Insights

Standards, local regulation and management practice, explained by the people who implement them.

We published our report on AI governance

Eighteen pages covering the risk assessment, the applicable regulatory framework and the ISO/IEC 42001 governance model. Free download.

Read more

Governing AI with rigour: what ISO/IEC 42001 actually requires

The first certifiable standard for artificial intelligence management systems does not ask you to slow AI down: it asks you to know what is being used, who answers for it, and what happens when it fails.

Read more

ISO 37001 and 37301: two standards, one system

How to design an integrity and compliance framework without duplicating structures, committees or documentation. What the two standards share and where they diverge.

Read more

AEO and ISO 28000: the security that enables trade

What Authorised Economic Operator status means for an exporter, how it relates to ISO 28000, and how much real work sits behind it.

Read more

Attack surface: what you do not know you expose

Findings that repeat across ASM monitoring of mid-sized organisations, and why they almost always turn up in assets nobody remembered having.

Read more

Controlled phishing: measure before you train

Why assessing human exposure changes the design of the awareness programme, and how to run a simulated exercise without breaking the team’s trust.

Read more

The 93 controls and the “we comply with almost everything” trap

Why a binary self-assessment of ISO/IEC 27001 always returns an optimistic result, and what changes when you measure maturity instead of presence.

Read more

your business partner

Protecting you today, innovating for tomorrow