Skip to main content

The Cyber Academy library.

Field-tested GRC reference material, written by a working CISO. Articles, deep-dive pillars, a growing encyclopedia, and a weekly newsletter that doesn't waste your time.

Resources

The pillar pages

See all

Pillar

NIS 2: the guide that replaces your legal watch.

In scope: 18 sectors, mid-sized (50+ FTE / 10M+ turnover) and larger. Two tiers, essential and important, with different supervisory intensity.Ten cybersecurity risk-management measures under Article 21. The directive says what; ISO 27001 is the most common how.Incident reporting: 24-hour early warning, 72-hour notification, full report at one month. Define the path before you need it.Personal liability and management accountability are now explicit. The board is on the hook, not just the CISO.Transposition state varies country to country, check your national authority before assuming the EU text applies as-is.

Read the guide

Pillar

DORA: what your RSSI did not tell you.

Applies to ~20 categories of financial entities plus designated critical ICT third-party providers, since 17 January 2025.Five pillars. The third-party register (Pillar 4) and the resilience testing (Pillar 3, including TLPT for significant entities) are the most operational and the most audited.For significant entities, threat-led penetration testing every three years, supervised by the national authority under TIBER-EU.Critical ICT third-party providers are supervised directly by the European Supervisory Authorities (ESAs). Their concentration risk now matters at EU level.Pair with ISO 22301 for BCMS, ISO 27001 for ICT risk management, and Lead Operational Resilience Manager for the regulator-facing layer.

Read the guide

Pillar

ISO 27001: Foundation, Lead Implementer, Lead Auditor, which one?

Foundation is the prerequisite. It gives the vocabulary and the management-system mental model. Two days, 1-hour exam.Lead Implementer (5 days) teaches you to build the ISMS, write the SoA, run the risk treatment and operate the management review cycle.Lead Auditor (5 days) teaches you to plan and lead third-party or internal audits. Different mindset: evidence, sampling, interview technique, reporting.Most CISOs and security leads take Lead Implementer. Internal auditors and Big Four consultants take Lead Auditor. Both is common over 12 to 18 months.Pass rates on instructor-led PECB cohorts: 99.1% at first attempt on our delivery; market average is 80% to 85% depending on the partner.

Read the guide

Encyclopedia preview

See all 87

AI Risk Manager

AI Risk Manager is the credential (PECB / ISACA emerging) for practitioners running AI-specific risk programmes: model risk, bias, drift, transparency, third-party model risk. Operational layer that complements ISO 42001 (system-level) and the AI Act (regulatory layer). Common companion to a CISO or Lead AI Auditor.

Advanced in AI Audit

AAIA

AAIA is the advanced ISACA credential for auditing AI systems, models and governance. Newer (2024 onwards). Requires existing CISA or equivalent. Built for senior auditors adding AI capability, mapped onto ISO 42001 and the EU AI Act high-risk obligations.

Business Continuity Management

BCM

BCM is the discipline that identifies threats to your critical operations, then designs the plans and procedures to keep them running through disruption. Not a one-off project. The BCM team that delivers under a real incident is the one that ran a tabletop exercise four months ago and wrote down what failed.

Business Email Compromise

BEC

BEC is the targeted social-engineering attack that impersonates an executive or supplier to redirect a payment or trick an employee into approving one. No malware required; pure pretexting. Average loss per incident dwarfs ransomware. Process controls (segregation of duties, callback verification) catch it; technology alone does not.

Business Impact Analysis

BIA

A BIA is the structured analysis that quantifies the impact of disruption on each critical activity over time. Outputs include the recovery time objective, recovery point objective and minimum business continuity objective. Mandatory input for ISO 22301 and DORA. Done well, it becomes the document the board actually reads.

CIS Controls

The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.

Five hand-picked links every Monday at 8am.

EU cyber regulation, audit findings, templates and short takes. From a working CISO desk. Free. No fluff.

Subscribe to The GRC Brief