Playbooks

    The method, written down step by step.

    Each playbook takes one job, such as an ISMS, a risk register or a supplier review, and sets out the steps, the inputs, the owners, and the evidence each step leaves behind.

    Pillar
    Track
    Framework

    25 of 25

    BCM under ISO 22301: BIA, strategy, exercise

    Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.

    Risk5 Sept 202622 min read

    The BISO operating model

    A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.

    Governance5 Sept 202622 min read

    Board and management reporting for security

    A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.

    Governance5 Sept 202621 min read

    Control ownership and the control catalogue

    A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.

    Governance5 Sept 202622 min read

    Control testing and ITGC

    A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.

    Compliance5 Sept 202622 min read

    Choosing the CRA conformity route

    Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.

    Governance5 Sept 202622 min read

    Product & OT

    Vulnerability handling and the SBOM under the CRA

    Annex I Part II run as a process: the bill of materials, component due diligence, intake, triage, the security update, disclosure and the Article 14 record.

    Risk5 Sept 202622 min read

    Product & OT

    DORA implementation

    A method for turning DORA into a running programme: scope, framework, incidents, testing, third-party risk, and the register of information built last.

    Compliance5 Sept 202622 min read

    BFSI

    The first 90 days as a security leader

    A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.

    Governance5 Sept 202622 min read

    Incident governance

    A method for governing incidents end to end: declaration, decision records, the reporting clock across four regimes, and corrective action verified closed.

    Governance5 Sept 202622 min read

    Policy architecture people can find

    A method for turning a pile of documents into a tiered policy set with owners, review dates and exceptions, so a reader can find the rule that applies.

    Governance5 Sept 202622 min read

    Product CSMS as a management system

    Running the cyber security management system UN R155 requires as an operating system rather than a document set, on the clause pattern an ISMS already follows.

    Governance5 Sept 202622 min read

    Product & OT

    Risk acceptance and residual risk

    A method for turning "we accept that risk" into a dated record: a named approver, a residual level tested against criteria, compensating controls and an expiry.

    Risk5 Sept 202622 min read

    Running the external audit

    A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.

    Compliance5 Sept 202622 min read

    Scenario-based risk assessment

    Fifteen to forty scenarios a committee can decide on: risk sources with a desired end state, consequences over time, likelihood with a stated basis, and owners.

    Risk5 Sept 202622 min read

    Security awareness that changes behaviour

    A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.

    Governance5 Sept 202622 min read

    The security operating model

    A method for writing down how security decisions are made: the functions, the decision rights, the three lines, the interfaces and the operating calendar.

    Governance5 Sept 202622 min read

    Security strategy on one page

    A method for turning business objectives, obligations and the risk picture into five to seven measured security objectives that fit on one approved page.

    Governance5 Sept 202622 min read

    Third-party risk across the contract lifecycle

    A lifecycle method for supplier assurance: tier first, assess by tier, contract for the rights you will need, keep assurance running, and exit on plan.

    Risk5 Sept 202622 min read

    BFSI

    From regulation to controls

    A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.

    Compliance4 Sept 202622 min read

    Building an ISMS people actually use

    A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.

    Governance3 Sept 202622 min read

    The risk register other people trust

    Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.

    Risk3 Sept 202622 min read