Compliance insights, cybersecurity best practices, and framework guides.
Practical compliance and GRC insights for SMEs — one email a month, no spam.
The EU AI Act is now law, and it reaches far further than the big tech labs. If your Irish business builds, sells, or simply uses an AI tool, you may already have obligations. Here is who is in scope and what the phased deadlines mean for you.
Data classification is the quiet foundation under access control, encryption and retention, yet most SMEs have never done it properly. This guide covers the four-tier scheme, the discover, classify, label and handle process, and how classification underpins GDPR and ISO 27001.
GDPR requires certain organisations to appoint a Data Protection Officer. This guide explains when appointing a DPO is mandatory, what the role involves, whether an external DPO is acceptable, and how the DPO differs from a vCISO or compliance consultant.
GDPR requires you to notify the DPC of a personal data breach within 72 hours of becoming aware. This guide explains what counts as a notifiable breach, what your notification must contain, when you must also notify affected individuals, and how to manage the first 72 hours.
An incident response plan is required by NIS2, referenced in GDPR, and expected under ISO 27001 — but most SMEs don't have a documented one. This guide provides a clear structure for building yours, covering preparation, detection, containment, recovery, and review.
GDPR Article 30 requires every organisation processing personal data to maintain a Record of Processing Activities — a structured inventory of what data you hold, why, who you share it with, and how long you keep it. This guide explains who needs one, what it must contain, and how to build it step by step.
Most SMBs don't have a defined patching process. This guide explains why patch management matters, what every framework requires, and how to build an SMB-friendly patching policy.
Your security is only as strong as your weakest supplier. Here's how to assess, manage, and monitor the third-party risk that most Irish SMEs are carrying without realising it.
The EU AI Act is rolling out and it has cybersecurity obligations baked in. This guide explains the risk categories, what’s required, and where AI governance meets your existing compliance frameworks.
Cyber insurance premiums are rising and underwriters want evidence. Here’s how a compliance assessment strengthens your application and can reduce your costs.
Run your first assessment in under 15 minutes — free, no credit card required.