Insights
Field notes from the frontier of governance.
We publish short, practical perspectives drawn directly from live engagements. New writing arrives shortly.
How long does ISO 42001 certification actually take?
A practical breakdown of the typical 90-day path to certification — the stage gates, the conditions that make it possible, and where the time really goes.
How to choose an ISO 27001 consultant
Seven questions to ask in the first call, six red flags worth walking away from, and the four profiles of firm you will meet in the market.
ISO 42001 vs the EU AI Act: what overlaps, what doesn't
A mapping of ISO 42001 controls against EU AI Act obligations — where certification carries you, and where the Act demands more.
ISO 27001 + 27701: the privacy extension, done once
How to scope a combined ISMS and PIMS programme so you build the privacy work into the security work — instead of paying for it twice.
SOC 2 vs ISO 27001: which one a UK SaaS should actually pursue
Buyer signal, cost, timeline — and how to decide based on where your next twenty enterprise deals are likely to come from.
New writing each month
We publish short, practical perspectives drawn directly from live engagements. To be notified when the next piece lands, drop us a line.