Field notes from security operations and the audit room.
Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.
The first ninety days of a part-time security owner
Someone has just been handed security on top of their existing job. Ninety days is enough to know what you have, what is already decided badly, and what the board has to sign. It is not enough to write forty policies, and the attempt is what usually fails.
Adding ISO 27001 when you already hold ISO 9001
If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.
Who owns security when nobody owns it
NIS2 makes the management body approve and oversee security measures. ISO 27001 requires the roles to be assigned. Neither says hire a CISO. In a company of forty, security lands on whoever is nearest, and nothing that is everyone's job gets done.
The security questionnaire you cannot answer, and what it is really asking
A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.
The Cyber Resilience Act reporting duty starts on 11 September
From 11 September 2026, anyone who places a product with digital elements on the EU market has 24 hours to report an actively exploited vulnerability. Not the company using the product. The company that made it.
What ISO 27001 actually costs an SME, including the lines nobody quotes
The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.
ISO 27001 for a company without a security team: what it actually involves
What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.