Blog
Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.
Penetration Testing for Startups: When, What and How Much
A startup usually needs a penetration test once it handles customer data or is asked to prove its security in a sale or audit. A pen test simulates real attacks to find exploitable weaknesses in your applications, network and cloud, then rates each finding by severity so you know what to fix first. When does…
ISO 27001 vs SOC 2: Which One Does Your Startup Need?
ISO 27001 and SOC 2 both prove to buyers that you handle data responsibly, but they are different instruments. ISO 27001 is an international certification awarded by an accredited body; SOC 2 is an attestation report written by a licensed CPA firm. Which you need is driven mainly by where your buyers are and what…
GDPR Compliance for Small Businesses: What Actually Applies
GDPR applies to a small business the moment it processes the personal data of people in the EU, regardless of headcount or turnover. Size affects how much paperwork you keep and whether you need a data protection officer, not whether the law applies. Most small firms need a lawful basis, a privacy notice and basic…
ISO 27001:2022 Explained: Structure, Controls and Certification
ISO/IEC 27001:2022 is the current version of the international standard for an information security management system (ISMS). Published in October 2022, it reorganised Annex A into 93 controls under four themes and added 11 new controls. The 2013 version is retired; 2022 is the version organisations now certify against. What ISO 27001:2022 is ISO/IEC 27001…
What is a SOC 2 Audit?
A SOC 2 audit is an independent examination of how a service organisation manages customer data against the Trust Services Criteria. Carried out by a licensed CPA firm under AICPA standards, it results in an attestation report, not a certificate, that buyers use as evidence your security and privacy controls are designed and operating properly.…
SOC 2 Type 1 vs Type 2: Which Report Do You Need?
A SOC 2 Type 1 report attests that your controls are suitably designed at a single point in time; a Type 2 report attests that those controls operated effectively over a period, commonly three to twelve months. Most buyers eventually want Type 2, but a Type 1 is a faster first step that proves your…
Data Protection by Design: Building GDPR into Your Product
Data protection by design means building privacy controls into a product from the first design decision, not bolting them on before launch. Article 25 of the GDPR makes it a legal requirement: you must apply data minimisation, purpose limitation and protective defaults by design and by default, and be able to show you did. What…
What is ISO 42001? The AI Management System Standard Explained
ISO/IEC 42001 is the first international standard for an artificial intelligence management system (AIMS). Published in December 2023, it sets out how an organisation should govern, risk-assess and continually improve the AI it builds or uses. Any organisation can certify to it, whether you develop AI or deploy someone else’s, in any sector. What ISO…
EU AI Act and ISO 42001: How the Standard Maps to the Regulation
ISO 42001 and the EU AI Act are not the same thing. The EU AI Act is binding law that regulates AI by risk level; ISO 42001 is a voluntary management-system standard. Certifying to ISO 42001 does not on its own make you AI Act compliant, but it gives you the governance backbone the regulation…
How to Interpret and Act on Penetration Test Results
A penetration test report is the document a tester gives you after the engagement, setting out every weakness found, how serious each one is, and how to fix it. Acting on it means reading the findings in priority order, remediating the critical and high issues first, then retesting to confirm the fixes hold. What does…