
Cyber Resilience Act·
CRA reporting is live. You may be the manufacturer.
CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

Incident Response·
One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72
Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

Ransomware·
Friday 18:47 to Monday 08:00: Anatomy of a Ransomware Attack on a 50-Person Company
An hour-by-hour reconstruction of a ransomware attack on a 50-person company: from the Friday click to the Monday ransom note, and where it is really decided.

Incident Response·
Incident Response Without a SOC: The 5-Step Playbook a 50-Person Company Can Actually Run
A practical 5-step incident response playbook for SMEs without a SOC — prepare, detect, contain, recover, report. Mapped to NIST 800-61r3, NIS2 and CRA clocks.

Incident Response·
5 Signs Your Business Has Already Been Compromised (And Doesn't Know It)
Average breach dwell time is weeks to months. Five concrete indicators of silent compromise — and what to do the moment you spot one.