Thinking

Practical guidance.
No theory for its own sake.

Articles on compliance, business continuity, and information security, written for the people who have to make it work in practice.

ISO 27001
June 2026

How to Prepare for an ISO 27001 Stage 1 Audit

What the certification body reviews at Stage 1, the findings that catch organisations out, from contradictory SoAs to the internal audit impartiality trap, and how to walk in ready.

Read the article →
ISO 27001
June 2026

Gap Analysis vs Audit: Which One Does Your Organisation Need?

The word audit covers four different activities, and buying the wrong one wastes money in both directions. The full taxonomy, ending in a decision you can make in one pass.

Read the article →
Data Protection
June 2026

What Happens If You Miss a DSAR Deadline

The consequence spectrum from ICO complaint to the litigation amplifier, the new statutory complaints route from June 2026, and the first 48 hours after a miss.

Read the article →
Business Continuity
June 2026

What to Expect from a Business Continuity Desktop Exercise

The session shape, who must be in the room, what good scenarios and outputs look like, and what separates a useful exercise from theatre.

Read the article →
Risk Management
May 2026

Four attacks a week. The threat has changed. Has your risk register?

The NCSC is handling four nationally significant cyber incidents every week, with nation-state actors now behind the majority of the most serious cases. If your risk register has not been updated to reflect the current threat landscape, the gap between document and reality is growing.

Read the article →
Cyber Resilience
November 2025

The Cyber Security and Resilience Bill: A Strategic Guide for Practical Action

New legislation is coming. Organisations that treat this as a compliance exercise will miss the point. Here is what the Bill actually requires and how to get ahead of it.

Read the article →
Governance
September 2025

Navigating the AI Revolution in Governance: A Leadership Guide

AI is changing what governance means in practice. This is a guide for leaders who need to make decisions now, not wait for the regulatory landscape to settle.

Read the article →
ISO 27001
October 2025

From Risk Registers to Real Compliance

Most risk registers are documents that satisfy an auditor, not tools that drive decisions. Here is what the difference looks like in practice and how to close the gap.

Read the article →
Business Continuity
February 2026

Crisis Communication: When Better Tools Feel Like Progress

Most organisations do not struggle with crisis communications because they lack tools. They struggle because the tools are not connected to clear decision-making frameworks.

Read the article →
Cyber Security
January 2026

Post-Quantum Cryptography: What Organisations Need to Know Now

The quantum threat to current encryption standards is not theoretical. The transition window is open now, and organisations that wait will face a harder migration later.

Read the article →
Cyber Security
July 2025

AI Is Redefining Authentication: What Every CEO and CIO Should Know

AI-powered attacks are breaking traditional authentication methods, from deepfaked biometrics to intercepted one-time passwords. What modern security and ISO 27001 compliance now require.

Read the article →
Cyber Security
May 2025

Emerging Phishing Trends: Is Your Business Prepared? (And How ISO 27001 Can Help)

From SIM-swap fraud to AI-powered campaigns and quishing, phishing keeps evolving. The countermeasures that work, the M&S lesson, and how ISO 27001:2022 structures the defence.

Read the article →
Data Protection
April 2025

Clarification on EU CSRD: What's Next and Timeline Confusion

The Corporate Sustainability Reporting Directive has implications beyond the EU. If your organisation works with European entities, here is what you need to understand.

Read the article →

No articles match your search.

Have a compliance challenge in mind?

We are happy to discuss your specific situation without obligation. If it is something we can help with, we will tell you how. If it is not, we will tell you that too.

Ask us a question

Message sent.

We will reply to you within one working day.