Blog

Field notes from the SMB security front line.

Practical writing on cybersecurity for SMBs — NIS2, DORA, GDPR, vCISO, training, audit. Written by practitioners, not marketers.

All articles

27 posts and counting.

Two technicians in blue coveralls at an industrial control-room console, one facing banks of process monitors and the other standing at a panel of illuminated switches.

NIS2·

NIS2 and the CRA: two clocks on one factory

NIS2 regulates the plant you run. The CRA regulates what leaves it. Two 24-hour clocks, two different triggers — and in most factories, no owner.

8 min read · Sylvio Sorel

A compliance officer reads a bound filing at a desk under a lamp at night, numbered ring binders lined up behind him.

DORA·

Your DORA register got accepted. Now supervisors read it.

Two DORA register of information filings in, 'accepted' means the file parsed. What supervisors now read from it, and what to fix before 31 December.

6 min read · Sylvio Sorel

Four white ring binders standing upright in a wooden crate, their spines hand-labelled — the physical evidence pack an auditor actually reads.

ISO 27001·

One ISMS, three regulators: the same nine documents

NIS2, DORA and your ISO auditor ask for the same nine documents — and reject them for three different reasons. Here is the pack, mapped.

7 min read · Sylvio Sorel

Three colleagues at a dark meeting table reviewing a document in a folder; one holds a pen over the page while another points to a line on it.

Vendor Risk Management·

You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.

A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

8 min read · Sylvio Sorel

A team reviewing AI governance documentation together at a desk in a bright modern office.

ISO 42001·

ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does

ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

5 min read · Sylvio Sorel

An engineer working on a laptop beside a wiring harness assembly rig in an electronics manufacturing facility.

Cyber Resilience Act·

CRA reporting is live. You may be the manufacturer.

CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

7 min read · Sylvio Sorel

An open pocket watch resting in an open hand — the reporting clocks that start before a company knows the scope of an incident.

Incident Response·

One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72

Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

7 min read · Sylvio Sorel

A 3D-rendered white robot with an AI badge working at a laptop, illustrating the EU AI Act Article 50 chatbot disclosure obligation.

AI Act·

On 2 August, Your Chatbot Must Say It's a Bot. The AI Deadline the Omnibus Didn't Move.

Everyone heard the AI Act was delayed sixteen months. Article 50 wasn't. From 2 August 2026, your chatbot must say it's a bot — fines up to €15M or 3%.

5 min read · Sylvio Sorel

A brass padlock and a rolled-up banknote resting on a computer keyboard.

Ransomware·

Friday 18:47 to Monday 08:00: Anatomy of a Ransomware Attack on a 50-Person Company

An hour-by-hour reconstruction of a ransomware attack on a 50-person company: from the Friday click to the Monday ransom note, and where it is really decided.

5 min read · Sylvio Sorel

A small team calmly working an incident response plan at night.

Incident Response·

Incident Response Without a SOC: The 5-Step Playbook a 50-Person Company Can Actually Run

A practical 5-step incident response playbook for SMEs without a SOC — prepare, detect, contain, recover, report. Mapped to NIST 800-61r3, NIS2 and CRA clocks.

7 min read · Sylvio Sorel

A senior advisor watches a colleague walk through a quarterly review at a whiteboard — the kind of milestone review where a board holds its vCISO to account.

Virtual CISO·

What a vCISO Actually Does in Month 1, Month 3, and Month 12 — A Timeline Your Board Can Hold Us To

What a virtual CISO actually delivers in month 1, month 3, and month 12 — a concrete milestone timeline SMB and mid-market boards can hold any provider to.

6 min read · Sylvio Sorel

Two executives reviewing a document together at a meeting table — the considered evaluation a vCISO hire deserves.

Virtual CISO·

10 Questions to Ask Before You Hire a vCISO — And the Answers That Should End the Meeting

Ten questions that separate a real vCISO from a templated invoice — and the red-flag answers to listen for. A vendor-neutral buyer's guide for SMB and mid-market boards.

7 min read · Sylvio Sorel

An aerial view of two paths crossing in a green field, a cyclist pausing at the intersection — which regulatory route applies to you.

