Skip to main content

Field notes from the audit room.

Practitioner articles by Christophe Mazzola and the Cyber Academy trainer pool. Real audits, real boards, real incidents, written down and dated. No press releases.

The pieces we wish we had read when we started in GRC.

July 2026

11 articles
The Rise of the Digital Compliance Officer
Audit room

The Rise of the Digital Compliance Officer: New Role for 2026

A new role is emerging across Europe: the Digital Compliance Officer. Here’s why the job is rising, what it actually involves, and how GRC leaders can prepare for it before 2026.

27 Jul 2026Read
ISO 27001: I Read the Standard Five Times. Then I Tried to Implement It.
ISO 27001

ISO 27001: I Read the Standard Five Times. Then I Tried to Implement It.

What happens when the standard tells you what but never tells you how, and how to close that gap in 5 days. August 17 to 21, online.

25 Jul 2026Read
ISO 27001: I Nodded Through Six Months of Meetings Before I Understood a Word
ISO 27001

ISO 27001: I Nodded Through Six Months of Meetings Before I Understood a Word

What nobody tells you about starting out in ISO 27001, and how to stop faking it in 2 days. August 31 to September 1, online.

24 Jul 2026Read
The Myth of the All-Knowing CISO
CISO life

The Myth of the All-Knowing CISO: Why Cyber Can’t Fix Broken IT

CISOs are expected to solve everything ; outages, incidents, misconfigurations, bad processes ; even when IT fundamentals are broken. Here’s the truth nobody wants to say out loud.

23 Jul 2026Read
A CISO at the boardroom window at dusk, with risk, governance and audit binders stacked on the desk
CISO life

CISO: They Gave Me the Title. Nobody Gave Me the Job.

Promoted into the CISO role but never trained for it? The skills that got you the title are not the skills the job needs. Here are the five parts of the job nobody teaches, and how to close the gap in five days.

21 Jul 2026Read
The EU AI Act Decoded: What You Need to Know
AI Act

The EU AI Act Decoded: What You Need to Know

The EU AI Act is now the world’s most comprehensive AI regulation. Here’s the clear, practical breakdown of what matters ; risk categories, obligations, timelines, and what organisations must actually do to comply.

18 Jul 2026Read
The Compliance Circus: Why Customer Security Questionnaires Are Broken
Audit room

The Compliance Circus: Why Customer Security Questionnaires Are Broken

Every week brings another “mandatory” security assessment with contradictory demands. Here’s why the system is broken ; and how CISOs can bring sanity back to third-party assurance.

15 Jul 2026Read
Supply Chain Security: Meeting NIS2 Obligations with Third Parties
NIS 2

Supply Chain Security: Meeting NIS2 Obligations with Third Parties

NIS2 makes third-party security a legal obligation ; not a “best practice.” Here’s the pragmatic, field-tested approach to meeting NIS2 supply chain requirements without overwhelming your organisation.

12 Jul 2026Read
Security Is a Mindset: From Cyber Defense to Everyday Life
CISO life

Security Is a Mindset: From Cyber Defense to Everyday Life

Cybersecurity and personal safety are built on the same foundations: context, awareness, layered defenses, and the ability to respond. Here’s why security isn’t just a job ; it’s a mindset that applies everywhere.

09 Jul 2026Read
PECB vs ISACA vs ExIn: Which Certification Path Fits You
PECB & ISACA

PECB vs ISACA vs ExIn: Which Certification Path Fits You?

ISO-focused? Audit-focused? Technical governance? Here’s the no-nonsense comparison of PECB, ISACA, and Exin ; and which certification path actually fits your GRC career goals.

06 Jul 2026Read
NIS2 Explained for CISOs: What Actually Changes in 2026
NIS 2

NIS2 Explained for CISOs: What Actually Changes in 2026

NIS2 becomes enforceable in 2026 and it’s a very different world for CISOs. Here is the no-nonsense breakdown of what actually changes ; governance, penalties, Board duties, supply chain risk, incident reporting, and operational expectations.

03 Jul 2026Read

June 2026

10 articles
Mapping the ISO Jungle: 27001, 27002, 27005, 31000, 42001
AI Act

Mapping the ISO Jungle: 27001, 27002, 27005, 31000, 42001

ISO standards can feel like an impenetrable jungle ; 27001, 27002, 27005, 31000, 42001… Here’s the clear, no-nonsense map GRC professionals actually need.

30 Jun 2026Read
ISO 27701:2025: What Changed and Why It Matters
GDPR & privacy

ISO 27701:2025, What Changed and Why It Matters

ISO/IEC 27701 has undergone its biggest transformation since launch. The 2025 edition is no longer a bolt-on to ISO 27001 ; it’s a full, standalone privacy management standard. Here’s what changed, why it matters, and how to prepare.

