Insights and updates on compliance, cybersecurity, and AI governance.

NIS2 Article 20(2) makes management bodies personally liable for cybersecurity oversight. Most boards approve risk reports they cannot meaningfully evaluate. Oversight becomes a signature.
Read article →
A fully ISO 27001 certified organisation passes every audit but has no governance. The CISO runs the ISMS and reports on its effectiveness. The board nods. There is no separation between operation and oversight.
Read article →
An ISO 27001 surveillance audit finds a well-designed ISMS with a critical gap: controls exist but evidence of their operation does not. Building a system and operating it are different disciplines.
Read article →
Five regulatory frameworks, three departments, one compliance manager holding it all together in a spreadsheet. The problem is architectural: each obligation was implemented independently with no shared control layer underneath.
Read article →
A financial services firm hit its DORA deadline on time. Eighteen months later, maintaining compliance consumes 35% of the risk team's capacity. The architecture was optimised for the deadline, not the decade after it.
Read article →
A CISO, a DPO, IT, and a board member each give a different answer to the same DORA compliance question. The problem is language, not knowledge.
Read article →
An organisation redesigns its ISMS for the third time as new regulations arrive. Each redesign takes months. The problem is the translation layer between regulatory text and technical implementation.
Read article →
An organisation spent €300,000 on external consultants for ISO 27001 certification. Twelve months later, nobody inside knows how to operate the management system. The gap between documents and culture is where governance fails.
Read article →
A DORA Article 29 concentration-risk requirement and an IT team's redundant-failover architecture can't be verified against each other because the regulatory obligation and the technical spec were never mapped together.
Read article →
PECB announces a partnership with NexGenio for the organisation and distribution of PECB training courses in Malta.
Read article →
Ten PECB certification courses across NIS2, DORA, and ISO standards, available in Self-Study or e-Learning format, with exam and certificate included.
Read article →