HomeArticles

Articles & Analyses

The frameworks we apply with our clients, explained in depth by our team.

Compliance16 min

DORA eighteen months on: what actually bites, and what to fix first

Register of information, contract remediation, classifying an incident within four hours: where DORA programmes stall, and the sequence that works when you are starting late.

15 July 2026Read more
Compliance17 min

The Cyber Resilience Act is product law, not a CISO programme

The CRA lands in stages: reporting of actively exploited vulnerabilities from 11 September 2026, the rest of the regulation from 11 December 2027. What it regulates is not your infrastructure but what you ship.

16 June 2026Read more
Compliance16 min

NIS2: work out your scope before a customer does it for you

Directive (EU) 2022/2555 in practice: who is genuinely in scope, what a regulator reads into “appropriate and proportionate”, the 24h / 72h / one-month cascade, and why Article 20 moves budgets.

8 November 2025Read more
Cybersecurity16 min

NIST CSF 2.0: Govern at the centre, and Tiers are not a score

Since February 2024 the CSF has six functions and no longer speaks only to critical infrastructure. What actually changed: Govern at the centre, Tiers mistaken for a grade, and a profile that is worth nothing without evidence.

22 October 2025Read more
Risk management17 min

Third-party risk management: the questionnaire isn't enough, and neither is the register

A high response rate, a tidy register, a negotiated audit clause — and nothing verified. What separates a defensible third-party risk programme from a compliance exercise: tiering, evidence, continuous signals, an exit plan.

5 October 2025Read more
Risk management17 min

EBIOS Risk Manager: France's threat-led risk method, seen from inside the workshops

Five workshops, a lot of senior business time, and one step that decides whether the rest was worth it: what ANSSI's method really delivers, why the ecosystem workshop matters most, and when to use something lighter.

15 September 2025Read more