NIS2 without a national law: what the CJEU referral changes
The European Commission has referred Ireland, Spain, France and the Netherlands to the CJEU over NIS2. What already binds organisations, and what to build now.
By Adrián González · CEO
Articles 25 to 48 of 73 in this category. To search by keyword, go back to the blog hub.
The European Commission has referred Ireland, Spain, France and the Netherlands to the CJEU over NIS2. What already binds organisations, and what to build now.
By Adrián González · CEO
Brussels did not pass a law. It published an execution policy linking the AI Act to NIS2, DORA and the CRA. The nine actions, the deadlines and the operating shift it demands of CISOs.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
A deepfake of the CFO cost one firm 25.6m dollars. Why voice no longer proves identity and how to protect your payments against AI-driven CEO fraud.
By Adrián González · CEO
A penetration testing report is not read by the number of findings. Real severity, CVSS v4.0, EPSS, false positives, prioritisation and what to demand from your provider to fix what matters.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
A professional penetration test has no single price. Realistic market ranges, day rates, the factors that move the budget and how to buy penetration testing well.
By Adrián González · CEO
Shadow AI already drives 20% of breaches and adds up to 670,000 dollars per incident. What it is, why you cannot see it and how to govern it without slowing your team.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
A 16-year-old flaw in the KVM hypervisor lets a guest virtual machine break out to the host on Intel and AMD. What Januscape is and how to protect your virtualisation.
By Adrián González · CEO
A flaw in the Microsoft Defender engine spawns a SYSTEM shell on fully patched Windows 10 and 11. What RoguePlanet is, how to check your engine version and how to detect and defend against it.
By Adrián González · CEO
OWASP, PTES, OSSTMM, NIST SP 800-115 and MITRE ATT&CK: what each penetration testing methodology contributes, how they differ and how they combine in a serious test.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
Stealing AI compute is now an industry: stolen cloud credentials and exposed inference servers that hand you the bill and fuel further attacks.
By Adrián González · CEO
Nmap, Burp Suite, BloodHound, NetExec, Impacket, Hashcat: a penetration tester's real toolkit by phase, what each family validates, how it chains together and the trace it leaves.
By Adrián González · CEO
An operational guide to turning NIS2 obligations into executable controls, with audit-ready evidence and reporting that is genuinely useful to leadership.
By Irene Ocando · Directora de Cumplimiento Normativo Hard2bit
The 93 Annex A controls are not implemented all at once. These four remove the most risk per hour invested and leave auditable evidence within weeks.
By Irene Ocando · Directora de Cumplimiento Normativo Hard2bit
What to automate in an ISMS and what must stay human, with the control design step that stops you ending up with data nobody reviews.
By Adrián González · CEO
NIS2 does not only affect large operators: many supplier SMEs will have to demonstrate controls, incident response and third-party management, often through their larger customers.
By Irene Ocando · Directora de Cumplimiento Normativo Hard2bit
What an AI compliance platform must actually deliver, how to evaluate one, and the question about model governance that almost nobody asks the vendor.
By Adrián González · CEO
A complete step-by-step guide to implementing ISO 27001: scope, risk assessment, controls, documentation, internal audit and certification, and how to approach it realistically.
By Adrián González · CEO
LLMs, copilots and vibe coding are already in companies, faster than their controls. The real risks to data, code and governance, plus the shadow-AI controls to put in place.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
How recent conflicts in Ukraine and Iran shape European cybersecurity: resilience, critical infrastructure, third parties, spillover and the lessons for businesses.
By Adrián González · CEO
A practical model to prioritise OT/IT risk for European manufacturers: critical processes, remote access, NIS2, IEC 62443, metrics and a realistic roadmap.
By Thilina Manana · COO y Director Técnico de Seguridad hard2bit
A Microsoft 365 security audit checklist for businesses: Entra ID, MFA, Conditional Access, email, permissions, tenant hardening and the risks that most often appear.
By Adrián González · CEO
Vulnerability management does not fail for lack of scanners, but for poor prioritisation. What to fix first, using exploitation, exposure, asset criticality and compromised credentials.
By Adrián González · CEO
A web security checklist to review TLS, HTTP headers, DNS, DMARC, cookies, technologies, CVEs, cloud exposure, leaks, subdomains, reputation and AI readiness with Hard2bit Scanner.
By Adrián González · CEO
What malware analysis is, how it is performed, the techniques it uses and what it can reveal in a real incident: persistence, credential theft, exfiltration and more.
By Adrián González · CEO
Before you leave…
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.
No spam. Reply within 24h.