Insights
Practitioner thinking on digital supply chain cyber risk.
Commentary across our four specialisms, written by the people delivering the work.
Articles
Latest articles
AI Governance
The EU AI Act: what regulated firms must do now
The EU AI Act is phasing in obligations through 2026 and 2027. Here is a practical, evidence-first way to prepare without stalling delivery.
Felix · 16 August 2026
Governance, Risk & Compliance
NIS2: from directive to demonstrable compliance
NIS2 raises the bar on management accountability, incident reporting and supply chain security. A practical route to evidence-backed readiness.
Felix · 9 August 2026
Assurance & Certification
ISO 27001 certification without the theatre
Certification is straightforward when the management system reflects how the business actually runs. Here is how to avoid a paper ISMS.
Felix · 1 August 2026
Third-Party Risk
Third-party risk: lessons from 200+ assessments
Patterns that recur across hundreds of supplier assessments — and the controls that actually reduce exposure.
Felix · 24 July 2026
AI Governance
AI governance: the evidence boards should demand
Regulators and customers are moving from AI principles to AI proof. Six artefacts that turn intent into defensible governance.
Felix · 16 July 2026
Themes
What we write about
Digital Supply Chain Cyber Risk
third-party risk management, supply chain cyber risk assessment, fourth-party risk visibility
Cybersecurity
attack-surface intelligence, operational resilience, cyber maturity benchmarking
Governance
AI governance & responsible adoption, cyber strategy, board cyber risk reporting
Compliance
NIST SP 800-161 / NIST CSF 2.0, DORA third-party risk requirements, compliance-gap mapping
Want this thinking applied to your supplier ecosystem?
A short, no-obligation discovery call to understand your risk profile and where to start.