Insights/Security Program & Risk

Security Program & Risk

Governance, risk, and compliance done as engineering: NIS2, DORA, ISO 27001, SOC 2, GDPR, risk assessment, and business continuity, with the audit as a by-product.
§ 0121 articles
01
Security Program & Risk
The NIST AI Risk Management Framework (AI RMF) explained
The NIST AI RMF is the leading voluntary framework for managing AI risk. This is what it is, its four core functions, and how to use it alongside the EU AI Act and ISO 42001.
June 13, 2026
11 min read
02
Security Program & Risk
AI governance: framework, documentation, and how to start
AI governance is how an organization controls the AI it builds and uses. This is what it covers, the documentation it requires, and a practical way to start.
June 13, 2026
11 min read
03
Security Program & Risk
The EU AI Act explained: risk tiers, obligations, and timeline
The EU AI Act is the first comprehensive law governing artificial intelligence. This is how its risk tiers work, what high-risk providers must do, the timeline, and the penalties.
June 14, 2026
12 min read
04
Security Program & Risk
ISO 42001: the AI management system standard, explained
ISO 42001 is the first certifiable standard for an AI management system, the AI equivalent of ISO 27001. This is what it covers, who needs it, and how it fits with the EU AI Act.
June 14, 2026
11 min read
05
Security Program & Risk
Shadow AI: the risk of unsanctioned AI use, and how to manage it
Shadow AI is the unsanctioned use of AI tools by employees, and it is one of the fastest-growing data risks. This is why it happens, the risks it creates, and how to manage it.
June 14, 2026
11 min read
06
Security Program & Risk
What is a virtual CISO (vCISO), and when do you need one?
A virtual CISO gives you senior security leadership on a fractional basis. Here is what the role covers, how it differs from a full-time CISO or a consultant, and the situations where it is the right choice.
June 11, 2026
9 min read
07
Security Program & Risk
NIS2 explained: who is in scope, what it requires, and the deadlines
NIS2 raises the cybersecurity baseline across 18 sectors of the EU economy, and it holds management personally accountable. Here is who it covers, what it demands, and what to do now.
June 10, 2026
15 min read
08
Security Program & Risk
Risk assessment: how to run one step by step
A risk assessment is the foundation of any serious security program. Without it you invest at random. Here is how to run a risk assessment step by step and turn it into a plan.
Jun 16, 2026
12 min read
09
Security Program & Risk
Cyber risk management: from assessment to decision
A risk assessment tells you where you are exposed. Risk management is what you do about it. Here is how to run risk as a continuous process, not a one-off document.
Jun 16, 2026
12 min read
10
Security Program & Risk
Business continuity and disaster recovery (BCP and DR)
When a system goes down, the question is not whether but how fast you get back to work. Here is what a business continuity plan and a disaster recovery plan are, and how to build them.
Jun 16, 2026
12 min read
11
Security Program & Risk
Vendor risk management (third-party risk)
Your security is only as strong as your vendors' security. Here is why third-party risk keeps growing, and how to manage it before a partner's weakness becomes yours.
Jun 16, 2026
11 min read
12
Security Program & Risk
ISMS: the information security management system
An ISMS turns security from a pile of tools into a system you can actually manage. Here is what an ISMS is, what it rests on, and why it is the heart of an ISO 27001 certificate.
Jun 16, 2026
12 min read
13
Security Program & Risk
ISO 27001 Annex A: 93 controls in four themes
Annex A is the catalog of security controls that ISO 27001 relies on. Here is how it is organized into four themes, what the controls cover, and how you choose the ones that apply to you.
Jun 16, 2026
11 min read
14
Security Program & Risk
The Statement of Applicability (SoA) in ISO 27001
The Statement of Applicability is one of the most important documents in ISO 27001. Here is what the SoA contains, why auditors look at it first, and how to produce one correctly.
Jun 16, 2026
11 min read
15
Security Program & Risk
DORA compliance checklist for financial entities
DORA has applied across the EU financial sector since January 2025. It rests on five pillars. This checklist turns them into concrete work you can assign and track.
May 22, 2026
13 min read
16
Security Program & Risk
NIS2 vs DORA: which one applies to you?
Two EU cybersecurity rules, overlapping but not identical. NIS2 is broad. DORA is the financial sector specialist. Here is how to tell which governs your organization.
May 20, 2026
13 min read
17
Security Program & Risk
ISO 27001 certification: the engineering path to the certificate
ISO 27001 certifies that you manage information security as a governed, ongoing process. Here is what it involves, how the certification runs, and why the security has to come before the certificate.
May 18, 2026
13 min read
18
Security Program & Risk
SOC 2 compliance: a technical readiness guide
A SOC 2 report tells customers you have security controls and follow them. Here is what the report covers, the difference between Type I and Type II, and how to get ready without faking it.
May 12, 2026
12 min read
19
Security Program & Risk
SOC 2 vs ISO 27001: which should you do first?
Both prove you take security seriously. One is a US attestation, the other an international certification. The right first move depends on who you sell to. Here is how to choose.
May 10, 2026
13 min read
20
Security Program & Risk
SOC 1 vs SOC 2 vs SOC 3: what is the difference?
Three reports, one confusing naming scheme. SOC 1 is about financial controls, SOC 2 about security, SOC 3 about showing the world. Here is which one a customer is actually asking for.
May 8, 2026
13 min read
21
Security Program & Risk
SOC 2 is a floor, not a finish line
A clean report tells a customer you have controls. It does not tell an attacker to stay out.
Apr 16, 2026
11 min read