Blog

Cybersecurity explained in language that actually makes sense.

Regulatory updates, Microsoft ecosystem security and the human factor. Practical content to protect your business — no unnecessary jargon, no fluff.

From the community, for the community

Cyber Resilience Act in 2026: what changes with the reporting obligations

CybersecurityCompliance

CRA reporting already applies. Which events manufacturers must report, how the deadlines work and what product, security and management teams need before the next incident.

Read article

How to write an AI policy using ISO/IEC 42001

GuidesCompliance

Draft, approve and review your AI policy with practical steps, examples and an editable Word template. Connect clauses 5.2, A.2 and B.2 of ISO/IEC 42001.

Read the guide and get the template

ISO/IEC 42001: what it is, how it is structured and what managing artificial intelligence really means

Artificial Intelligence Compliance

A practical guide to the AI management system: clauses 4–10, 38 controls, risk, impact, evidence, implementation and its real relationship with the EU AI Act.

Read article

Cybersecurity in the final stretch of 2026: CRA, AI Act, NIS2 and the milestones after summer

Cybersecurity Compliance Artificial Intelligence NIS2

From September to December, CRA reporting, a Data Act milestone, the AI Act's new phase, digital identity and post-quantum cryptography all move forward while Spain's NIS2 transposition remains unfinished. The calendar and what to review.

Read article

How do I assess my suppliers' cybersecurity?

Cybersecurity SMEs Supply chain Compliance TPRM

Assessing your suppliers is not about sending a 100-question form to everyone. A seven-phase method anchored in ISO 27001, ISO 27036 and NIST, with tiering criteria, the domains you actually need to ask about, what to do with the answers and a free tool that builds the questionnaire as a fillable PDF.

Read article

How much does a cybersecurity audit cost for an SME? Real ranges, no fluff

Cybersecurity SMEs Budget Compliance

Six different services are sold as a «cybersecurity audit» and they cost between €800 and €25,000. Market ranges in Spain in 2026, the formula every euro comes from, what pushes a quote up, seven red flags and the eight questions to ask before you sign.

Read article

Microsoft Entra ID retires SMS and voice call: what changes, when, and how to migrate to passkeys

Microsoft 365 Cybersecurity

From 1 September 2026 passkeys become the default sign-in method in Entra ID, and Microsoft's SMS and voice delivery shuts down completely on 1 February 2027. What changes, who it affects, and the steps to avoid getting caught out.

Read article

Microsoft Purview: what it is, what you can do with it and what each licence includes

Microsoft 365 Data protection Compliance Cybersecurity

Almost every Microsoft 365 plan includes some Purview: the problem is rarely the licence, it is that nobody has configured it. What it solves, what each plan really brings from Business Basic to E5, the Office 365 E5 trap and a simulator to see what you are missing with yours.

Read article

Guide: configuring passkeys in Microsoft Entra ID

Guides Microsoft 365 Cybersecurity

A step-by-step configuration guide, from an empty policy to verifying the rollout: passkey profiles, attestation, AAGUID restrictions, passkeys in Microsoft Authenticator, registering third-party managers such as Dashlane, Temporary Access Pass, registration campaign and Conditional Access.

Read guide

I've been in cybersecurity five years, and they feel like ten

Personal Leadership Cybersecurity

The skills that actually let you lead in cybersecurity appear on no syllabus and nobody certifies them. I learned mine behind the bar of my family's business, at fourteen. What you inherit from that, what it has cost, and the five things that have served me most — none of them technical.

Read article

NIS2 in Spain 2026: what already binds you and how to check it in 5 minutes

NIS2 Compliance Cybersecurity

Spain is more than 640 days overdue and already before the Court of Justice of the EU. But the Article 21 measures come from the Directive and are not going to change. Who is in scope, what really changes between essential and important entities, the Article 23 deadlines and a free checklist to see where you stand.

Read article

The AI Digital Omnibus: what Regulation (EU) 2026/1744 changes and what companies must do

Cybersecurity Compliance Artificial Intelligence

The EU postpones high-risk AI system obligations to 2027-2028, but adds new prohibitions that already apply in December 2026 and formally connects AI compliance with cybersecurity. Here's what changes, plus a checklist to start today.

Read article
Topics

What I write about

Practical, no-nonsense content to protect your business: industry news, things that actually work, and tips you can apply first thing Monday morning.

01

Microsoft security, squeezed

How to get the most out of the security you already pay for in your licences: Purview, Defender, Entra ID and Intune. Configurations, common mistakes and step-by-step guides.

Microsoft 365 Purview Defender Entra ID
02

Compliance in plain English

ISO 27001, ENS, NIS2 and the AI Act explained without jargon or scare tactics. What they really ask of you, where to start, and how to comply without drowning your team in paperwork.

ISO 27001 ENS NIS2 AI Act
03

The human factor

Awareness that sticks, real-world social engineering and a genuine security culture. Because the best technology is useless if your people click where they shouldn't.

Awareness Social engineering Culture