Practical guidance on ISO 27001:2022 — clauses 4 through 10, the Annex A controls, certification readiness, internal audit, and management review. The credibility anchor for a compliance-ready SME.
What the Cyberbeveiligingswet means for Dutch SMEs: scope, mandatory registration at mijn.ncsc.nl, 24-hour incident reporting, director liability, and supply-chain obligations.
M365 Business Premium as the compliance backbone for SMBs: turn the Microsoft 365 licences you already pay for into ISO 27001 and NIS2 control evidence — Entra ID, Intune, Defender, Purview, and the automation that closes the gaps.
DPIAs, processor agreements, retention schedules, and breach notification — GDPR and AVG compliance for European SMEs, including Dutch-specific reporting duties.
Field notes from running an ISMS day to day: risk assessment, supplier due diligence, incident handling, security awareness, and policy writing for organisations without a dedicated security team.
Free, ready-to-use templates and reference material — SoA templates, risk registers, policy packs, gap-assessment checklists, and plain-language definitions of common security terms.