Cybersecurity Briefings
Short, practical notes on cyber risk, regulation and assurance, each drawn from a question raised in an advisory conversation and addressed in terms a board or senior leader can act on.
Get new briefings in your inbox as they are published.
Board Assurance over CRA Reporting Readiness
From 11 September 2026, Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting product security. Boards need assurance that management can meet these obligations, fifteen months before the CRA's main requirements apply in December 2027.
The Cyber Security and Resilience Bill Puts UK Boards on Notice
The Cyber Security and Resilience Bill is the UK's answer to many of the same cyber resilience problems addressed by the EU's NIS2 Directive, which does not apply in the UK after Brexit. It updates the Network and Information Systems Regulations 2018 and is moving through its final stages in Parliament. It brings managed service providers, data centres and large electricity load controllers into UK cyber regulation for the first time, with penalties reaching 4% of worldwide turnover for the most serious breaches.
Governing the NIS2 Gaps That Remain at Programme Close
A NIS2 programme may reach its planned end date with some findings still open. Supplier negotiations can take longer than expected, technical remediation may depend on wider investment, and new gaps can emerge while delivery is under way. Extending the programme until every issue disappears may be impractical because the obligations, systems and risk environment continue to change.
A NIS2 Programme Should Leave an Operating Model Behind
When a NIS2 programme closes, the steering committee stands down and the programme team disperses. The regulatory obligations continue: controls require ongoing verification and evidence, risk assessments require refreshing, the incident notification capability requires testing, and the management body needs reporting to exercise oversight. Each of these needs to be designed, owned and handed over before the programme closes.
Governing a Compliance Platform
Compliance platforms like Drata centralise the control framework, evidence and ownership structure that an auditor interrogates. Their value depends entirely on whether what is in them reflects the organisation's actual control environment.
Deciding What the Board Needs to Know About Cyber Risk
A board cannot delegate accountability for the adequacy of the information on which it oversees material cyber risk. Management may develop and produce the reporting, but the board must determine whether it supports the judgements the board is required to make. Where the board never exercises that accountability, its oversight is defined by management by default.
The Governance Foundations of a NIS2 Programme
NIS2 places substantive, ongoing obligations on the management body. Building a compliance position that meets them requires a governed programme, with a mandate, a defined scope and formal close conditions. Organisations that treat NIS2 as a list of controls to check off will find the position they have built is difficult to demonstrate and harder to sustain.
ISO 27001 Certification and NIS2 Supervisory Scrutiny
ISO 27001 certification demonstrates that a management system was in place and conformed to the standard at the point of audit. NIS2 supervisory scrutiny asks a different set of questions: whether specific obligations under the directive are met at the time of inspection, including management body accountability, incident notification readiness and supply chain security in the form the directive requires.
The Scope Decision Behind a Credible NIS2 Programme
A programme scoped too broadly cannot be delivered in time. One scoped too narrowly produces gaps that surface during supervisory inspection rather than during the programme. Both result from the same mistake: treating regulatory scope as programme scope rather than as its starting point.
The Human Oversight Gap in AI Deployment
For high-risk AI systems, the AI Act requires effective human oversight and places a specific obligation on deployers to assign that oversight to individuals with the necessary competence, training, authority and support. Greater system autonomy does not reduce that obligation.
NIS2 Is Not One Rulebook Across Europe
NIS2 is a European directive, not a regulation. Unlike a regulation, it does not apply identically across all EU Member States. Each Member State must enact its own implementing legislation, and scope, supervision and enforcement can differ materially between jurisdictions.
Starting a NIS2 Programme Without Knowing Your Position
Most organisations that are in scope for NIS2 cannot yet answer three questions with confidence: which entities are in scope and under which national law, whether the governance conditions for a programme exist, and what scale of work lies ahead. Commissioning a programme without those answers produces a programme that either over-corrects or addresses the wrong things.
ISO 42001 Certification and EU AI Act Obligations
ISO 42001 provides a framework for managing AI risk through a documented management system. The EU AI Act imposes specific obligations on organisations that develop or deploy high-risk AI systems: conformity assessment before deployment, system-level transparency requirements and registration. These are product and deployment obligations.
The CRA Makes EU Market Access Conditional on Product Cybersecurity
The Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements sold in the EU. Products that do not meet those requirements cannot carry the CE marking and cannot be placed on the EU market. The compliance question is a market access question.
NIS2 Makes Cybersecurity a Leadership Duty
NIS2 does not only impose obligations on the security function. Article 20 places specific requirements on the management body: to approve the cybersecurity risk management measures the organisation adopts, to oversee their implementation, and to follow cybersecurity training. These obligations sit with senior leaders directly and cannot be discharged by the CISO or delegated to a technical team.
When a Fractional CISO Is the Right Appointment
The CISO appointment is often approached as a headcount question. The prior question is what governance structure cybersecurity leadership requires, and whether a permanent appointment is proportionate to the organisation's scale, risk profile and current circumstances.
Zero Trust and Cloud Security Assurance
Boards approve cloud migrations. They rarely have equivalent visibility into the access governance model that determines who can reach the workloads afterwards, or who is accountable for it.