Passkeys and phishing-resistant MFA: SME roadmap in 2026
SMS MFA no longer satisfies enterprise customers. How to migrate to FIDO2/passkeys without chaos?
Read article: Passkeys and phishing-resistant MFA: SME roadmap in 2026 →Insights on ISO certification, NIS2, EU regulation and audit readiness in the Netherlands. Practical analysis for leadership, IT and compliance teams — educational, not legal advice.
We cover regulatory changes, audit trends and what organisations can do in practice. Each article links to topics in our knowledge base — from vendor management to processor agreements.
Free tool: Vendor & processor document generator — GDPR, ISO 27001, NIS2, DORA and more; fill in and print as PDF.
For operational ISMS work see ISO Ready. Sources: sources & linking.
Browse the articles below for the latest posts. Combine news with guides on ISO 27001 certification and NIS2 in the knowledge base.
SMS MFA no longer satisfies enterprise customers. How to migrate to FIDO2/passkeys without chaos?
Read article: Passkeys and phishing-resistant MFA: SME roadmap in 2026 →
Auditors sample CVE follow-up and patch SLAs. How to organise prioritisation and evidence without a SOC?
Read article: Patch and vulnerability management: surveillance favourite in 2026 →
High-risk AI systems face tighter deadlines. What must you document before supervision and due diligence?
Read article: AI Act high-risk: checklist for SMEs with AI applications →
Joiner-mover-leaver processes are surveillance favourites. How to link HR, IdP and SaaS with an auditable trail?
Read article: Identity lifecycle: HR to offboarding without orphaned accounts →
Joiner-mover-leaver processes are surveillance favourites. How to link HR, IdP and SaaS with an auditable trail?
Read article: Identity lifecycle: HR to offboarding without orphaned accounts →
Joiner-mover-leaver processes are surveillance favourites. How to link HR, IdP and SaaS with an auditable trail?
Read article: Identity lifecycle: HR to offboarding without orphaned accounts →
The Cyber Resilience Act requires SBOM and vulnerability disclosure for software. How to prepare your chain and due diligence?
Read article: CRA and SBOM: what software vendors must document in 2026 →
Supervisors and chain partners increasingly ask for NIS2-specific evidence. What belongs in your readiness file?
Read article: NIS2 audit readiness: preparing for supervision and chain reviews →
AWS, Azure and SaaS do not deliver compliance automatically. Which controls stay yours — and how do you prove it in ISO 27001?
Read article: Cloud shared responsibility: SoA and audit without gaps →
AWS, Azure and SaaS do not deliver compliance automatically. Which controls stay yours — and how do you prove it in ISO 27001?
Read article: Cloud shared responsibility: SoA and audit without gaps →
AWS, Azure and SaaS do not deliver compliance automatically. Which controls stay yours — and how do you prove it in ISO 27001?
Read article: Cloud shared responsibility: SoA and audit without gaps →
Insurers and auditors overlap in 2026. MFA, backup, incident response — what must be ready before renewal?
Read article: Cyber insurance and ISO 27001: evidence insurers ask for →