Cybersecurity

sbom requirements eu cyber resilience act a tall stack blank paper sheets

SBOM Requirements: Essential EU CRA Guide to Avoid Risk

A deep-dive on SBOM requirements under the EU Cyber Resilience Act for software teams: what Annex I, Part II actually obliges you to document, the seven minimum data fields every component entry needs, how to choose between SPDX and CycloneDX, how to generate and store SBOMs in your delivery pipeline, keeping them current across versions and patches, the VEX workflow that makes vulnerability matching usable, what market surveillance authorities can demand, the fine bands up to €15 million, and a 90-day plan to get compliant before the December 2027 deadline.

Read more
cyber resilience act checklist software developers a clipboard with check marks

Cyber Resilience Act Checklist: Proven Steps to Avoid Fines

A working Cyber Resilience Act checklist for software developers and engineering leads. Six workstreams in delivery order: inventory and classification, the Annex I secure development requirements, machine-readable SBOMs with CycloneDX or SPDX, vulnerability handling that survives an audit, the 24-hour reporting capability due by 11 September 2026, and the technical file, declaration of conformity and CE marking due by 11 December 2027 — plus the fine bands, the 2026 Commission guidance, the draft harmonised standards, a 16-month plan and the mistakes development teams most often make.

Read more
cyber resilience act reporting requirements a three ascending rounded pillars

Cyber Resilience Act Reporting: Proven Guide to Avoid Fines

Cyber Resilience Act reporting becomes a live legal duty on 11 September 2026, fifteen months before the rest of Regulation (EU) 2024/2847 applies. This operational guide covers the two triggers that start the clock, what “becoming aware” means, the 24-hour early warning, the 72-hour notification and the 14-day or one-month final report, the ENISA single reporting platform and how to choose a coordinating CSIRT, what each submission must contain, who is authorised to file out of hours, the parallel duty to notify users, how the clocks interact with NIS2, DORA and UK GDPR, the evidence pack, the penalty bands, and a four-week readiness plan.

Read more
cyber resilience act compliance uk software companies a three ascending rounded pillars

Cyber Resilience Act Compliance: Essential UK Risk Guide

Cyber Resilience Act compliance stops being a 2027 problem on 11 September 2026, when the Article 14 reporting duties in Regulation (EU) 2024/2847 switch on and every UK software company selling into the European Union inherits a 24-hour clock. This guide explains which products with digital elements are caught, why a UK vendor is almost always the manufacturer, how the default, Class I, Class II and critical tiers change your conformity route, what the Annex I essential requirements mean in engineering terms, how the SBOM and vulnerability handling duties work, the five-year support period and ten-year update availability rules, the three reporting clocks, the penalty ceilings, and a twelve-month programme to reach a defensible position.

Read more
backup vs disaster recovery vs high availability a blank signpost two arrow boards

Backup vs Disaster Recovery: Simple Guide to Avoid Downtime

Backup, disaster recovery and high availability get used as though they were interchangeable, and they are not. A backup is a copy of your data you can go back to. Disaster recovery is the plan and environment that get a service running again somewhere else. High availability is the redundancy that stops a component failure becoming an outage at all. This guide sets out what each layer really protects against, where backup and disaster recovery genuinely diverge, how RTO and RPO drive the whole decision, what the three approaches cost a UK business in practice, how ransomware has changed the arithmetic, and a five-step framework for deciding which workload deserves which layer.

Read more
penetration testing frequency a shield with magnifying glass

Penetration Testing Frequency: Proven Rules for Safer IT

Once a year is a floor, not a schedule. This guide sets out how often a business should conduct penetration testing and why the calendar date matters far less than what changed in the estate since the last report. It covers the twelve-month baseline and where it comes from, the seven change triggers that should force an unscheduled round, exactly what PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus and NIS2 actually require, where vulnerability scanning stops and human testing starts, indicative UK programme costs at every cadence, and how to build a calendar that survives a year of competing priorities.

Read more
cybersecurity risk register template smes a upright board of blank tiles

Cybersecurity Risk Register: Proven Template for Safe SMEs

Most cybersecurity risk register templates are built for banks and abandoned by small businesses within a fortnight. This guide strips the document back to the eleven fields that earn their place, gives likelihood and impact scales anchored to time and money rather than adjectives, and shows a worked register for a sixty-person firm with real rows, owners and treatment decisions. It also covers the four treatment options and how to use each one honestly, a two-afternoon build method, the review cadence and out-of-cycle triggers that stop the register rotting, and when a spreadsheet stops being enough.

Read more
incident response retainer cost and inclusions a shield lightning bolt plinth

Incident Response Retainer: Essential Costs to Avoid Risk

An incident response retainer is a contract you buy before anything has happened, to guarantee access to specialists who are otherwise fully booked the moment a large ransomware event hits the market. The cheapest and most expensive quotes can describe genuinely different products, and on a procurement spreadsheet they look interchangeable. This guide covers what you are actually buying: the standard reactive and proactive inclusions, the exclusions that destroy budgets, the three pricing models in common use, realistic UK cost bands for 2026 by organisation size, what response-time service levels genuinely promise, how prepaid hours are consumed and lost, and a scorecard for comparing providers before you sign.

Read more
cyber tabletop exercise how to run a shield rehearsal hexagons

Cyber Tabletop Exercise: Proven Steps to Avoid Costly Risk

An incident response plan that has never been tested is a document, not a capability. A cyber tabletop exercise is the cheapest way to find out whether your organisation can actually respond — who holds shutdown authority, when the regulatory clock starts, and whether anyone has drafted a holding statement before they needed one. This guide covers the full cycle: setting objectives and scope, choosing a scenario grounded in your real risk register, deciding who belongs in the room, building the four-document exercise pack, a three-hour run sheet, the facilitation techniques that keep the discussion honest, and the after-action reporting that converts findings into tracked and closed actions.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
CHAT