Cyris360 Blog
Our articles provide insights, practical guidance, and expert perspectives on information security, governance, risk, compliance, and emerging cybersecurity challenges. Explore our latest publications to stay informed about industry developments, best practices, and regulatory updates.
Bitwarden Security Deep Dive
Published on 22 Apr 2026
Password managers are foundational to modern cybersecurity, enabling individuals and organizations to protect sensitive data through encryption and secure credential storage. Among them, Bitwarden stands out as a widely adopted, open-source solution built on a zero-knowledge architecture. But how secure is it against advanced threat scenarios?
- #bitwarden
- #password
- #ISO27secret001
- #encryption
- authentication
NIS2 transposition progress across European countries
Published on 1 May 2025
The NIS2 Directive, which came into effect on October 17, 2024, represents a significant regulatory shift aimed at strengthening cybersecurity resilience across the European Union (EU). Expanding upon its predecessor (NIS1), NIS2 introduces stricter security obligations, enhances incident reporting requirements, increases oversight from national cybersecurity authorities, and broadens the sectors covered under its scope.
- #NIS2
- #EU
- #Compliance
- #GRC
Risk Management under NIS2
Published on 1 Jul 2025
The NIS2 Directive raises the bar for cybersecurity governance (Art 20) and risk management measures (Art 21). That’s where ISO/IEC27001 shines, particularly in combination with its risk-based ISMS, it delivers exactly the structure and audit-ability you need to turn mere compliance into true resilience.
- #GRC
- #ISMS
- #ISO27001
- #riskmanagement
- #NIS2
NIS2 Compliance Made Easy
Published on 12 Mar 2025
The European Union’s NIS2 Directive represents a paradigm shift in cybersecurity governance, reinforcing regulatory requirements for organizations operating in critical sectors. As cyber threats grow in complexity and frequency, businesses must prepare for stricter compliance measures, enhanced security protocols, and greater accountability.
- #GRC
- #ISMS
- #ISO27001
- #compliance
- #NIS2
- #regulation
3 Reasons for Startups and Small-Organizations to implement an ISMS according to ISO/IEC 27001
Published on 15 Oct 2024
In today’s fast-paced digital economy, data is a critical asset for every organization, regardless of size. For startups and small-to-medium businesses (SMBs), agility and innovation are key advantages that fuel their early growth. However, without proper security and governance, the very flexibility that helps these companies thrive can become a double-edged sword.
- #GRC
- #ISMS
- #SMB
- #ISO27001
- #NIS2
How to leverage ISO/IEC 27001 and ISO 22301 standards to comply with NIS2 regulation
Published on 26 Mar 2024
In this article, we will go more in depth into the technical requirements specified in Article 21, and we will show how implementing an ISO27001-compliant Information Security Management System (ISMS) in combination with ISO22301-compliant Business Continuity Management System (BCMS) can greatly benefit your journey to prepare for NIS2 compliance.
- #GRC
- #ISMS
- #BCMS
- #ISO27001
- #ISO22301
- #NIS2
A guide to implementing the new ISO 27001 Controls [3/3]
Published on 1 Feb 2024
In this last part 3 of this article, we will provide a general description and a few guidelines on the implementation of one new control in physical category, namely 7.4, and three (out of seven) new controls in technological category, namely: 8.16, 8.23 and 8.28 (all highlighted in bold characters).
- #GRC
- #ISMS
- #ISO27001
- #infosec
- #NIS2
A guide to implementing the new ISO 27001 Controls [2/3]
Published on 30 Jan 2024
In the current part 2 of this article, we will provide a general description and a few guidelines on the implementation of four (out of seven) consecutive new controls in technological category, namely: 8.9, 8.10, 8.11 and 8.12 (highlighted in bold characters).
- #GRC
- #ISMS
- #ISO27001
- #infosec
- #NIS2
A guide to implementing the new ISO 27001 Controls [1/3]
Published on 26 Jan 2024
In part 1 of this article, we will provide a general description and a few guidelines on the implementation of the new controls in organizational category, namely: 5.7, 5.23, and 5.30 (highlighted in bold characters).
- #GRC
- #ISMS
- #ISO27001
- #infosec
- #NIS2
