What should an incident response plan contain?
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
Resources
Fundamentals of management systems, cybersecurity and compliance — with a short answer first and the details after.
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Can an ISO 27001 ISMS use your existing tools? Yes — how wikis, document management, ticketing and project tools can carry large parts of it.
How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
What ISO 9001 and ISO/IEC 27001 have in common, which processes an integrated management system (IMS) can share, and what remains specific to each standard.
NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.
What an information security management system (ISMS) is, what it consists of, how it relates to ISO/IEC 27001 — and why it is more than a set of documents.
Tell us what you’re working on.