Knowledge Hub
Practical insights on information security and compliance,
from active auditors
ISO 27001 Clause 5: what the standard requires from management
Management can hand out the security work, but not the responsibility. This guide covers what Clause 5 asks of top management and how auditors test it.October 1, 2026Read moreISO 27001 Clause 5: what the standard requires from management
Management can hand out the security work, but not the responsibility. This guide covers what Clause 5 asks of top management and how auditors test it.
October 1, 2026
DORA: what actually lands on you as a supplier
DORA cannot fine you, but it can cost you the deal. This guide covers what actually lands on a supplier when a regulated customer has to meet its obligations.
September 22, 2026
NIS-2: how to tell in 20 minutes whether it applies to you
No one writes to tell you NIS-2 applies to you. This guide walks through the three-step test of sector, size and exceptions, and what follows if you are in scope.
September 3, 2026
SOC 2 Type I or Type II: What Your First Enterprise Deal Actually Requires
A SOC 2 report is an accountant's opinion, not a certificate. This guide explains Type I versus Type II and why timing usually decides which one your deal needs.
August 19, 2026
Incident Management: Building a Process You'll Actually Follow
Everyone agrees incident management matters, until an incident hits and the process is forgotten. This guide shows how to build one your team will actually follow.
July 15, 2026
ISO 27001 Clause 8: putting the plan into action
Clause 6 gives you the plan, Clause 8 is where you run it. Four workstreams keep your ISMS running week to week and give a Stage 2 auditor the evidence they follow.
June 30, 2026
ISO 27001 Clauses 6 & 8: planning and executing your risk management
Clause 6 defines how your organisation identifies, scores, and treats information security risk. Clause 8 is where you run it and keep the evidence.
June 19, 2026
ISO 27001 Clause 10.2: nonconformity and corrective action
If you're building or running an ISMS, problems will surface. Clause 10.2 is the clause that determines whether your organisation learns from it or repeats it.
May 26, 2026
How to build an asset inventory that holds up under audit
Most organisations list their tools. Auditors want documented ownership, classification, and lifecycle management. This guide shows you the difference.
May 20, 2026
ISO 27001 Clause 4: how to perform a context analysis
A practical guide to ISO 27001 Clause 4: how to analyse your organisation's context, define your ISMS scope, identify interested parties, and produce the documentation that auditors expect.
March 3, 2026
ISO 27001 Chapters 4-10: the first steps in setting-up your ISMS
ISO 27001 clauses 4–10 set out the mandatory structure for building, operating, and certifying an ISMS. This explains what each clause requires you to document, evidence, and maintain.
March 3, 2026