Back to home
Blog
Notes from practice: detection & response, hardening, GRC and web — short, concrete and without marketing. What I build, break and learn from.
ISO 27001 for Swiss SMEs: Effort, Costs, RoadmapWhat ISO 27001:2022 demands, when certification pays off for a Swiss SME, which costs are realistic — and a roadmap over twelve months.Read more
Hardening Microsoft 365: 12 Settings for Swiss SMEsTwelve settings in Entra ID, Exchange and SharePoint that stop most common attacks — with portal path, licence requirement and pitfalls.Read more
Open-Source GRC Tools Compared: Four Candidates for SMEsCISO Assistant, Eramba, verinice and SimpleRisk in a hands-on comparison: frameworks, risk register, operations and licence — and which tool suits which SME.Read more
CISO Assistant: GRC Without the Excel GraveyardA look at the open-source tool CISO Assistant — compliance assessments and risk register in one place, self-hosted instead of an expensive suite.Read more
M365 Assessment: Where Tenants Are Really VulnerableWhat a Microsoft 365 security assessment checks, which findings appear in almost every tenant — and why Secure Score alone is not enough.Read more
NIS2 and Switzerland: Affected Without Being a MemberThe EU directive NIS2 does not apply in Switzerland — yet it reaches Swiss companies through supply chains, subsidiaries and contracts.Read more
No posts in this category.