Microsoft security, squeezed
How to get the most out of the security you already pay for in your licences: Purview, Defender, Entra ID and Intune. Configurations, common mistakes and step-by-step guides.
Regulatory updates, Microsoft ecosystem security and the human factor. Practical content to protect your business — no unnecessary jargon, no fluff.
From the community, for the community
No articles match that search.
CRA reporting already applies. Which events manufacturers must report, how the deadlines work and what product, security and management teams need before the next incident.
Read article →Draft, approve and review your AI policy with practical steps, examples and an editable Word template. Connect clauses 5.2, A.2 and B.2 of ISO/IEC 42001.
Read the guide and get the template →A practical guide to the AI management system: clauses 4–10, 38 controls, risk, impact, evidence, implementation and its real relationship with the EU AI Act.
Read article →From September to December, CRA reporting, a Data Act milestone, the AI Act's new phase, digital identity and post-quantum cryptography all move forward while Spain's NIS2 transposition remains unfinished. The calendar and what to review.
Read article →Assessing your suppliers is not about sending a 100-question form to everyone. A seven-phase method anchored in ISO 27001, ISO 27036 and NIST, with tiering criteria, the domains you actually need to ask about, what to do with the answers and a free tool that builds the questionnaire as a fillable PDF.
Read article →Six different services are sold as a «cybersecurity audit» and they cost between €800 and €25,000. Market ranges in Spain in 2026, the formula every euro comes from, what pushes a quote up, seven red flags and the eight questions to ask before you sign.
Read article →From 1 September 2026 passkeys become the default sign-in method in Entra ID, and Microsoft's SMS and voice delivery shuts down completely on 1 February 2027. What changes, who it affects, and the steps to avoid getting caught out.
Read article →Almost every Microsoft 365 plan includes some Purview: the problem is rarely the licence, it is that nobody has configured it. What it solves, what each plan really brings from Business Basic to E5, the Office 365 E5 trap and a simulator to see what you are missing with yours.
Read article →A step-by-step configuration guide, from an empty policy to verifying the rollout: passkey profiles, attestation, AAGUID restrictions, passkeys in Microsoft Authenticator, registering third-party managers such as Dashlane, Temporary Access Pass, registration campaign and Conditional Access.
Read guide →The skills that actually let you lead in cybersecurity appear on no syllabus and nobody certifies them. I learned mine behind the bar of my family's business, at fourteen. What you inherit from that, what it has cost, and the five things that have served me most — none of them technical.
Read article →Spain is more than 640 days overdue and already before the Court of Justice of the EU. But the Article 21 measures come from the Directive and are not going to change. Who is in scope, what really changes between essential and important entities, the Article 23 deadlines and a free checklist to see where you stand.
Read article →The EU postpones high-risk AI system obligations to 2027-2028, but adds new prohibitions that already apply in December 2026 and formally connects AI compliance with cybersecurity. Here's what changes, plus a checklist to start today.
Read article →Practical, no-nonsense content to protect your business: industry news, things that actually work, and tips you can apply first thing Monday morning.
How to get the most out of the security you already pay for in your licences: Purview, Defender, Entra ID and Intune. Configurations, common mistakes and step-by-step guides.
ISO 27001, ENS, NIS2 and the AI Act explained without jargon or scare tactics. What they really ask of you, where to start, and how to comply without drowning your team in paperwork.
Awareness that sticks, real-world social engineering and a genuine security culture. Because the best technology is useless if your people click where they shouldn't.