Notes from the assurance engineering team.
Plain English. ISO dates. No marketing vapour. Subscribe to the RSS feed if that's how you consume things.
-
Why we turn buyers away
A product built to produce discomfort has to be willing to refuse the customer who wants to look better rather than be better. Here is the qualification we run before we sell anyone anything — and why the discomfort is the point.
-
Why your risk register is lying to you
Your risk register records what you typed, not what your evidence does. Here is why the heat map and the self-scored residual survive — and what an honest, evidence-backed register looks like instead.
-
I'm a lead ISO 27001 auditor. Here's what I can't see when I sign off your audit.
An honest account of what a point-in-time audit structurally cannot observe — written from the auditor's chair, not against it. The limits are in the frame, not the diligence.
-
The eleven months your certificate isn't watching
An audit is a sample taken on a single day; the certificate hangs on the wall for a year. Here is what happens in the gap between the two — and why "compliant at the time" is a breach pattern, not a defence.
-
Why confidence decays — and why your dashboard should say so
Most GRC dashboards print a static green tick. Frank prints an expiry date. Here's why every claim we publish carries one.