Insights
Security guidance written for
the people who have to act on it.
Notes from delivering security operations, audits, penetration tests and red-team exercises for European teams — covering what regulators actually ask for, how to buy testing that produces evidence, and how to keep control of data flowing into AI systems.
Regulation
Regulation · 9 min readNIS2 and penetration testing: what the directive actually requires
NIS2 never uses the words penetration test. Here is what Article 21 actually requires, why testing is still the practical way to evidence it, and how to scope work that satisfies a regulator.
Regulation · 8 min readSweden's Cybersecurity Act: what it changes for security testing
Sweden transposed NIS2 through the Cybersecurity Act, in force 15 January 2026. What changed for in-scope organisations, and how to build a testing programme that survives supervision.
Regulation · 8 min readDenmark's NIS2 law and what cloud-first companies have to evidence
Denmark's NIS2 implementation took effect 1 July 2025. For cloud-first Danish companies the hard part is not the policy set — it is producing evidence about infrastructure someone else operates.
Regulation · 8 min readFinland's Cybersecurity Act: where penetration testing actually helps
Finland's Cybersecurity Act entered into force on 8 April 2025, ahead of most of the EU. A practical view of which testing produces evidence Traficom-supervised entities can use.
Regulation · 9 min readDORA threat-led penetration testing: who is in scope and what it involves
DORA has applied since 17 January 2025. Threat-led penetration testing is only required for a designated subset of financial entities — here is how to tell whether that is you, and what to do if it is not.
Regulation · 9 min readNIS2, DORA and ISO 27001: which testing evidence satisfies which
Three frameworks, overlapping obligations, one security budget. A practical mapping of what each actually asks for and how far a single well-scoped test programme can stretch.
Testing
Testing · 10 min readHow to scope a penetration test (a checklist you can reuse)
Most disappointing penetration tests were badly scoped, not badly executed. A practical scoping method, the questions a good provider will ask you, and the exclusions that quietly destroy value.
Testing · 8 min readPenetration test, vulnerability scan, or red team: choosing by the question you have
Three different exercises, routinely sold as substitutes for each other. What each one can and cannot tell you, what each costs in effort, and how to pick without overbuying.
Testing · 8 min readWhat a good penetration test report looks like — and seven red flags
The report is the deliverable. How to judge quality, what every finding must contain, and the warning signs that a report was generated rather than written.
Testing · 8 min readPASSI qualification: what French buyers should expect, and when they don't need it
ANSSI's PASSI scheme qualifies security audit providers in France. What it covers, which organisations genuinely require it, and how to evaluate an unqualified provider properly.
Testing · 8 min readPenetration testing pricing in Europe: what actually drives the number
Why quotes for the same scope vary by a factor of five, which cost drivers are real and which are margin, and how to compare proposals that are not comparable on their face.
Testing · 7 min readRetesting: why 'fixed' is not evidence until someone checks
Remediation tickets marked done are assertions. Retesting converts them into evidence — and it is the cheapest, most-skipped step in the entire security testing cycle.
Operations
Operations · 9 min readManaged SOC, in-house SOC, or MDR: an honest comparison
Three delivery models for security monitoring, with genuinely different economics and failure modes. What each actually costs, what you keep control of, and how to tell which fits.
Operations · 8 min readSOC metrics that matter: from alert volume to investigation quality
Alert counts and closure rates measure activity, not security. The metrics that actually predict whether your SOC will handle a real incident well — and how to instrument them.
Operations · 9 min readThe first 24 hours after ransomware: decisions in the order they arrive
What to do, in what order, when ransomware hits — including the regulatory clock, the decisions that are irreversible, and the mistakes made in the first hour that cost the most.
Operations · 8 min readWhy security awareness training fails, and what phishing simulation should measure
Annual training and click-rate targets produce compliance evidence, not behaviour change. What actually reduces risk, and the one metric worth optimising in a phishing programme.
AI security
AI security · 8 min readWhat actually leaks when your team uses AI assistants at work
A concrete inventory of the data that leaves your organisation through AI assistants, which paths are riskiest, and what to do that is not simply blocking the tools.
AI security · 9 min readEU AI Act and GDPR: the questions to answer before you deploy an LLM feature
Two regimes apply in parallel to AI systems processing personal data. A practical set of questions that determines your obligations before you build, not after.
AI security · 9 min readLLM prompt pseudonymization: how it works and where it breaks
Replacing sensitive values before a prompt reaches a model provider is a genuinely useful control. An honest account of the mechanics, the failure modes, and what it does not achieve.
AI security · 8 min readAI gateway, DLP, or enterprise AI licences: three controls, three different failures
These three are routinely compared as alternatives. They address different parts of the problem and fail in different places — here is which gap each one actually closes.
Talk to the team
What do you need tested?
Send us the system, service, or control you are concerned about. We will help turn it into a workable scope.
Discuss your scope