I've published a new article! It explains how companies like Apple use cybersecurity to outmatch their competitors and gain a sizeable market share:
https://t.co/1EhL64wUlN
I received a lot of questions about how ISO 27001 and ISO 42001 fit together, so back in May I held a webinar to walk through the topic in a practical way.
I explained what can be integrated, what needs to stay separate, how to deal with security and AI risks, and how to avoid duplicating work when implementing both standards.
You can watch the recording here: https://t.co/XwI2MifMAF
#ISO27001 #ISO42001 #AIGovernance #InformationSecurity #CyberSecurity #RiskManagement #Compliance
If you are preparing for NIS2 in Czechia, using documentation that already reflects the Czech regulatory context can save a lot of time.
We've now published our Czech NIS2 Documentation Toolkit, with all the key policies, procedures, and other documents needed for implementation, available in Czech.
You can check these documents free of charge: https://t.co/vhSK4hwo37
#NIS2 #KybernetickaBezpecnost #Compliance #CyberSecurity #RiskManagement
If your customers ask for a SOC 2 report, that doesn't necessarily mean you have to choose between SOC 2 and ISO 27001.
ISO 27001 helps you build and manage your information security program, while SOC 2 demonstrates how your controls perform against the Trust Services Criteria. In practice, a well-implemented ISO 27001 ISMS can make the SOC 2 process much more straightforward.
Read more about the Comparison of SOC 2 and ISO 27001 certification here: https://t.co/SlxSPgLhk7
#SOC2 #ISO27001 #InformationSecurity #CyberSecurity #Compliance #ISMS
- What a financial planner taught me about cybersecurity -
For many of us, venturing into areas beyond our own expertise can provoke varying degrees of worry or anxiety. Part of the problem is the language we use. In cybersecurity we talk about “threat actors”, “Advanced Persistent Threats”, “phishing campaigns” and “compromised credentials”. To us, these are everyday terms, but to everyone else, they can sound like something from a spy novel. In reality, we’re often talking about criminals, scams, fraud, and people trying to trick us into handing over money or information.
https://t.co/S7DrEHHjMG
- How can you redefine #resilience for the next frontier of #vulnerabilities? -
EY research explores how cybersecurity leaders are using recent frontier AI threat revelations as a catalyst to build resilience
https://t.co/sN6celZFDi
I've reviewed quite a few business continuity plans over the years, and a lot of them look good on paper. The question is whether they'd actually work when something goes wrong.
That's what ISO 22301 is all about. In this webinar, I'll explain how to use it to build business continuity plans for NIS2 and DORA: https://t.co/DMZvMMg7jQ
#ISO22301 #NIS2 #DORA #BusinessContinuity #CyberResilience
Many companies pursue cybersecurity certifications because customers expect them.
But does a certificate alone create a lasting competitive advantage?
Check out how Apple turned cybersecurity and privacy into core product features and an integral part of its brand, creating a level of differentiation that competitors find difficult to replicate: https://t.co/bJSHmqav9q
#CyberSecurity #InformationSecurity #ISO27001 #BusinessStrategy #CyberResilience #Leadership #InfoSec
* #Agentic#AI Is Rewriting the Rules of #Data#Risk Management *
Most enterprises still manage data risk with the same structures they used before generative AI came along - as distinct domains. Privacy manages regulatory compliance, cybersecurity manages breach defense, data governance manages classification and stewardship, and AI development teams manage performance and speed to market. But that structure doesn’t hold today when a single AI deployment simultaneously triggers privacy, cyber, governance, regulatory, and performance implications.
https://t.co/cNcomubszf
Defining the ISMS scope is one of the first practical steps in ISO 27001 implementation, and it has a direct impact on how complex the project becomes.
In this free live webinar, I’ll explain how to set the ISMS scope correctly, including what must be included, how to approach cloud servers, when the scope should cover the whole company, and how to handle interfaces and dependencies. I’ll also show what needs to be documented and how to do it.
Join us and bring your questions to the discussion: https://t.co/eItyJlbgCV
#ISO27001 #ISMS #InformationSecurity #CyberSecurity #Compliance #RiskManagement #InfoSec
ISO 27001 can seem overwhelming when you're just getting started.
If you want to understand the key concepts, requirements, and implementation steps without spending hours reading the standard, our free ISO 27001 Foundations Course is a good place to start: https://t.co/0Ybrjab6ci
#ISO27001 #InformationSecurity #ISMS #CyberSecurity #InfoSec #Compliance
Many companies pursue cybersecurity certifications because customers expect them.
But does a certificate alone create a lasting competitive advantage?
Check out how Apple turned cybersecurity and privacy into core product features and an integral part of its brand, creating a level of differentiation that competitors find difficult to replicate: https://t.co/bJSHmqav9q
#CyberSecurity #InformationSecurity #ISO27001 #BusinessStrategy #CyberResilience #Leadership #InfoSec
* #OWASP Introduces #Agentic#AI#Security Maturity Framework *
The framework maps the governance problem across two linked dimensions. One axis captures what is being deployed, ranging from shadow AI and single‑vendor tools through custom agents to multi‑agent and federated systems. The other criterion measures governance maturity, from ad hoc processes up to continuous monitoring and adaptive automated enforcement.
https://t.co/scpHhjK9D8
Defining the ISMS scope is one of the first practical steps in ISO 27001 implementation, and it has a direct impact on how complex the project becomes.
In this free live webinar, I’ll explain how to set the ISMS scope correctly, including what must be included, how to approach cloud servers, when the scope should cover the whole company, and how to handle interfaces and dependencies. I’ll also show what needs to be documented and how to do it.
Join us and bring your questions to the discussion: https://t.co/eItyJlbgCV
#ISO27001 #ISMS #InformationSecurity #CyberSecurity #Compliance #RiskManagement #InfoSec
If you want to learn how to plan, perform, manage, and lead ISO 42001 audits, this free Lead Auditor Course provides a structured overview of the audit process, audit principles, evidence gathering, reporting, and evaluating compliance with AI governance requirements.
Enroll free of charge here: https://t.co/scVFS2g3Vk
#ISO42001 #LeadAuditor #AIGovernance #ArtificialIntelligence #AICompliance #Compliance #InternalAudit
* Turn #Privacy#Regulation into a #Competitive#Advantage *
Over time, many companies improve their performance. As companies update their data practices, compliance becomes more visible to customers and business partners. That visibility builds credibility and signals trust, strengthening key relationships. What first looks like a constraint becomes a source of differentiation.
https://t.co/xBin2n43PG
One of the first questions organizations should answer when working on AI governance is surprisingly simple: What is your AI role?
The answer affects everything that follows, from governance responsibilities and documentation to compliance obligations under ISO 42001 and the EU AI Act. A company using ChatGPT faces different requirements than a company embedding AI into its own products.
In this article, I explain the key AI roles defined by both frameworks, where they overlap, where they differ, and why getting this wrong can create compliance gaps later on: https://t.co/gSFHRYuqB2
#ISO42001 #AIGovernance #EUAIAct #ArtificialIntelligence #AICompliance #Compliance #RiskManagement