Notes from the assurance engineering team.
Plain English. ISO dates. No marketing vapour. Subscribe to the RSS feed if that's how you consume things.
-
A programme can be up to date and still not name the risk
A critical infrastructure risk management programme can be current, reviewed and lawfully attested, and still not contain the hazard that takes the asset down.
-
A contradiction in the wild: implemented, accepted, and being fixed
One control, three of the organisation's own approved registers, three different answers — and the structural reason nobody had noticed.
-
A green dashboard is an argument, not evidence
A green tile is a claim someone is making, not a fact you observed. Here is the difference between an assertion and evidence — and why a tool that turns your self-reports green is manufacturing the confidence it was supposed to test.
-
Can your board honestly sign that the programme was up to date?
The Security of Critical Infrastructure Act makes a board put its name, once a year, to a risk management programme being up to date. Here is why that signature is a point-in-time claim over a programme that drifts — and what a board would need in order to sign it honestly.
-
Why we turn buyers away
A product built to produce discomfort has to be willing to refuse the customer who wants to look better rather than be better. Here is the qualification we run before we sell anyone anything — and why the discomfort is the point.
-
Why your risk register is lying to you
Your risk register records what you typed, not what your evidence does. Here is why the heat map and the self-scored residual survive — and what an honest, evidence-backed register looks like instead.
-
I'm a lead ISO 27001 auditor. Here's what I can't see when I sign off your audit.
An honest account of what a point-in-time audit structurally cannot observe — written from the auditor's chair, not against it. The limits are in the frame, not the diligence.
-
The eleven months your certificate isn't watching
An audit is a sample taken on a single day; the certificate hangs on the wall for a year. Here is what happens in the gap between the two — and why "compliant at the time" is a breach pattern, not a defence.
-
Why confidence decays — and why your dashboard should say so
Most GRC dashboards print a static green tick. Frank prints an expiry date. Here's why every claim we publish carries one.