Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

The first ninety days of a part-time security owner
vCISO · 9 min read · 16 Sept 2026

The first ninety days of a part-time security owner

Someone has just been handed security on top of their existing job. Ninety days is enough to know what you have, what is already decided badly, and what the board has to sign. It is not enough to write forty policies, and the attempt is what usually fails.

Daniel Grigorovich
Daniel Grigorovich · Founder
Adding ISO 27001 when you already hold ISO 9001
ISO 27001 · 6 min read · 14 Sept 2026

Adding ISO 27001 when you already hold ISO 9001

If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.

Daniel Grigorovich
Daniel Grigorovich · Founder
Who owns security when nobody owns it
vCISO · 7 min read · 11 Sept 2026

Who owns security when nobody owns it

NIS2 makes the management body approve and oversee security measures. ISO 27001 requires the roles to be assigned. Neither says hire a CISO. In a company of forty, security lands on whoever is nearest, and nothing that is everyone's job gets done.

Daniel Grigorovich
Daniel Grigorovich · Founder
The security questionnaire you cannot answer, and what it is really asking
GRC · 6 min read · 10 Sept 2026

The security questionnaire you cannot answer, and what it is really asking

A CAIQ is around 260 questions. A full SIG is over 800. Behind all of them sit the same three questions, and answering those once is the difference between two days of work and six weeks.

Daniel Grigorovich
Daniel Grigorovich · Founder
The Cyber Resilience Act reporting duty starts on 11 September
CRA · 6 min read · 9 Sept 2026

The Cyber Resilience Act reporting duty starts on 11 September

From 11 September 2026, anyone who places a product with digital elements on the EU market has 24 hours to report an actively exploited vulnerability. Not the company using the product. The company that made it.

Daniel Grigorovich
Daniel Grigorovich · Founder
What ISO 27001 actually costs an SME, including the lines nobody quotes
ISO 27001 · 8 min read · 4 Sept 2026

What ISO 27001 actually costs an SME, including the lines nobody quotes

The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.

Daniel Grigorovich
Daniel Grigorovich · Founder
ISO 27001 for a company without a security team
ISO 27001 · 8 min read · 2 Sept 2026

ISO 27001 for a company without a security team: what it actually involves

What ISO 27001 really asks of a company with no CISO and no security team: the decisions only you can make, the documents the standard forces, the 93 controls, and the honest timeline.

Daniel Grigorovich
Daniel Grigorovich · Founder