Guides · 3 published
What a director actually needs to know, written for someone who has two other jobs.
No gated whitepapers, no lead-capture forms in the middle of a sentence. Each guide is the version we would give a client over coffee, and each one ends in the same place: your own number.
- 01Regulation
What NIS2 Article 21 actually asks of a 50-person company
The ten cybersecurity risk-management measures of NIS2 Article 21(2), what each one means for a company of 50 to 250 people with no risk officer, the 24/72-hour reporting clock, and what management is personally on the hook for.
9 min read · 10 September 2026
- 02Crisis
The first 48 hours of a ransomware attack
What to do, in order, in the first two days of a ransomware attack at a company with no internal security team: containment, who to call, what to tell clients and staff, the legal clocks, and the decisions you must not take at 3 a.m.
11 min read · 10 September 2026
- 03Template
A business continuity plan that fits on two pages
A copy-and-fill continuity plan template for a 50 to 500-person company: critical activities, maximum tolerable downtime, the call list, four scenario sheets, and the review rhythm that keeps it from going stale. Mapped to ISO 22301 and NIS2 Article 21(2)(c).
8 min read · 10 September 2026