Skip to content

Home » Governance and compliance

Governance and compliance guides

Guides for boards and business owners on cyber security governance, budgets, compliance and IASME Cyber Assurance, written by our testers and assessors.

Book a call

a calculator sitting on top of a table next to a laptop

How to build a defensible cyber security budget

  • 7 min read

In short. A defensible cyber security budget starts with a risk assessment, not last year’s figures or a vendor’s shopping list. Identify your most valuable assets and the threats most likely to hit them, then spread spend across people, process and technology so every pound maps to a business risk you can explain to the board. A defensible cyber security… 

man standing in front of people sitting beside table with laptop computers

How to report cyber risk to the board

  • 7 min read

In short. Boards and technical teams want the same thing, a protected business, but talk past each other. Report cyber risk in business terms: link each vulnerability to an impact, choose a few metrics that show trend, answer “so what?” every time, and bring evidence from testing rather than assurances. Technical teams and boards have the same objective when it… 

teal and white graffiti wall

Cyber security compliance checklist for UK small businesses

  • 8 min read

Which cyber security obligations apply to a UK small business (UK GDPR, PECR, PCI DSS, Cyber Essentials, sector regulators), what each actually requires, and a ten-point checklist of what to have in place and be able to evidence.

man writing on paper

IASME Cyber Assurance Level 1 vs Level 2 explained

  • 8 min read

IASME Cyber Assurance builds on Cyber Essentials to cover governance, risk, people and resilience. Level 1 is a verified self-assessment renewed annually; Level 2 is an independent audit valid for three years. Which one you need, and how it compares with ISO 27001.