Skip to content

Blog

One concept at a time. A short post that explains it, an artefact you can use the same day, and sometimes a video walking through it.

Every post here ends in something concrete. If you would rather start from the artefacts, the newest are on Latest, and the full set lives in the resource library.

New posts go out on an RSS feed.

Which regulation wins? There is a rule for that

If you work in a regulated team you have DORA, NIS2, GDPR and the AI Act arriving on the same desk. At some point somebody asks the obvious question, and it is a good one: which of these do we actually have to follow?

Nobody in the room ever seems to know there is a formal answer.

The Digital Omnibus didn't delay the AI Act. It rewrote parts of it.

Every headline since 24 July has said the same thing: the AI Act got pushed back. True, and also the least interesting part of Regulation (EU) 2026/1744, the "Digital Omnibus on AI," which entered into force on 27 July 2026. I went through the consolidated EUR-Lex text rather than the summaries. Sixty-nine amendment markers, thirty-nine locations in the Act. Two new prohibited practices. A deleted article replaced by a wider one. A redefinition of what counts as a safety component. A new category of company the Act now treats differently. None of that is a date.

Stop asking how important your server is

It is the wrong question, and it is the first question almost every asset register asks.

You end up with a spreadsheet where someone has typed "high" next to a database because it felt important, and "medium" next to a file share because it felt less so. Nobody can defend a single one of those numbers, because they were never derived from anything.

The hard part of ISO 27001 is not the policies

Every template pack on the internet gives you the same thing: a folder of Word documents with your company name find-and-replaced into them. Information Security Policy, Access Control Policy, seventeen more. They look like progress.

They are the easy half. The hard half is proving, on a Tuesday in month nine, that requirement 6.1.3(d) is met and pointing at the thing that meets it.

The ESAs just told you what DORA expects about AI-driven attacks

The article-by-article series ended with the point that DORA is a chain, and that everything downstream inherits the quality of your asset and function map. On 31 July 2026 the three ESAs published a joint statement that tests exactly that claim. It is about frontier AI models being used to find and exploit vulnerabilities faster than your patch cycle can close them, and it says the rulebook you already have is the rulebook you are expected to use.

DORA oversight, and the whole regulation on one page

This is the finale of the article-by-article series. Chapter V, section II, Articles 31 onward, is the part of DORA that reaches past individual firms and up to the providers everyone depends on: the critical ICT third-party providers, supervised directly at EU level. Then, as promised at the start, DORA on one page.