Resources
The substance, published openly.
Plain-spoken guides, articles and checklists on compliance, testing and managed security: the kind of answers we'd give in a first call. Choose a section below to get started.
ISO 27001 toolkit
A plain-language guide and a downloadable Control Pack for all 93 ISO 27001:2022 Annex A controls. A new control publishes every day.
Browse 93 controlsISO 22301 toolkit
A plain-language guide and a downloadable Control Pack for all 26 ISO 22301:2019 business continuity (BCMS) clauses, from context to continual improvement.
Browse 26 clausesGuides & downloads
Whitepapers, checklists, and guides with formatted PDFs to take away. We publish the substance openly.
Browse downloadsArticles
Short, plain-spoken answers to the compliance and testing questions buyers actually ask.
Read articlesInteractive tools
Quick, interactive checks you can run yourself to baseline compliance readiness, vendor risk, security budget ROI, and maturity.
Run checksLatest articles.
- Compliance · guide
ISO 27001: a practical guide to information security management
ISO 27001 is a management system, not a checklist. Here are the core principles and a seven-step path from gap analysis to certification.
- Assessment · article
Is penetration testing manual or automated? (Both.)
Scanners give you coverage. People find the business-logic and chained flaws that sink a deal. Good testing uses both.
- Compliance · article
SOC 2 Type I vs Type II: which one do you need?
Type I proves your controls are designed right at a point in time. Type II proves they actually work over a period. Here is how to choose.
Still exploring?
Get the next resource by email.
No spam. We share the guides and tools we publish, and you can unsubscribe any time.