Automating ISO 27001: how to keep an ISMS alive all year
What to automate in an ISMS and what must stay human, with the control design step that stops you ending up with data nobody reviews.
By Adrián González · CEO y socio fundador
Articles 73 to 96 of 123. To search by keyword, go back to the blog hub.
What to automate in an ISMS and what must stay human, with the control design step that stops you ending up with data nobody reviews.
By Adrián González · CEO y socio fundador
NIS2 does not only affect large operators: many supplier SMEs will have to demonstrate controls, incident response and third-party management, often through their larger customers.
By Irene Ocando · Directora de Cumplimiento Normativo Hard2bit
What an AI compliance platform must actually deliver, how to evaluate one, and the question about model governance that almost nobody asks the vendor.
By Adrián González · CEO y socio fundador
A complete step-by-step guide to implementing ISO 27001: scope, risk assessment, controls, documentation, internal audit and certification, and how to approach it realistically.
By Adrián González · CEO y socio fundador
LLMs, copilots and vibe coding are already in companies, faster than their controls. The real risks to data, code and governance, plus the shadow-AI controls to put in place.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
How recent conflicts in Ukraine and Iran shape European cybersecurity: resilience, critical infrastructure, third parties, spillover and the lessons for businesses.
By Adrián González · CEO y socio fundador
What a breach linked to the European Commission reveals about supply chain, API keys, third parties, cloud, monitoring and compliance under NIS2, DORA, ENS and ISO 27001.
By Adrián González · CEO y socio fundador
A practical model to prioritise OT/IT risk for European manufacturers: critical processes, remote access, NIS2, IEC 62443, metrics and a realistic roadmap.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
A Microsoft 365 security audit checklist for businesses: Entra ID, MFA, Conditional Access, email, permissions, tenant hardening and the risks that most often appear.
By Adrián González · CEO y socio fundador
Vulnerability management does not fail for lack of scanners, but for poor prioritisation. What to fix first, using exploitation, exposure, asset criticality and compromised credentials.
By Adrián González · CEO y socio fundador
A web security checklist to review TLS, HTTP headers, DNS, DMARC, cookies, technologies, CVEs, cloud exposure, leaks, subdomains, reputation and AI readiness with Hard2bit Scanner.
By Adrián González · CEO y socio fundador
What malware analysis is, how it is performed, the techniques it uses and what it can reveal in a real incident: persistence, credential theft, exfiltration and more.
By Adrián González · CEO y socio fundador
An IT security audit identifies vulnerabilities, misconfigurations and risks that can compromise a company's systems. A practical checklist of what to review and the common failings.
By Adrián González · CEO y socio fundador
Langflow's IDOR (CVE-2026-55255) landed on CISA's KEV list on 7 July. Attackers abuse it to harvest LLM keys, cloud credentials and database secrets embedded in AI flows.
By Adrián González · CEO y socio fundador
Treating cybersecurity and compliance as separate functions no longer works. Why NIS2, DORA and modern risk management demand unified controls, evidence, governance and operations.
By Adrián González · CEO y socio fundador
An executive guide for boards on what to communicate, to whom and at what cadence during the first 24 hours of a cyber incident, aligning business, legal and technical response.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
In 2026 most incidents combine credential theft, abuse of privileged access and resilience gaps. A practical guide to prioritising measures and aligning with NIS2 and DORA.
By Adrián González · CEO y socio fundador
A red team exercise does not hunt for vulnerabilities: it validates whether your SOC detects them. The key differences, the metrics that matter and when it is worth it.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
A practical set of questions for evaluating a cybersecurity provider, MSSP or software product in 2026. Reduce hidden risk and buy with more judgement, operation and control.
By Adrián González · CEO y socio fundador
Scanning for vulnerabilities is not managing risk. How to prioritise, remediate and evidence vulnerabilities in ENS, NIS2, ISO 27001 and enterprise environments.
By Adrián González · CEO y socio fundador
Many organisations use "audit" and "pentest" interchangeably, but they are not the same. What each one reviews, when to buy which, and how to choose.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
What penetration testing is, the types that exist, how a test is run, the methodology behind it and when it genuinely makes sense for an organisation.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
What a Security Operations Centre really is, the service levels it should offer and how it maps to NIS2, DORA and ENS: monitoring, managed security and forensic investigation.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador
Vulnerability management is not just running a scanner. It includes inventory, detection, risk-based prioritisation, remediation, verification, exceptions, reporting and continuous follow-up.
By Adrián González · CEO y socio fundador
Before you leave…
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.
No spam. Reply within 24h.