top of page
Insights


How Lead Auditors Assess Risk Under ISO 27001
In my experience as a Lead Auditor, I’ve seen many organisations approach ISO 27001 risk assessment as a creative writing exercise. They’ll start by building a massive spreadsheet, filling it with ‘low, medium, high’ labels and hope I don't look too closely at the underlying detail.
But in 2026, with cyber threats evolving at machine speed, auditors have had to change their approach to adjust to a much more threatening landscape. What we’re not looking for is a perfect list
Daniel Sampson
Feb 263 min read


Managing Third Party Risk in 2026: Using ISO 27001 and ISO 42001 for Supply Chain Assurance
It’s February 2026. The traditional definition of a corporate perimeter has collapsed. In a hyper connected ecosystem driven by SaaS and integrated AI solutions, your organisation’s greatest vulnerabilities likely lie outside your own walls.
Daniel Sampson
Feb 194 min read
bottom of page