27 Jun 2026Read
How to Prepare Your Organization for NIS2 Compliance
NIS 2

How to Prepare Your Organization for NIS2 Compliance

NIS2 enforcement hits in 2026. Here’s the practical, direct, no-nonsense roadmap to get your organisation compliant ; without drowning in paperwork or wasting months on theory.

24 Jun 2026Read
How to Plan Internal Audits Across Multiple Standards
Audit room

How to Plan Internal Audits Across Multiple Standards

Managing ISO 27001, GDPR, NIS2, DORA, SOC 2 and others at the same time can feel impossible. Here’s how to build a single, efficient internal audit program that works across every framework.

21 Jun 2026Read
How to Integrate AI Risk into Your Existing ISMS and Risk Register
AI Act

How to Integrate AI Risk into Your Existing ISMS and Risk Register

AI introduces new risks your ISMS was never designed to handle. Here’s the clear, practical method to integrate AI risk into your existing ISO 27001 risk register ; without reinventing your entire governance model.

18 Jun 2026Read
How to Evaluate Third-Party Vendors Like a CISO
CISO life

How to Evaluate Third-Party Vendors Like a CISO (The Real Way)

Vendor security isn’t about checklists ; it’s about context, contracts, governance, and credibility. Here’s the sharp, field-tested guide to evaluating third parties the way a modern CISO actually does it.

15 Jun 2026Read
How to Build an Audit Trail that Stands Up to Scrutiny
Audit room

How to Build an Audit Trail that Stands Up to Scrutiny

Regulators, auditors, and courts don’t care about what you intended ; they care about what you can prove. Here’s how to build an audit trail that survives NIS2, DORA, GDPR, AI Act, and forensic review.

12 Jun 2026Read
How to Build an AI Risk Register
AI Act

How to Build an AI Risk Register (with Template)

AI introduces new risks traditional risk registers cannot capture. Here’s the clear, pragmatic method for building an AI risk register ; and a ready-to-use template you can apply today.

09 Jun 2026Read
How AI Is Changing Audit and Compliance Management
AI Act

How AI Is Changing Audit and Compliance Management

AI isn’t replacing auditors or compliance teams ; it’s reshaping how they work. Here’s the practical, field-tested breakdown of how AI transforms risk, audit, evidence, and governance in 2026 and beyond.

06 Jun 2026Read
Evaluating Cloud Providers under DORA and NIS2
NIS 2

Evaluating Cloud Providers under DORA & NIS2

Cloud providers now sit at the centre of regulatory scrutiny. Here’s how to evaluate them properly under DORA and NIS2 ; without drowning in paperwork or missing critical risks.

03 Jun 2026Read

May 2026

6 articles
Continuous Compliance: Turning Audits into Ongoing Practice
Audit room

Continuous Compliance: Turning Audits into Ongoing Practice

Annual audits are dead. Continuous compliance is the only model that survives NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act. Here’s how to turn compliance into a living, breathing operational habit ; not a once-a-year panic attack.

31 May 2026Read
Can ChatGPT Draft Your ISMS Policy
AI Act

Can ChatGPT Draft Your ISMS Policy? A Real Test

Can AI write your ISMS policies? Yes ; but not the way most people think. Here’s a field-tested look at what works, what fails, and how to use AI safely in your governance program.

28 May 2026Read
Building a Compliance Dashboard that Speaks Board Language
Audit room

Building a Compliance Dashboard that Speaks Board Language

Most compliance dashboards overwhelm executives with noise. Here’s how to build one that speaks the Board’s language ; clear, strategic, and decision-ready.

25 May 2026Read
Brussels' Next Move: What Comes After NIS2 and DORA
NIS 2

Brussels’ Next Move: What Comes After NIS2 and DORA

NIS2 and DORA were only Phase 1. AI Act, Data Act, CRA, EUCS and new accountability rules are about to define Phase 2. Here’s the concrete roadmap GRC leaders must prepare for.

22 May 2026Read
Bridging GDPR, NIS2, and DORA for Unified Compliance
NIS 2

Bridging GDPR, NIS2, and DORA for Unified Compliance

GDPR, NIS2, and DORA overlap more than most organisations realise. Here’s how to build one unified compliance model instead of three separate nightmares.

19 May 2026Read
Awareness Program is dead
CISO life

Awareness Program is dead.

Awareness training reduces risk, but only when it’s designed for real humans, real incentives, and real-world context. Here’s why most programs fall flat ; and what actually works.

16 May 2026Read

March 2026

3 articles

February 2026

1 article

January 2026

21 articles
Storytelling for Compliance Leaders

Storytelling for Compliance Leaders

Because facts inform, but stories make people care about compliance.

