Latest issueVol. 01

GRC controls that actually hold in audit.

Thoughts, research, and practical experiences from the intersection of cybersecurity, IT audit, GRC, AI, and technology. Written to learn, document, and share.

CoveringISO 27001·NIST CSF·CIS Controls·SOC 2
Credit risk PD models that survive audit: a concise data analytical playbook
Featured
Python Automation·5 min

Credit risk PD models that survive audit: a concise data analytical playbook

A 5-minute walkthrough of a probability-of-default project — from risk question to monitored model — built so credit, finance, and audit can all sign off.

Read article

Latest

From the workbench

Credit card fraud detection: a business-minded analysis of the Kaggle dataset
Python AutomationRead
15 minAdvanced

Credit card fraud detection: a business-minded analysis of the Kaggle dataset

227,845 transactions, 394 frauds, a 0.17% base rate. An end-to-end study from EDA to a calibrated, dollar-aware threshold.

regreSSHion, xz-utils, and the year Linux supply-chain bugs got real — a defender's field guide
CybersecurityRead
11 minIntermediate

regreSSHion, xz-utils, and the year Linux supply-chain bugs got real — a defender's field guide

Two of the most consequential Linux vulnerabilities of the modern era hit within four months of each other. What actually happened, why your patching cadence almost certainly missed one of them, and the five-minute defender's checklist to run today.

Business Impact Analysis: a literature review of what actually works
ISO StandardsRead
18 minAdvanced

Business Impact Analysis: a literature review of what actually works

Forty years of BIA research, three standards, and one uncomfortable finding: most organisations run the activity backwards — collecting RTOs as opinions instead of deriving them from quantified loss curves.

Why BCMS fails when nobody quantifies the cost of one bad day
ISO StandardsRead
16 minAdvanced

Why BCMS fails when nobody quantifies the cost of one bad day

A Monte Carlo simulation of a fictitious Telco shows the architecture was structurally incompatible with the business promise — 71% of scenarios breached the 8h RTO, median ALE USD 442K without treatment.

ISO 27001 Annex A.8 mapped to NIST CSF
ISO StandardsRead
11 minIntermediate

ISO 27001 Annex A.8 mapped to NIST CSF

A working crosswalk between Annex A.8 technological controls and the five NIST CSF functions, plus what auditors actually look for.

VAPT 101: from recon to a reportable finding
VAPT & Red TeamRead
9 minBeginner

VAPT 101: from recon to a reportable finding

The end-to-end workflow of a black-box web app pen test, and what makes a finding survive client pushback.

Newsletter

One well-researched note per week.

GRC + cybersecurity + AI deep dives, written from real audit and engineering work. No filler.

Free. Unsubscribe anytime.