NIS2·

NIS2 vs DORA vs ISO 27001: which ones apply to you

NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

7 min read · Sylvio Sorel

A management team in a glass-walled boardroom discussing AI governance and EU AI Act readiness.

AI Act·

AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer

The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.

8 min read · Sylvio Sorel

A fintech operator reviewing a payments dashboard — DORA applies to non-bank financial entities across the EU.

DORA·

You're Not a Bank. DORA Still Applies. And the First Inspections Have Started.

DORA has been fully applicable since 17 January 2025. Most non-banks read that as someone else's problem. In 2026, that misread becomes a supervisory problem.

5 min read · Sylvio Sorel

A chess board mid-game — boards now have to make calculated, defensible moves on NIS2.

NIS2·

NIS2 Enforcement Has Started: 8 Questions Your Board Must Answer in the First 30 Days

NIS2 is now enforced across most of the EU. Article 20 puts directors personally on the hook. Eight questions every board must answer in 30 days.

7 min read · Sylvio Sorel

A keyboard and a phishing hook icon — the entry point most attacks rely on.

Training & Awareness·

The Human Firewall: How to Turn Your Employees from Your Weakest Link into Your First Line of Defense

Over 90% of breaches start with human error. Treat employees as a security control to invest in, not a problem to mitigate — here is how.

7 min read · Sylvio Sorel

Compliance binders next to a padlock — paperwork is not protection.

Compliance·

Compliance Is Not Security: What GDPR, PCI DSS, and NIS2 Won't Protect You From

Passing audits is not the same as being defensible. Where the major frameworks stop, what attackers exploit anyway, and how to bridge the gap.

7 min read · Sylvio Sorel

Vendor Risk Management

Vendor Risk Management·

Vendor, Partner, Breach: How Third-Party Relationships Are Your Biggest Security Blind Spot

Most SMBs cannot name their critical suppliers, let alone assess them. Why third-party access is the most common breach path — and how to manage it without enterprise overhead.

8 min read · Sylvio Sorel

Cloud Security

Cloud Security·

Remote Work, Real Risk: How to Secure a Distributed Team Without a Big IT Budget

Distributed teams demolished the traditional perimeter. Here is the SMB-sized stack — MFA, EDR, ZTNA basics — that delivers most of the protection without enterprise spend.

7 min read · Sylvio Sorel

Server lights blinking in a dark rack — the indicators of compromise that hide in plain sight.

Incident Response·

5 Signs Your Business Has Already Been Compromised (And Doesn't Know It)

Average breach dwell time is weeks to months. Five concrete indicators of silent compromise — and what to do the moment you spot one.

4 min read · Sylvio Sorel

Cyber Insurance

Cyber Insurance·

Cyber Insurance Isn't Enough: What Insurers Won't Tell You About Coverage Gaps

Cyber insurance pays out far less than buyers expect. Five critical coverage gaps SMBs discover too late — and how to use insurance properly.

8 min read · Sylvio Sorel

Governance

Governance·

Do You Actually Own Your Data? A Plain-English Guide to Data Governance for SMBs

You hold the data, but the law treats you as a custodian, not an owner. Five questions every SMB must answer to be defensible under GDPR, NIS2, and beyond.

6 min read · Sylvio Sorel

A 90-day roadmap with milestones — security as a project plan, not a destination.

Roadmap·

Your 90-Day Cybersecurity Roadmap: From Vulnerable to Confident

A pragmatic, three-month plan for SMBs starting from scratch. Quick wins month one, the human firewall month two, governance month three.

6 min read · Sylvio Sorel

A pile of euro notes — what a single breach actually costs a small business.

Data Breach·

The $50K Mistake: What a Single Data Breach Really Costs a Small Business

A data breach is not a technology failure — it is a business-ending financial event. Where the €50k-€150k goes, line by line, and the prevention math.

6 min read · Sylvio Sorel

Streams of data over a dark background — the modern threat landscape that no longer skips small businesses.

Cyber Risk·

Why Small Businesses Are Now the #1 Target for Cybercriminals (And What to Do About It)

Over 43% of cyberattacks now hit SMBs and only 14% are prepared. Why attackers chose this market — and the five-step response that closes the gap.

3 min read · Sylvio Sorel