genuine commercial asset. It is also silent on the four questions that decide whether you get breached. Here is exactly where the standard stops.

Daniel Grigorovich
Daniel Grigorovich · Founder
Doing ISO 27001 and NIS2 once instead of twice
ISO 27001 · 6 min read · 8 Sept 2026

Doing ISO 27001 and NIS2 once instead of twice

Roughly 70 to 80 per cent of what NIS2 Article 21 asks for is already covered by an ISO 27001 ISMS. The remaining fifth is where the work is, and it is not the part anyone budgets for.

Daniel Grigorovich
Daniel Grigorovich · Founder
Evidence that assembles itself, and evidence you assemble the month before
ISO 27001 · 6 min read · 7 Sept 2026

Evidence that assembles itself, and evidence you assemble the month before

Every framework asks you to prove a control ran. There are two ways to do that, and the difference between them is roughly one month of work per audit, every audit, forever.

Daniel Grigorovich
Daniel Grigorovich · Founder
Stage 1 and Stage 2: what the auditor asks for, and what they accept
ISO 27001 · 6 min read · 7 Sept 2026

Stage 1 and Stage 2: what the auditor asks for, and what they accept

Stage 1 reads your documents. Stage 2 tests whether the documented system actually ran. Most projects prepare hard for the first and get caught by the second. Here is what each one looks at and what a finding costs you.

Daniel Grigorovich
Daniel Grigorovich · Founder
Internal audit and management review, the two steps everyone underestimates
ISO 27001 · 8 min read · 4 Sept 2026

Internal audit and management review, the two steps everyone underestimates

Clauses 9.2 and 9.3 are two meetings and a report on most project plans. They are also where Stage 2 audits get delayed. What each one actually requires, who is allowed to run it, and when to schedule them.

Daniel Grigorovich
Daniel Grigorovich · Founder
What ISO 27001 actually costs an SME, including the lines nobody quotes
ISO 27001 · 8 min read · 4 Sept 2026

What ISO 27001 actually costs an SME, including the lines nobody quotes

The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.

Daniel Grigorovich
Daniel Grigorovich · Founder
The 93 Annex A controls, grouped the way you will actually work through them
ISO 27001 · 7 min read · 3 Sept 2026

The 93 Annex A controls, grouped the way you will actually work through them

ISO groups the 93 controls into four themes. That is a filing system, not a work plan. Here is the grouping that matches how a company without a security team actually gets through them.

Daniel Grigorovich
Daniel Grigorovich · Founder
How long ISO 27001 really takes, and what makes it slower
ISO 27001 · 6 min read · 3 Sept 2026

How long ISO 27001 really takes, and what makes it slower

Nine to twelve months is the honest answer for a company starting from scratch. Here is where every month goes, which parts can be compressed, and the one constraint that cannot be.

Daniel Grigorovich
Daniel Grigorovich · Founder
Scope and Statement of Applicability, explained without the jargon
ISO 27001 · 8 min read · 2 Sept 2026

Scope and Statement of Applicability, explained without the jargon

Two documents decide how much ISO 27001 costs you and whether the certificate answers your customer's question. Here is what scope and the Statement of Applicability actually are, and how small companies get them wrong.

Daniel Grigorovich
Daniel Grigorovich · Founder
ISO 27001 for a company without a security team
ISO 27001 · 8 min read · 2 Sept 2026

ISO 27001 for a company without a security team: what it actually involves

What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.

Daniel Grigorovich
Daniel Grigorovich · Founder
Is €50K for ISO27001 Worth It? Probably Not the Way You're Spending It.
ISO 27001 · 5 min read · 18 Feb 2026

Is €50K for ISO27001 Worth It? Probably Not the Way You're Spending It.

SMEs spend €50-80K on ISO 27001 certification without fixing real security gaps. Learn when the investment makes sense and what to do instead.

Daniel Grigorovich
Daniel Grigorovich · Founder