Resources
Articles, guides and checklists for the people who have to prove it.
Practical writing on DORA, NIS2 and ISO 27001 programmes — how requirements become scope, how scope becomes evidence, and what auditors actually ask for. No gated fluff; the useful things are free to read.
Latest
- FeaturedGuideDORANIS2ISO 27001· 4 min read
What a new framework version changes — and what it must never touch
A framework pack gets a new version. Which applicability decisions carry over, which need review, which are gone — and why the old adoption must stay frozen.
Read → - GuideISO 27001· 5 min read
ISO 27001 clause 9 without the slide deck: internal audit and management review on a derived posture
Clause 9 asks for monitoring, internal audit and management review. When posture is computed from records, the review is a delta between two frozen snapshots.
Read → - GuideNIS2· 5 min read
NIS2 incident reporting: the 24-hour, 72-hour and one-month path as a runbook, not a policy
Article 23 sets three deadlines and asks different questions at each. Who decides "significant", who notifies whom, and which records the answers come from.
Read → - ArticleDORANIS2ISO 27001· 4 min read
A backup restore drill is evidence — if you record it like one
DORA, NIS2 and ISO 27001 ask whether you can restore, not whether you back up. What turns a restore test into evidence: date, scope, control, the gap it found.
Read → - GuideDORA· 4 min read
The DORA register of information in 30 minutes: a walkthrough of the checklist
Run the register-of-information checklist with three people in half an hour: which records to open first, what "Partly" usually means, and what to do next.
Read → - ArticleDORANIS2ISO 27001· 5 min read
Four-eyes per flow: what a second approver actually changes — and when a single-admin tenant may switch it off
Segregation of duties is only real when the system refuses a self-approval. Which three flows carry it, what an approver may do, how an exception is audited.
Read → - ArticleDORANIS2ISO 27001· 4 min read
Evidence recency: why "twelve months" is not a rule, and what to measure instead
Auditors do not ask how old evidence is; they ask whether it still shows the control operating. Measure recency per control against its own review period.
Read → - GuideDORANIS2ISO 27001· 4 min read
Provider → service → function: the three links most third-party obligations read back to
DORA Art. 28, NIS2 Art. 21(2)(d) and ISO 27001 supplier controls all assume you know which provider delivers which service to which function. Model it once.
Read → - GuideDORANIS2ISO 27001· 5 min read
Applicability has five scopes — and "tenant-wide" is usually the wrong first answer
A requirement rarely applies to a whole organisation. Deciding applicability per asset, IT service, business solution or process makes "not applicable" hold up.
Read → - ChecklistDORA· PDF · 10 pages · 51 KB
DORA register of information — readiness checklist
The DORA register of information is a projection of records you already need — providers, services, functions, contracts. 18 questions on whether they exist.
Read → - GuideDORA· 5 min read
The DORA testing programme is a scoping problem before it is a testing problem
DORA Article 24 asks for a yearly, risk-based testing programme. The hard part is not the test: it is deriving scope from the inventory and closing every gap.
Read → - ChecklistNIS2· PDF · 18 pages · 72 KB
NIS2 Article 21 self-check
A checklist across governance, the ten Article 21(2) measure areas and Article 23 reporting — thirty-two questions, each with the record that proves the answer.
Read → - ArticleDORANIS2ISO 27001· 4 min read
Why a compliance percentage should never be typed into a box
A posture number somebody typed is a slide, not a fact. What deriving posture from adoption, applicability, coverage and evidence means — and why you freeze it.
Read → - GuideISO 27001· 5 min read
The Statement of Applicability is a decision log, not a checklist
ISO/IEC 27001 asks for the one thing most SoAs lack: the reason. Keeping applicability, justification and implementation status as records that outlive audits.
Read → - GuideNIS2· 6 min read
NIS2 Article 21: ten measure areas, one inventory — where to start when the deadline has already passed
NIS2 Article 21 lists ten measure areas but never says which system they protect. Start from the inventory and the management-body decision, not a policy pack.
Read → - GuideDORA· 2 min read
The DORA register of information: what the ESAs actually ask for, and where the data has to come from
The DORA register is a prescribed template, not a product feature. Which linked records — providers, services, functions — must exist to fill it with no sheet.
Read → - WhitepaperDORA· PDF · 16 pages · 69 KB
DORA readiness self-assessment
A structured self-assessment across the five DORA pillars — ICT risk, incidents, testing, third-party risk, information sharing — with the record behind each.
Read → - TemplateISO 27001· XLSX · 14 KB
Statement of Applicability data sheet
A data sheet for the ISO/IEC 27001:2022 Statement of Applicability: all 93 Annex A control ids, applicability with justification, scope, status and evidence.
Read →
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.