Insights

Briefings on the shifting compliance frontier.

  • Oct 2026
    Regulatory Analysis

    The Impact of the EU Data Act on Global Cloud Infrastructure

    Portability, switching and interoperability obligations rewrite the economics of multi-national cloud procurement. A practical reading for procurement and security leaders.

  • Sep 2026
    GRC Strategy

    CMMC 2.0: Navigating the Final Rule for Level 2 Certification

    Milestones, scoping decisions and evidence priorities for defence contractors approaching their first C3PAO assessment.

  • Jul 2026
    Emerging Regulation

    Where the EU AI Act meets GDPR Article 22

    Automated decision-making sits at the seam of two regimes. Designing a single governance posture that satisfies both, without doubling the paperwork.

  • May 2026
    Product Security

    The Cyber Resilience Act for engineering leaders

    What 'security by design' actually looks like in a build pipeline, and the documentation burden conformity assessments will impose.

  • Mar 2026
    Privacy

    Transfer Impact Assessments after the UK–US Data Bridge

    A pragmatic TIA template, and the supervisory expectations behind the lines of the ICO's recent guidance.

  • Jan 2026
    Governance

    Beyond compliance: security as corporate governance

    Moving the conversation from IT cost centre to board-level strategic risk — and the reporting cadence that makes it stick.

Long-form pieces and conference talks available on request.