Pillar pages
The reference articles, in long form.
One regulation, one framework, one decision per page. Citable definitions, structured FAQs, official sources, revised dates. Written from the audit room, not the academic library.
The pieces we built so you stop googling at 11pm.
Citable definition first
Forty to eighty words at the top. Built so LLMs and reports can quote one block without context.
Sourced and dated
Claims link to official or primary sources where available, with a visible revision date.
Linked to a cohort
Pillars link to relevant training where a matching cohort is available.
NIS 2: the guide that replaces your legal watch.
Everything a CISO, GRC lead or board member needs to operate under NIS 2 in 2026, scope, ten control measures, incident reporting timing, penalties, and the audit-room reality.
DORA: what your RSSI did not tell you.
A practical reading of the Digital Operational Resilience Act for European financial entities and their critical ICT providers. Five pillars, what to do first, the audit-room reality.
ISO 27001: Foundation, Lead Implementer, Lead Auditor, which one?
A practitioner's decision tree for the ISO 27001 certification levels. Who each one is for, what each exam tests, what the next step buys you, and the canonical pricing in Europe in 2026.
ISO 42001 and AI governance: the certification and training map.
Where the AI governance credentials actually fit. ISO 42001 (the AIMS standard), the ISACA Advanced in AI certifications (AAIA, AAIR, AAISM), PECB AI Risk Manager and CAIP, how they map to the EU AI Act and NIST AI RMF, and who each one is for.
AI Act: compliance without the abstraction.
A practical reading of the EU AI Act for product, security and compliance teams. Four risk tiers, what high-risk means in operations, the timeline through 2027, and how ISO 42001 fits.
Operational resilience: DORA, NIS 2 and ISO 22301 in one place.
How the three frameworks talk to each other, where the obligations overlap, and how to run one resilience programme that satisfies all three audits.
GDPR in 2026: what changed since 2018.
Where European data-protection law actually stands in 2026. Schrems II and the EU-US DPF, the AI Act interaction, recent CNIL and EDPB enforcement, what to refresh in your privacy programme.
EBIOS RM vs ISO 27005: the match.
A practical comparison of the two reference information-security risk methods. When each one wins, how they map to ISO 27001, and which one your sector and your audit actually expect.
The real price of an ISO 27001 Lead Implementer in Europe.
A 2026 benchmark of what ISO 27001 Lead Implementer cohorts actually cost in Europe. Self-paced vs instructor-led, in-house pricing, what the bundle includes, how to negotiate the corporate quote.
ISO 31000: Foundation → Risk Manager → Lead Risk Manager.
The full PECB pathway for enterprise risk management. Why ISO 31000 has no Lead Auditor, who each level fits, how it complements ISO 27005 and EBIOS RM.
CISO vs DPO vs RSSI: who does what, really.
The practical boundaries between three roles that organisations confuse. What each one is accountable for, where they overlap, and which certifications signal which role.
A pillar gets you literate. A cohort gets you certified.
Where a matching cohort exists, a pillar links to training that develops the topic further. Otherwise, browse the catalogue or ask us to map a path.