Frameworks decoded, regulations translated, practice over theory. Ideas for the people doing the work.

CSFaaS shipped 55 improvements in four weeks, covering AI-powered prompt automation, MCP hardening, CyFun integration, risk workflows, auditability, permissions, scalability, UX and education. Together, these updates reflect a platform becoming more mature, reliable and operational release after release, with major new capabilities coming next.
Read article
Anthropic has announced plans to mark content generated or processed by Claude as part of its commitments under the EU AI Act and the Code of Practice on Transparency of AI-Generated Content. For new Claude models launched in the EU on or after August 2, 2026, Anthropic says marking will be supported from launch. The approach relies on two complementary mechanisms: embedded watermarks in text and signed provenance metadata for files.
Read article
CyFun® does more than build on the NIST Cybersecurity Framework. It turns cybersecurity guidance into something assessable, measurable and auditable. By distinguishing between documentation and implementation maturity, CyFun® helps organisations move from knowing what they should do to demonstrating what they actually do.
Read article
Threats, vulnerabilities, likelihood, impact… These terms are often used interchangeably, yet each plays a distinct role in cybersecurity risk assessment. In this Back to Basics, discover the fundamental building blocks of risk modeling and how they fit together to create meaningful and actionable risk analyses.
Read article
The real challenge of using Excel + Power BI for GRC instead of an existing GRC platform is not creating dashboards, but designing the governance system behind them. Defining taxonomies, workflows, roles, permissions, data relationships, validation rules, review cycles, and other governance structures ultimately means rebuilding a GRC platform from scratch. “The question is not ‘Can we build it?’ but ‘Why are we rebuilding something that already exists?’”
Read article
Risk management starts with a common vocabulary. Risk, Risk Assessment, and Risk Assessment Methodology, as defined in NIST SP 800-30, provide the foundation for effective, consistent, and repeatable cybersecurity risk assessments.
Read article
MCP enables AI assistants to securely access enterprise data, but it also creates a new data leakage risk. When employees connect personal AI accounts to corporate MCP servers, sensitive information may leave the organization’s controlled environment. AI governance is now as important as access control.
Read article
AI agents can access data, call APIs and execute actions. But are they inventoried, monitored and included in your risk register? An AI agent is not just a tool. It is a new digital actor in your organization.
Read article
A cybersecurity framework turns scattered controls into a measurable baseline. Here is why one (or a few) should anchor your entire security programme.
Read article
Vague AI definitions sink governance efforts. Learn how policy and regulation define AI, and why a narrow, practical scope beats a sweeping one.
Read article
Technology alone will not protect your organisation. Learn how a strong cybersecurity governance process turns scattered controls into accountable, board-level risk management.
Read article
Defining risk appetite and risk tolerance helps organizations make consistent, informed decisions. These principles, supported by ISO and NIST frameworks, strengthen governance and improve overall risk management.
Read articleBring the program, the work and the proof together in one workspace.