// Cyber Horizon Blog
GRC insights & guides
Practical compliance guides, security frameworks explained, and risk management insights — written by practitioners, for practitioners.
The NHS Data Security and Protection Toolkit (DSPT): A Practical Guide
Any organisation handling NHS patient data must complete the DSPT annually. What it assesses, how it aligns to the CAF, and how to pass without a yearly scramble.
BSI C5: Germany’s Cloud Security Standard Explained
The BSI Cloud Computing Compliance Criteria Catalogue (C5) is Germany’s benchmark for cloud-provider security. What it covers, how the auditor attestation works, and why enterprise buyers ask for it.
POPIA: South Africa’s Protection of Personal Information Act Explained
POPIA governs how organisations process personal information in South Africa. The eight conditions for lawful processing, the Information Regulator, breach rules, and how to comply.
SoA vs Risk Treatment Plan: Two Documents Teams Always Confuse
The Statement of Applicability and the Risk Treatment Plan are both required by ISO 27001 and constantly muddled. What each is for, how they connect, and how to keep them in sync.
Audit Evidence: What Auditors Actually Accept (and Reject)
Most audit pain is evidence pain. Point-in-time vs operating effectiveness, what makes a screenshot admissible, how sampling works, and how to collect evidence continuously.
User Access Reviews That Actually Pass Audits
The most-sampled control in SOC 2 and ISO 27001 audits — and the most rubber-stamped. Cadence, scope, reviewers, evidence, and how auditors catch box-ticking.
ISO 27001 Internal Audits: How to Run One That Actually Helps
Clause 9.2 requires internal ISMS audits — done well, they’re your best pre-certification dress rehearsal. The programme, auditor independence, and turning findings into improvement.
The Statement of Applicability: ISO 27001’s Most Important Document
The SoA links your risk assessment to the 93 Annex A controls — and it’s the first document your auditor opens. What it must contain and the mistakes that cause findings.
The UK Cyber Assessment Framework (CAF): A Practical Guide
The NCSC’s CAF is how UK critical infrastructure, NIS-regulated operators and government departments are assessed. The four objectives, 14 principles, and outcome-based scoring.
Want GRC insights in your inbox?
We publish practical guides regularly. No fluff, no sales pitches.