An organisation can expose far more than its security inventory suggests. Domains, certificates, employee profiles, job adverts, public documents, code repositories and internet-facing services all…
Łukasz Krzewicki
Explore all publications and insights
Every device, application and cloud service in your organisation keeps a diary — an endless stream of log entries recording logins, connections, changes, and failures. Somewhere in that flood, the…
What is cyber risk management? It’s the continuous process of identifying, analysing, evaluating and reducing risk tied to cyber threats. The goal is to protect the organisation from incidents,…
Burglars rarely force the front door when somebody has left a back window open for them. In cybersecurity, that window is increasingly likely to be a supplier – the firm that maintains your IT…
When a serious disruption in an organisation hits, the pressure of the moment leaves no room to work out priorities. Teams restore whatever feels most urgent, or whatever the loudest part of the…
Let’s start with the basic definition. What is risk assessment really? In short, it is a structured process of identifying, analysing and evaluating risks that could affect an organisation. The…
Few words in business inspire quite as much quiet dread as audit — which is simultaneously precisely the point and utterly unnecessary. While many see the audit as an inherently antagonistic…
Every organisation relies on hundreds, thousands, or even tens of thousands of assets to deliver products, services and day-to-day operations. Some of these assets are easy to identify: IT systems,…
What Is a QMS? A quality management system is a structured framework through which an organisation plans and runs everything that affects the quality of its products and services, while continuously…
What Is the EU AI Act? The EU AI Act responds to the rapid adoption of AI across business processes, especially where AI influences decisions, customer interactions, risk management, or access to…
Every revision of ISO 9001 is a response to changes that have already taken place in the way organisations operate. The objective is not merely to make editorial improvements to the standard but to…
What is PDCA (Plan-Do-Check-Act)? PDCA is an iterative model of continuous improvement, which aims to optimise processes, enhance quality, and boost operational efficiency, while limiting the risk…
Risk appetite and risk tolerance are two concepts central to risk management. They appear in frameworks, regulatory submissions, and board-level conversations. They are also regularly conflated,…
Introduction to Risk Assessment and Incident Response A great many companies still run risk assessment and incident response as two separate processes. The risk management or compliance team…
Imagine a scenario that has become increasingly common across Europe. The board learns that the organisation may fall under new cybersecurity requirements. The security team starts reviewing NIS2….
What Is an Audit Trail? An audit trail is an automatic, chronological record of actions and events occurring across an organisation’s IT systems and internal procedures. Each event is logged…
What Is the Cyber Resilience Act? The Cyber Resilience Act is Regulation (EU) 2024/2847 of the European Parliament and of the Council, which establishes uniform horizontal cybersecurity requirements…
What is the NIS2 Directive? NIS2 is an EU cybersecurity directive that significantly expands the number of organisations in scope while raising the bar for risk management and incident response. In…
What Is an Information Security Policy? An information security policy defines what an organisation needs to protect and to what standard. It applies to everyone who handles the organisation’s…
What Is ISO 22301? ISO 22301 defines what a business continuity management system (BCMS) needs to include. At its core, the standard calls for a business impact analysis, documented continuity plans,…
What Are SOC Audits? A SOC audit is an independent assessment of the internal controls at a service organisation. Its purpose is to give the organisation’s clients confidence that appropriate…
Board liability and the real risk of non-compliance For some, a compliance gap analysis might seem like a mere formality. However, for a Management Board, it should be a rigorous control tool used to…
What Is a Control Measure? A control measure is a specific action, procedure, or safeguard designed to limit risk and help an organisation achieve its objectives. It is not a synonym for internal…
What Is Inherent Risk? Inherent risk is the level of threat linked to an activity, process, or asset before any controls are applied. It is driven by the nature of the activity itself, not by how…
NIS2 Requirements for Incident Management The NIS2 Directive obliges organisations to detect incidents promptly, limit their impact, and meet strict reporting timelines. It also requires the entire…
Internal controls are evolving from reactive to proactive thanks to automation and AI. Integrated Risk Management (IRM) is becoming the standard, combining operational risks, cybersecurity, and…
In this environment, companies need structured and reliable ways to protect their data and prove resilience. ISO/IEC 27001, one of the most widely adopted international standards, provides a…
The recent years have been challenging for business continuity. There is practically no industry that is not beset with difficulties due to disruptions in supply chains, sanitary restrictions, the…
What is Risk and Control Self-Assessment (RCSA)? RCSA is a structured process that allows teams across an organisation to identify risks, evaluate the controls in place, and assess their…
Definitions first. According to COSO, internal control is a set of processes and actions that help a company meet its goals, whether that means running efficiently, reporting accurately, or staying…
Managing risk requires anticipating potential threats, understanding their impact, and making informed decisions. In many ways, it resembles a game of chess, where every move influences future…
From digital transformation and regulatory changes to disruptions in global supply chains, companies face ever more complex challenges that shape the reality of doing business. Volatility brings…
In an era of increasing business complexity and rapidly changing regulations, organisations need proven risk management methods. A risk assessment matrix has become a key tool in this context,…
In an era where a brand’s reputation can be made or broken in the click of a button, understanding and managing reputation risk has become a critical component of strategic planning for…
In the intricate world of finance, managing risk is not just a precaution; it’s a necessity. Whether you’re navigating the volatile markets as an investor, steering a business through…
In the digital age, where financial transactions and sensitive data are constantly at risk, understanding how to report a security incident is paramount. This guide aims to demystify the process,…
Are you curious about what CAPAs stand for and their significance across different sectors? If you’re involved in business management, quality control, or just interested in process…
Whether you’re a business owner, a finance professional, or simply someone who wants to understand why audits are crucial, this article is for you. Auditing plays a vital role in ensuring the…
What is a risk management strategy A risk management strategy is an essential aspect of any organization, encompassing the identification, assessment, and prioritization of risks followed by…
Optimize processes, increase the company’s competitiveness — that’s what we are hearing all the time nowadays. And we will in the future, as new technologies disrupt areas of companies’…
Since every company is different, there is no single, right way to run an Internal Audit. But there are common Internal Audit management pitfalls to avoid, such as: Ineffective leadership which leads…
If the Board does not see Internal Audits as crucial for the business, then either the Board is missing a trick, or Internal Audits aren’t doing their job. This short article aims to help Board…
Enterprise Risk Management (ERM) is an effective but complex process that identifies, monitors and reports risks across a wide range of an organization’s operations. Some of the best GRC…
Companies that operate in highly regulated sectors such as life sciences, food and manufacturing are legally obliged to manage risk. Since all business activities have an element of risk, it is…
nternal Audit provides important guidance for life science companies, which helps them manage risks effectively, and run strong control and governance processes. By evaluating an organisation’s…
