Blog
Field notes from the SMB security front line.
Practical writing on cybersecurity for SMBs — NIS2, DORA, GDPR, vCISO, training, audit. Written by practitioners, not marketers.
All articles
27 posts and counting.

NIS2·
NIS2 and the CRA: two clocks on one factory
NIS2 regulates the plant you run. The CRA regulates what leaves it. Two 24-hour clocks, two different triggers — and in most factories, no owner.

DORA·
Your DORA register got accepted. Now supervisors read it.
Two DORA register of information filings in, 'accepted' means the file parsed. What supervisors now read from it, and what to fix before 31 December.

ISO 27001·
One ISMS, three regulators: the same nine documents
NIS2, DORA and your ISO auditor ask for the same nine documents — and reject them for three different reasons. Here is the pack, mapped.

Vendor Risk Management·
You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.
A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

ISO 42001·
ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does
ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

Cyber Resilience Act·
CRA reporting is live. You may be the manufacturer.
CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

Incident Response·
One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72
Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

AI Act·
On 2 August, Your Chatbot Must Say It's a Bot. The AI Deadline the Omnibus Didn't Move.
Everyone heard the AI Act was delayed sixteen months. Article 50 wasn't. From 2 August 2026, your chatbot must say it's a bot — fines up to €15M or 3%.

Ransomware·
Friday 18:47 to Monday 08:00: Anatomy of a Ransomware Attack on a 50-Person Company
An hour-by-hour reconstruction of a ransomware attack on a 50-person company: from the Friday click to the Monday ransom note, and where it is really decided.

Incident Response·
Incident Response Without a SOC: The 5-Step Playbook a 50-Person Company Can Actually Run
A practical 5-step incident response playbook for SMEs without a SOC — prepare, detect, contain, recover, report. Mapped to NIST 800-61r3, NIS2 and CRA clocks.

Virtual CISO·
What a vCISO Actually Does in Month 1, Month 3, and Month 12 — A Timeline Your Board Can Hold Us To
What a virtual CISO actually delivers in month 1, month 3, and month 12 — a concrete milestone timeline SMB and mid-market boards can hold any provider to.

Virtual CISO·
10 Questions to Ask Before You Hire a vCISO — And the Answers That Should End the Meeting
Ten questions that separate a real vCISO from a templated invoice — and the red-flag answers to listen for. A vendor-neutral buyer's guide for SMB and mid-market boards.

NIS2·
NIS2 vs DORA vs ISO 27001: which ones apply to you
NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

AI Act·
AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer
The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.

DORA·
You're Not a Bank. DORA Still Applies. And the First Inspections Have Started.
DORA has been fully applicable since 17 January 2025. Most non-banks read that as someone else's problem. In 2026, that misread becomes a supervisory problem.

NIS2·
NIS2 Enforcement Has Started: 8 Questions Your Board Must Answer in the First 30 Days
NIS2 is now enforced across most of the EU. Article 20 puts directors personally on the hook. Eight questions every board must answer in 30 days.

Training & Awareness·
The Human Firewall: How to Turn Your Employees from Your Weakest Link into Your First Line of Defense
Over 90% of breaches start with human error. Treat employees as a security control to invest in, not a problem to mitigate — here is how.

Compliance·
Compliance Is Not Security: What GDPR, PCI DSS, and NIS2 Won't Protect You From
Passing audits is not the same as being defensible. Where the major frameworks stop, what attackers exploit anyway, and how to bridge the gap.
Vendor Risk Management·
Vendor, Partner, Breach: How Third-Party Relationships Are Your Biggest Security Blind Spot
Most SMBs cannot name their critical suppliers, let alone assess them. Why third-party access is the most common breach path — and how to manage it without enterprise overhead.
Cloud Security·
Remote Work, Real Risk: How to Secure a Distributed Team Without a Big IT Budget
Distributed teams demolished the traditional perimeter. Here is the SMB-sized stack — MFA, EDR, ZTNA basics — that delivers most of the protection without enterprise spend.

Incident Response·
5 Signs Your Business Has Already Been Compromised (And Doesn't Know It)
Average breach dwell time is weeks to months. Five concrete indicators of silent compromise — and what to do the moment you spot one.
Cyber Insurance·
Cyber Insurance Isn't Enough: What Insurers Won't Tell You About Coverage Gaps
Cyber insurance pays out far less than buyers expect. Five critical coverage gaps SMBs discover too late — and how to use insurance properly.
Governance·
Do You Actually Own Your Data? A Plain-English Guide to Data Governance for SMBs
You hold the data, but the law treats you as a custodian, not an owner. Five questions every SMB must answer to be defensible under GDPR, NIS2, and beyond.

Roadmap·
Your 90-Day Cybersecurity Roadmap: From Vulnerable to Confident
A pragmatic, three-month plan for SMBs starting from scratch. Quick wins month one, the human firewall month two, governance month three.

Data Breach·
The $50K Mistake: What a Single Data Breach Really Costs a Small Business
A data breach is not a technology failure — it is a business-ending financial event. Where the €50k-€150k goes, line by line, and the prevention math.

Cyber Risk·
Why Small Businesses Are Now the #1 Target for Cybercriminals (And What to Do About It)
Over 43% of cyberattacks now hit SMBs and only 14% are prepared. Why attackers chose this market — and the five-step response that closes the gap.
Browse by topic
Where the writing lands, by theme.
Each topic links to the service or framework page where the analysis from these articles gets put into practice with our clients.
NIS2
Article 21 measures, three-stage notification, supply-chain security, board liability.
Visit pageDORA
Five pillars, four-hour reporting, third-party register, threat-led testing.
Visit pageGDPR
ROPA, DPIAs, data subject rights, breach response, processor contracts.
Visit pageISO 27001
Implementation, internal audit, certification — sized for SMBs, no enterprise bloat.
Visit pagevCISO
When a fractional security executive is the right call, and how to scope one.
Visit pageAwareness
Why annual e-learning fails, what continuous training looks like, how to measure it.
Visit page