Insights
Notes from certification programmes and quantum readiness work
Short, specific writing on what auditors ask for, how the two standards differ in practice, and how to size quantum risk without the marketing.
Certification
18 Jun 2026
6 min read
ISO 42001 vs ISO 27001: what actually differs
Both are management system standards with the same skeleton. The difference is what you are managing, and the evidence an auditor expects.
Post-quantum
2 May 2026
5 min read
Harvest now, decrypt later: sizing the risk honestly
The threat is real but it is not universal. The deciding factor is how long your data must stay confidential.
Certification
27 Mar 2026
4 min read
What certification auditors actually ask for
Documentation is not the hard part. Demonstrating that your management system is operating is.
