Sharper thinking on cyber resilience
Explainers, articles, practical guides, threat briefings and composite case studies — on the frameworks, the threats, the technology and the real engagements behind cyber resilience. Written to be useful whether or not you ever talk to us.
DORA, explained: what it actually asks you to do
The Digital Operational Resilience Act has applied since January 2025. Five obligations, and the one that catches most firms out.
8 min read ExplainerNIS2: are you in scope, and what changes if you are
Broader sectors, tighter deadlines and personal accountability for management. How to work out whether it reaches you.
7 min read ExplainerIACS UR E26 and E27, explained for fleet operators
Two unified requirements that changed what a newbuild has to demonstrate. What they cover, who they bind, and what they mean for existing tonnage.
6 min read ExplainerCMMC 2.0 and the defence supply chain
What the levels mean, how it relates to NIST SP 800-171, and why the assessment is the easy part.
6 min read ExplainerThe NCSC Cyber Assessment Framework, explained
An outcome-based framework rather than a control checklist. Why that distinction changes what you have to produce.
6 min read ArticleWhy you cannot scan an OT network
The single most common way an IT security programme causes an industrial incident, and what to do instead.
6 min read ArticleCoverage is not a percentage
What ATT&CK mapping tells you, what it does not, and how a coverage number becomes misleading.
6 min read ArticleCertification assesses the facility. Custody follows the asset.
Why a vendor chain full of assessed facilities can still leak, and what has to be true instead.
5 min read ArticleWhat an AI agentic SOC actually means
A term doing a lot of work in a lot of marketing. What changes operationally, and what should not.
6 min read GuideTwelve questions to ask an MDR provider
The questions that separate providers quickly, including the three most will not answer straight.
7 min read GuidePreparing for a TPN assessment
What to do in the eight weeks before, and the three areas that most often cause findings.
6 min read GuideBuilding a third-party risk programme that survives contact with a regulator
Six steps, in the order that actually works, and the one most programmes skip.
7 min read Threat briefingInfostealers and the credential you never issued
Why the compromise that gets you may never touch a device you manage, and what to do about it.
5 min read Case studyComposite: a 40-vessel operator, the first ninety days
What changes, in what order, when a fleet with no OT visibility starts from one vessel class.
6 min read Case studyComposite: a manufacturer answering customer security schedules
How a bid activity staffed by operations people becomes a repeatable answer drawn from one evidence base.
5 min read ExplainerISO 27001 or SOC 2: which one, and when you need both
Two of the most requested procurement assurances, built for different audiences. How to choose, and when doing both is the cheaper path.
7 min read ExplainerThe EU AI Act, for security and risk teams
A risk-tiered law for anyone building or deploying AI. What it classifies, what it demands, and where it reuses your existing security work.
7 min read Article“We passed the pen test” is not a security posture
A clean pen test is a snapshot of one scope in one week. Why treating it as a grade quietly stops a programme improving.
6 min read ArticleCompliant is not the same as secure
You can pass every audit and still be breached. Why compliance and security diverge, and how to make one produce the other.
6 min read Threat briefingOT ransomware: when they take production and the data
Ransomware crews learned that stopped production pays faster than encrypted files. The double-extortion play against OT, and how to blunt it.
5 min read Threat briefingMFA fatigue and stolen session tokens
MFA stopped password reuse, so attackers stopped attacking the password. Two techniques that bypass MFA, and what actually closes them.
5 min read Case studyComposite: a regional bank getting DORA-ready in two quarters
A composite of DORA engagements: what a bank with a capable IT team but no resilience owner did first, and the order that worked.
6 min read Case studyComposite: a hospital group securing medical devices without downtime
A composite of healthcare engagements: bringing thousands of unmanaged medical devices into view without a scan that could disrupt care.
6 min readNothing matches that combination.
Questions, answered
What is the Learning Hub for?
Are the case studies real clients?
How current is the regulatory content?
Rather talk it through?
Thirty minutes, starting with your environment rather than our product.