Publication

Insights

Analysis of European cybersecurity regulation and practice, written by the people who do the work. Named authors, dated, revised when the facts change.

Subscribe: RSS Atom

All articles

7 articles

InsightThe CRA Reporting Clock Started. Most Manufacturers Cannot Yet Meet It.The Cyber Resilience Act's vulnerability reporting obligations took effect on 11 September 2026. The timelines are measured in hours, and they assume a manufacturer already knows what is inside its own products — which is the part most organisations have not solved.Marieta MusatCybersecurity Consulting Manager, CYBERVETTERInsightThe Certificate Is Issued to a System, Not to a WeekAn audit samples a fortnight of evidence and infers a year of behaviour. That inference only holds where the management system runs on habit rather than on preparation — which is a question about people, not about documentation.Marieta MusatCybersecurity Consulting Manager, CYBERVETTERInsightSecurity Left, Security in the Cloud, and the New Question of Securing AI ItselfDevSecOps and cloud security are now well-established disciplines — but AI is reshaping both how software gets built and what security teams need to defend. A practical look at where the real risk sits, beyond the hype.Marieta MusatCybersecurity Consulting Manager, CYBERVETTERInsightAI Coding Assistants Didn't Create Supply-Chain Risk — They Accelerated ItAI-assisted development is now mainstream in most engineering teams, and it genuinely speeds delivery. It has also opened new paths into the software supply chain that traditional review processes weren't built to catch.Adrian VossSenior Consultant, CYBERVETTERInsightHardening Is Not a Project: Building Resilience Into Systems That Never Stop ChangingSecure configuration, identity management, and patching are too often treated as one-off compliance exercises. Genuine resilience comes from treating hardening as a continuous discipline — and from auditors and engineers actually talking to each other.Marieta MusatCybersecurity Consulting Manager, CYBERVETTERInsightWhat Technical Due Diligence Finds That the Questionnaire Never WillA clean vendor questionnaire and a passed compliance audit tell you what an organisation says about itself. Only hands-on technical inspection tells you what is actually running.Adrian VossSenior Consultant, CYBERVETTERInsightInside the SOC: Why Detection and Response Is a Discipline, Not a DashboardBehind every well-run Security Operations Centre is less about the tools on screen and more about triage discipline, documentation habits, and honest post-incident learning. Here is what actually separates fast, defensible incident response from slow, chaotic response.Marieta MusatCybersecurity Consulting Manager, CYBERVETTER