Resources
The Cyber Academy library.
Field-tested GRC reference material, written by a working CISO. Articles, deep-dive pillars, a growing encyclopedia, and a weekly newsletter that doesn't waste your time.
Resources
Blog
Field notes
Short-form articles on regulations, audits and the CISO desk.
Pillars
Deep dives
The full guides on NIS 2, DORA, ISO 27001, AI Act and more.
Encyclopedia
GRC vocabulary
Practical definitions for common GRC terms, with sources and revision details where available.
Newsletter
The GRC Brief
Five hand-picked links on EU cyber regulation. No fluff.
Latest
Latest from the blog

CRA Article 14: You Have 24 Hours to Report, and the Platform Isn't Live Yet
The Cyber Resilience Act reporting obligation starts on 11 September 2026, not 2027. It covers products you shipped years ago, it runs on a 24-hour clock, and ENISA's platform is still not public. Here is what you can actually finish before the date.
Read
The Future of the CISO Role with AI
AI is rewriting the CISO job description. Here’s what the next generation of CISOs will look like ; and why the role is shifting from technical guardian to cognitive leader.
Read
Why Most Awareness Programs Fail (and How to Fix Them)
Most awareness programs look good on paper but change nothing in real life. Here’s why they fail ; and how to finally build one that works.
ReadDeep dives
The pillar pages
Pillar
NIS 2: the guide that replaces your legal watch.
In scope: 18 sectors, mid-sized (50+ FTE / 10M+ turnover) and larger. Two tiers, essential and important, with different supervisory intensity.Ten cybersecurity risk-management measures under Article 21. The directive says what; ISO 27001 is the most common how.Incident reporting: 24-hour early warning, 72-hour notification, full report at one month. Define the path before you need it.Personal liability and management accountability are now explicit. The board is on the hook, not just the CISO.Transposition state varies country to country, check your national authority before assuming the EU text applies as-is.
Read the guidePillar
DORA: what your RSSI did not tell you.
Applies to ~20 categories of financial entities plus designated critical ICT third-party providers, since 17 January 2025.Five pillars. The third-party register (Pillar 4) and the resilience testing (Pillar 3, including TLPT for significant entities) are the most operational and the most audited.For significant entities, threat-led penetration testing every three years, supervised by the national authority under TIBER-EU.Critical ICT third-party providers are supervised directly by the European Supervisory Authorities (ESAs). Their concentration risk now matters at EU level.Pair with ISO 22301 for BCMS, ISO 27001 for ICT risk management, and Lead Operational Resilience Manager for the regulator-facing layer.
Read the guidePillar
ISO 27001: Foundation, Lead Implementer, Lead Auditor, which one?
Foundation is the prerequisite. It gives the vocabulary and the management-system mental model. Two days, 1-hour exam.Lead Implementer (5 days) teaches you to build the ISMS, write the SoA, run the risk treatment and operate the management review cycle.Lead Auditor (5 days) teaches you to plan and lead third-party or internal audits. Different mindset: evidence, sampling, interview technique, reporting.Most CISOs and security leads take Lead Implementer. Internal auditors and Big Four consultants take Lead Auditor. Both is common over 12 to 18 months.Pass rates on instructor-led PECB cohorts: 99.1% at first attempt on our delivery; market average is 80% to 85% depending on the partner.
Read the guideVocabulary
Encyclopedia preview
AI Risk Manager
AI Risk Manager is the credential (PECB / ISACA emerging) for practitioners running AI-specific risk programmes: model risk, bias, drift, transparency, third-party model risk. Operational layer that complements ISO 42001 (system-level) and the AI Act (regulatory layer). Common companion to a CISO or Lead AI Auditor.
Advanced in AI Audit
AAIAAAIA is the advanced ISACA credential for auditing AI systems, models and governance. Newer (2024 onwards). Requires existing CISA or equivalent. Built for senior auditors adding AI capability, mapped onto ISO 42001 and the EU AI Act high-risk obligations.
Business Continuity Management
BCMBCM is the discipline that identifies threats to your critical operations, then designs the plans and procedures to keep them running through disruption. Not a one-off project. The BCM team that delivers under a real incident is the one that ran a tabletop exercise four months ago and wrote down what failed.
Business Email Compromise
BECBEC is the targeted social-engineering attack that impersonates an executive or supplier to redirect a payment or trick an employee into approving one. No malware required; pure pretexting. Average loss per incident dwarfs ransomware. Process controls (segregation of duties, callback verification) catch it; technology alone does not.
Business Impact Analysis
BIAA BIA is the structured analysis that quantifies the impact of disruption on each critical activity over time. Outputs include the recovery time objective, recovery point objective and minimum business continuity objective. Mandatory input for ISO 22301 and DORA. Done well, it becomes the document the board actually reads.
CIS Controls
The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.
The GRC Brief
Five hand-picked links every Monday at 8am.
EU cyber regulation, audit findings, templates and short takes. From a working CISO desk. Free. No fluff.
Subscribe to The GRC Brief