4 August 2026 · By P LarnerBlog post
Why most risk statements say nothing, and the condition, event and consequence structure that fixes them, with real register entries rewritten in full.
Risk Management#condition event consequence#risk register#risk statements#ownership#scoring
Read more →4 August 2026 · By P LarnerBlog post
How to turn a write-only risk register into a management tool. Keep it small, write real statements, give risks owners with budget, and review by volatility.
Risk Management#review cadence#governance#risk register#ownership#board reporting
Read more →3 August 2026 · By P LarnerBlog post
A practitioner's refresher on GDPR and UK GDPR, the principles, lawful bases, breach duties and fines, and where UK divergence is heading.
Regulation & Legislation#accountability#UK GDPR#GDPR#ICO#data protection#breach notification
Read more →2 August 2026 · By P LarnerBlog post
What the UK Cyber Security Council is, the four titles, which specialisms are actually open, what the assessment involves, and the annual CPD that keeps it.
Frameworks & Standards#CIISec#professional registration#CPD#ChCSP#chartership#UK Cyber Security Council
Read more →2 August 2026 · By P LarnerBlog post
What Secure by Design actually asks of delivery teams, how continuous assurance replaces accreditation, and the failure mode to avoid.
Regulation & Legislation#accreditation#continuous assurance#MOD#Secure by Design#SbD#delivery teams
Read more →2 August 2026 · By P LarnerBlog post
What UK Secure by Design is, who it applies to across government and the MOD, how continuous assurance works, and what suppliers must do.
Regulation & Legislation#GovAssure#accreditation#suppliers#government#Secure by Design#SbD
Read more →31 July 2026 · By P LarnerBlog post
What DORA requires of financial firms and their ICT suppliers, the five pillars explained, and how UK organisations end up in scope.
Regulation & Legislation#EU regulation#financial services#operational resilience#third-party risk#DORA
Read more →30 July 2026 · By P LarnerBlog post
What NIS2 is, who the essential and important entity tiers catch, what boards must now own, and where UK organisations stand.
Regulation & Legislation#EU regulation#NIS2#managed service providers#critical infrastructure#board accountability
Read more →30 July 2026 · By P LarnerBlog post
Risk appetite, tolerance and capacity answer different questions. Getting the terms straight, and why the difference matters.
Risk Management#escalation#thresholds#Orange Book#capacity#risk appetite#tolerance
Read more →30 July 2026 · By P LarnerBlog post
How to run a Monte Carlo risk assessment in four steps, from calibrated ranges and lognormal distributions to reading a loss exceedance curve.
Risk Management#calibration#FAIR#loss exceedance#simulation#Monte Carlo#quantification
Read more →29 July 2026 · By P LarnerBlog post
How to turn thousands of scanner findings into a handful of thematic, owned risks your register can actually carry.
Security in Practice#KEV#vulnerability management#CVSS#EPSS#risk register#remediation SLAs
Read more →29 July 2026 · By P LarnerBlog post
On-premise or SaaS GRC? Why your risk data deserves the self-hosted default, a fair hearing for SaaS resilience, and how to make the call properly.
Data Sovereignty & Hosting#data sovereignty#attack surface#GRC platform#self-hosting#SaaS#data custody
Read more →28 July 2026 · By P LarnerBlog post
You cannot protect, patch or monitor what you do not know you have. Every security discipline quietly assumes an accurate list of systems exists, and in most organisations that assumption is wrong. This post explains why every serious framework puts asset management first and how to build a register that actually works.
Security in Practice#discovery#reconciliation#asset management#shadow IT#inventory#CIS Controls
Read more →28 July 2026 · By P LarnerBlog post
The organisation has a low appetite for risk" isn't an appetite statement, it's a mood. Real organisations hold several appetites at once. This post makes the case for a multi-dimensional appetite profile: six to eight risk dimensions, each with its own level, rationale, tolerances, and owner
Risk Management#governance#Orange Book#tolerances#risk appetite#board reporting
Read more →25 July 2026 · By P LarnerBlog post
Threat models, risk registers and incident logs describe the same reality but cannot be joined. How the TRACE taxonomy turns four documents into one engine.
Risk Management#TRACE#incident analysis#threat taxonomy#MITRE ATT&CK#threat modelling#STRIDE
Read more →25 July 2026 · By P LarnerBlog post
How to prepare for a compliance audit: evidence hygiene through the year, control narratives, common findings, and an internal dry run before the real thing.
Security in Practice#control narratives#findings#ISO 27001#evidence#audit preparation#SOC 2
Read more →25 July 2026 · By P LarnerBlog post
The UK's NIS overhaul as it stands: MSPs and data centres in scope, 24 and 72 hour reporting clocks, turnover-linked fines, and what to do before Royal Assent.
Regulation & Legislation#Cyber Security and Resilience Bill#NIS Regulations#CAF#MSPs#NCSC#incident reporting
Read more →25 July 2026 · By P LarnerBlog post
The 24 hour, 72 hour and one month NIS2 deadlines, what each report must contain, and why the templates need writing before the incident starts.
Regulation & Legislation#NIS2#early warning#GDPR#incident reporting#CSIRT#DORA
Read more →25 July 2026 · By P LarnerBlog post
Where 5x5 matrices earn their place, where they mislead, and when quantified risk analysis is worth the effort. Most mature programmes end up using both.
Risk Management#ALE#FAIR#hybrid approach#risk matrix#quantitative risk#qualitative risk
Read more →25 July 2026 · By P LarnerBlog post
Cloud by default was never a risk decision. What offline really means, and a four-question test for which workloads genuinely belong in the cloud.
Data Sovereignty & Hosting#self-hosting#MOVEit#offline#supply chain#cloud#SaaS#data custody
Read more →