§ 0121 articles
01
Security Program & Risk
The NIST AI Risk Management Framework (AI RMF) explained
The NIST AI RMF is the leading voluntary framework for managing AI risk. See its four core functions and how to use it alongside the EU AI Act and ISO 42001.
June 13, 2026
5 min read
→025 min read
Security Program & Risk
AI governance: framework, documentation, and how to start
AI governance is how an organization controls the AI it builds and uses. See what it covers, the documentation it requires, and a practical way to start.
June 13, 2026
5 min read
→035 min read
Security Program & Risk
The EU AI Act explained: risk tiers, obligations, and timeline
The EU AI Act is the first comprehensive law on artificial intelligence. See how its risk tiers work, what high-risk providers must do, and the timeline.
June 14, 2026
6 min read
→046 min read
Security Program & Risk
ISO 42001: the AI management system standard, explained
ISO 42001 is the first certifiable standard for an AI management system, the AI equivalent of ISO 27001. See what it covers and how it fits the EU AI Act.
June 14, 2026
11 min read
→0511 min read
Security Program & Risk
Shadow AI: the risk of unsanctioned AI use, and how to manage it
Shadow AI is the unsanctioned use of AI tools by employees, and a fast-growing data risk. See why it happens and how to manage the risk it creates.
June 14, 2026
11 min read
→0611 min read
Security Program & Risk
What is a virtual CISO (vCISO), and when do you need one?
A virtual CISO gives you senior security leadership on a fractional basis. See what the role covers, how it differs from a full-time CISO, and when it fits.
June 11, 2026
10 min read
→0710 min read
Security Program & Risk
NIS2 explained: who is in scope, what it requires, and the deadlines
NIS2 raises the cybersecurity baseline across 18 EU sectors and holds management personally accountable. See who it covers, what it demands, and what to do.
June 10, 2026
15 min read
→0815 min read
Security Program & Risk
Risk assessment: how to run one step by step
A risk assessment is the foundation of a serious security program; without it you invest at random. See how to run one step by step and turn it into a plan.
Jun 16, 2026
11 min read
→0911 min read
Security Program & Risk
Cyber risk management: from assessment to decision
A risk assessment tells you where you are exposed. Risk management is what you do about it. See how to run risk as a continuous process, not a one-off doc.
Jun 16, 2026
11 min read
→1011 min read
Security Program & Risk
Business continuity and disaster recovery (BCP and DR)
When a system goes down, the question is how fast you recover. See what a business continuity plan and a disaster recovery plan are, and how to build each.
Jun 16, 2026
11 min read
→1111 min read
Security Program & Risk
Vendor risk management (third-party risk)
Your security is only as strong as your vendors' security. See why third-party risk keeps growing and how to manage it before a partner's weakness is yours.
Jun 16, 2026
9 min read
→129 min read
Security Program & Risk
ISMS: the information security management system
An ISMS turns security from a pile of tools into a system you can actually manage. See what an ISMS is, what it rests on, and why ISO 27001 is built on it.
Jun 16, 2026
10 min read
→1310 min read
Security Program & Risk
ISO 27001 Annex A: 93 controls in four themes
Annex A is the catalog of security controls ISO 27001 relies on. See how it splits into four themes, what the controls cover, and how to choose yours.
Jun 16, 2026
10 min read
→1410 min read
Security Program & Risk
The Statement of Applicability (SoA) in ISO 27001
The Statement of Applicability is a core ISO 27001 document. See what the SoA contains, why auditors check it first, and how to produce one correctly.
Jun 16, 2026
10 min read
→1510 min read
Security Program & Risk
DORA compliance checklist for financial entities
DORA has applied across the EU financial sector since January 2025 and rests on five pillars. This checklist turns them into work you can assign and track.
May 22, 2026
12 min read
→1612 min read
Security Program & Risk
NIS2 vs DORA: which one applies to you?
Two EU cybersecurity rules overlap but are not identical. NIS2 is broad; DORA is the financial-sector specialist. Here is how to tell which one governs you.
May 20, 2026
12 min read
→1712 min read
Security Program & Risk
ISO 27001 certification: the engineering path to the certificate
ISO 27001 certifies that you manage information security as a governed, ongoing process. See what it involves, how it runs, and why security comes first.
May 18, 2026
13 min read
→1813 min read
Security Program & Risk
SOC 2 compliance: a technical readiness guide
A SOC 2 report tells customers you have security controls and follow them. See what it covers, how Type I and Type II differ, and how to get ready honestly.
May 12, 2026
12 min read
→1912 min read
Security Program & Risk
SOC 2 vs ISO 27001: which should you do first?
Both prove you take security seriously: one a US attestation, the other a global certification. The right first move depends on who you sell to. Here is how.
May 10, 2026
13 min read
→2013 min read
Security Program & Risk
SOC 1 vs SOC 2 vs SOC 3: what is the difference?
Three reports, one confusing scheme. SOC 1 covers financial controls, SOC 2 security, SOC 3 public proof. See which one a customer is really asking for.
May 8, 2026
13 min read
→2113 min read
Security Program & Risk
SOC 2 is a floor, not a finish line
A clean SOC 2 report tells a customer you have controls. It does not tell an attacker to stay out. Here is the gap between passing an audit and being secure.
Apr 16, 2026
11 min read
→11 min read