Resources

Learn to prove trust.

Guides, playbooks and field notes on getting audit-ready across every framework, written by people who've been on both sides of the audit table.

Guide

ISO 27017 explained: proof your cloud is actually secure

Everyone runs on the cloud. Almost nobody can prove they run on it securely. ISO 27017 is the standard that turns 'trust us, it is in AWS' into something an auditor will sign. Here is what it asks, and why your monitoring already does most of it.

8 min read
Blog

The cloud shared-responsibility model, in plain English

CSC, CSP, shared. Three little labels that decide whether your next cloud audit is a formality or a fire drill. Here is what they mean, and why writing them down is the whole game.

6 min read
Blog

You have ISO 27001. ISO 27017 is mostly already done.

If you already hold ISO 27001, adding a cloud-security credential sounds like another year of work. It is not. 27017's controls are the same 27002:2022 set you already run, plus four cloud-specific ones. Here is the honest gap.

5 min read
Blog

Controller or processor? The ISO 27701 question that decides everything

Before a single privacy control applies, ISO 27701 asks one deceptively simple question: are you a controller, a processor, or both? Get the answer right and the whole programme falls into place. Get it wrong and you protect the wrong things.

6 min read
Blog

You have ISO 27001. ISO 27701 is closer than you think.

Adding a privacy certification on top of your security one sounds like a second mountain. It is more like a well-marked extension of the trail you already climbed. Here is exactly what carries over and what is genuinely new.

5 min read
Guide

ISO 22301 explained: business continuity that survives a real disruption

Most 'business continuity plans' are a document nobody has opened since the last audit. ISO 22301 is the antidote. Here is what it actually asks of you, in plain English, and why your customers keep asking whether you have it.

9 min read
Playbook

MTPD, RTO, RPO: the three numbers at the heart of a BIA

Three acronyms, one job: telling you how bad a disruption is allowed to get before someone important starts shouting. Get these numbers right and the rest of business continuity basically writes itself.

6 min read
Blog

You have ISO 27001. Here's how much of ISO 22301 you've already done.

Business continuity sounds like a whole new mountain to climb. Good news: if you already hold ISO 27001, you are further up it than you think. Here is what carries over for free and what genuinely needs building.

5 min read
Guide

Why threat intelligence belongs in your compliance programme

A passed audit proves your controls existed on paper. It says nothing about what attackers are trying this week. Here is why threat intelligence is the missing half of real security, and why we built a whole command centre for it right inside the platform.

8 min read
Guide

Which compliance framework does your business actually need?

SOC 2? ISO 27001? HIPAA? Everyone has an opinion and most of them are wrong for you. A no-nonsense guide to picking the one certificate that actually unblocks your next deal, instead of collecting all of them like Pokemon.

11 min read
Blog

The real cost of doing compliance in spreadsheets

Spreadsheets feel free. They are not. The bill just arrives later, in the form of your best engineer's weekend and a file named evidence_final_ACTUALFINAL_v9.xlsx. Let us add it up honestly.

8 min read
Blog

How a compliance report quietly closes your biggest deals

Nobody buys your product because you have SOC 2. But plenty of people refuse to buy because you don't. Compliance is rarely the reason you win, and often the reason you lose. Here is how to flip that.

7 min read
Playbook

The security questionnaire from hell (and how to answer it in an afternoon)

300 questions. A spreadsheet with merged cells. A deadline of 'end of week.' The security questionnaire is where deals go to nap. Here is how to wake them up fast, without inventing answers you cannot back up.

9 min read
Guide

Your first audit, demystified: what actually happens in the room

The word 'audit' triggers a very specific fear, somewhere between a tax inspection and a driving test. The reality is calmer, more human, and entirely survivable. Here is what actually happens, and how to walk in ready.

10 min read
Guide

Security is a team sport: turning your people into your best control

You can buy the best tools money can offer and still get undone by one tired person clicking one convincing link. Your people are either your weakest control or your strongest. The difference is almost entirely training.

8 min read
Guide

SOC 2 or ISO 27001: which one should you actually do first?

The eternal question, usually answered with a shrug and a link to a comparison table. Let us skip the table and answer the real question: which one gets your specific deals unstuck faster, and why doing one makes the other easy.

9 min read
Blog

Why continuous compliance beats the annual scramble every single time

The traditional compliance year has a shape, and the shape is a cliff. Eleven months of quiet drift, then one month of frantic screenshotting. There is a calmer way to live, and it does not involve screenshotting settings at midnight.

6 min read
Playbook

An evidence-automation playbook for teams that would rather ship

Collecting evidence by hand is the compliance equivalent of doing dishes with a single fork. It works, technically, and it will consume your entire life. Here is how to automate the boring 80 percent so your team can get back to building.

10 min read
Guide

Data residency, explained without the jargon (and without the eye-glaze)

'Where does our data live?' sounds like a simple question. Then a customer in Frankfurt asks it in a contract, and suddenly it is a project. Here is what data residency really means, and why it is quietly a sales feature.

6 min read
Blog

NIS2: what actually changed, and the awkward question for your board

NIS2 quietly turned cybersecurity from an IT concern into a board responsibility, with personal accountability attached. If your directors think this is still someone else's problem, this one is for them.

7 min read
Guide

Getting ahead of AI governance with ISO 42001 (before your customers ask)

'How do you govern your AI?' is showing up in more security questionnaires every quarter. ISO 42001 is a much better answer than a nervous shrug. Here is what the first AI management system standard actually asks for.

9 min read
Guide

The EU AI Act, explained without the legalese

The world's first comprehensive AI law is here, it is long, and it is written in fluent Regulation. Here is what it actually means for your company, sorted by the only thing that matters: how risky your AI is.

9 min read
Playbook

An EU AI Act readiness playbook: seven steps to a defensible programme

You cannot comply with a 100-plus-article regulation by reading it cover to cover and hoping. You need a sequence. Here are seven concrete steps that take you from 'we should probably look at this' to a programme you could actually defend.

10 min read
Blog

EU AI Act vs ISO 42001: do you need both?

One is a law you must obey. The other is a certification you choose to earn. They are not competitors, they are dance partners, and running them together is far less work than running them apart.

6 min read
Guide

Cyber Essentials vs Cyber Trust: choosing Singapore's CSA marks

Singapore's Cyber Security Agency offers two marks, and the names do not make the difference obvious. One is a solid baseline, the other a tiered mark of distinction. Here is which one fits where you are, without the guesswork.

9 min read
Guide

The Data Protection Trustmark (DPTM): proving PDPA accountability

Complying with Singapore's PDPA is table stakes. Proving it, visibly, to customers and partners, is a competitive advantage. That is what the DPTM is for. Here is what it takes and why it is worth the effort.

8 min read
Playbook

The Philippines Data Privacy Act (RA 10173): a compliance playbook

The Philippines DPA is a real law with real teeth, including personal liability and a 72-hour breach clock. The National Privacy Commission has helpfully organised compliance into five pillars. Here is how to actually stand them up.

10 min read
Blog

One evidence set, many jurisdictions: compliance across Southeast Asia

Expanding across Southeast Asia means meeting Singapore's PDPA and DPTM, the Philippines DPA, and more, each with its own rules. Doing that as separate projects is a fast way to lose your mind. There is a much saner path.

6 min read