01 Jan 2026Read
GRC KPIs That Matter: How to Prove Compliance with Numbers

GRC KPIs That Matter: How to Prove Compliance with Numbers

Most GRC KPIs are useless. Here are the ones that actually prove compliance ; and drive decisions.

01 Jan 2026Read
How to Get Executives to Care About Risk

How to Get Executives to Care About Risk

How to make executives genuinely care about risk ; and act on it.

01 Jan 2026Read
GRC Dashboards Executives Actually Read

GRC Dashboards Executives Actually Read

If you want executives to pay attention, you must stop reporting like a compliance officer and start reporting like a business partner.

01 Jan 2026Read
How to Run a Risk Assessment that Doesn't Bore the Board

How to Run a Risk Assessment that Doesn’t Bore the Board

If you want your board to actually care, not just endure your slides, you need to turn risk assessment from a reporting ritual into a decision conversation. Here’s how.

01 Jan 2026Read
How to Talk Compliance to Non-GRC People (and Make Them Care)

How to Talk Compliance to Non-GRC People (and Make Them Care)

How to Talk GRC to Non-GRC People (and Make Them Care)

01 Jan 2026Read
5 Mistakes in Risk Registers (and How to Fix Them)

5 Mistakes in Risk Registers (and How to Fix Them)

Because most risk registers are just expensive spreadsheets of wishful thinking.

01 Jan 2026Read
Top 10 Gaps Auditors Will Look for Under NIS2

Top 10 Gaps Auditors Will Look for Under NIS2

And why “we have a policy for that” won’t be enough this time with NIS2

01 Jan 2026Read
From Checkbox to Strategy: The Death of Fake Compliance

From Checkbox to Strategy: The Death of Fake Compliance

Compliance built on checklists is dying. Here's how organisations move from fake maturity to real strategic security.

01 Jan 2026Read
AI Governance vs. AI Compliance: What's the Difference

AI Governance vs. AI Compliance: What’s the Difference?

And why confusing AI Governance and AI Compliance will get you in trouble.

01 Jan 2026Read
The Ultimate Guide to ISO Certifications for GRC Pros

The Ultimate Guide to ISO Certifications for GRC Pros

A practical, field-tested guide to ISO certifications every GRC professional should understand ; and why they matter in real life.

01 Jan 2026Read
How to Write Policies People Actually Follow

How to Write Policies People Actually Follow

Because “In accordance with applicable legal requirements…” is not how humans talk. Therefore, not your policies should not include this.

01 Jan 2026Read
Data Classification Policies that Actually Work

Data Classification Policies that Actually Work

Because most “Confidential / Internal / Public” labels are just data decorative.

01 Jan 2026Read
From intern to CISO: How to Build a GRC Career That Scales

From intern to CISO: How to Build a GRC Career That Scales

A field-tested roadmap for your career from junior GRC analyst to CISO ; without getting lost in templates, audits, or corporate confusion.

01 Jan 2026Read
Lessons from Failed Audits: What Every Organization Should Learn

Lessons from Failed Audits: What Every Organization Should Learn

Why audits fail, what it really means, and the lessons every organization must learn to avoid repeating the same mistakes.

01 Jan 2026Read
Lead Auditor vs. Lead Implementer: Which Certification Fits You

Lead Auditor vs. Lead Implementer: Which Certification Fits You?

How to Talk GRC to Non-GRC People (and Make Them Care)

01 Jan 2026Read
Top 10 Audit Findings in 2025: The Real Ones

Top 10 Audit Findings in 2025: The Real Ones

Field notes from actual gap assessments across Europe, not from textbooks.

01 Jan 2026Read
How to Build a Compliance Culture Beyond Checklists

How to Build a Compliance Culture Beyond Checklists

Compliance culture is not built with policies or checklists ; it’s built with behaviours, ownership, and clarity.

01 Jan 2026Read
How to Stand Out as a vCISO

How to Stand Out as a vCISO

How a vCISO can truly stand out in a crowded market by being practical, human, and relentlessly useful.

01 Jan 2026Read
Why 2026 Is the Year of Compliance Convergence

Why 2026 Is the Year of Compliance Convergence

How to Talk GRC to Non-GRC People (and Make Them Care) By 2026, the companies that survive the regulatory storm, NIS2, DORA, the AI Act, The CRA Act, The DATA Act, ESG, privacy, you name it, will be the ones that finally stop managing frameworks in isolation. We’re entering the era of GRC convergen

01 Jan 2026Read
When Excel Is Enough and When You Need a Real GRC Platform

When Excel Is Enough and When You Need a Real GRC Platform

Excel works… until it doesn’t. Here’s the pragmatic line between “good enough” spreadsheets and when your organisation truly needs a GRC platform.

01 Jan 2026Read

Want the next field note in your inbox?

The GRC Brief newsletter ships one short edition every Monday at 8am CET. Five links, one short take. Three-minute read, no AI fluff.