Skip to content
Cyber Horizon

// Cyber Horizon Blog

GRC insights & guides

Practical compliance guides, security frameworks explained, and risk management insights — written by practitioners, for practitioners.

GRCBuying GuideProcurement

How to Choose a GRC Platform: An Honest Buyer’s Checklist

We sell one of these, so read accordingly — these are the questions we would want asked of us, including the ones where our answer is no. Pricing traps, integration claims worth testing, and the signals a platform will not survive month four.

9 October 2026·9 min readRead more
Getting StartedComplianceOperations

Compliance When You’re the Only One Doing It

Every guide assumes a security team. Most companies that need one have a single person doing this alongside another job. A different order of operations built around that constraint — scope hard, automate evidence, write policy last.

2 October 2026·9 min readRead more
DORAThird-Party RiskFinancial Services

DORA for Suppliers: What ICT Providers to EU Financial Firms Must Do

DORA’s sharpest effect lands on the software companies that sell to banks, not on the banks. The contract terms your customer is obliged to extract, the register of information they will ask you to fill, and what to have ready first.

25 September 2026·9 min readRead more
ISO 27001CostCertification

What ISO 27001 Certification Actually Costs in 2026

Five vendors will quote you five numbers between £5,000 and £100,000. The spread exists because they are quoting different things. The four separate cost buckets, a worked three-year example for a 40-person SaaS, and where teams overspend.

18 September 2026·10 min readRead more
Vendor RiskThird-Party RiskTPRM

Vendor Tiering: Stop Assessing Every Supplier the Same Way

A practical model for tiering vendors by data access and criticality, matching due-diligence depth to tier, and scoring third-party risk — so your team stops drowning in questionnaires.

11 September 2026·2 min readRead more
ISO 27005Risk ManagementISMS

ISO 27005: Information Security Risk Management, Properly

How ISO 27005 turns ISO 27001’s “assess your risks” clause into a working method — context, identification, analysis, evaluation and treatment, with practical scales you can adopt.

4 September 2026·2 min readRead more
DPIAGDPRPrivacy

How to Run a DPIA That Actually Protects You

A step-by-step Data Protection Impact Assessment walkthrough — when the UK/EU GDPR requires one, how to score risk to individuals, and the mistakes that make a DPIA worthless.

28 August 2026·3 min readRead more
Risk QuantificationCRQGRC

Cyber Risk Quantification: Best Tools and GRC Platforms for Understanding Financial Impact (2026)

Compare the most effective cyber risk quantification tools and GRC platforms that translate cyber risk into financial impact — FAIR, Monte Carlo and integrated CRQ approaches.

27 August 2026·14 min readRead more
GLBAFFIECFinancial Services

GLBA & FFIEC: Security Compliance for US Financial Services

What the Gramm-Leach-Bliley Safeguards Rule actually requires, how FFIEC guidance shapes bank examinations, and a practical control checklist for lenders and fintechs.

21 August 2026·3 min readRead more

Want GRC insights in your inbox?

We publish practical guides regularly. No fluff, no sales pitches.

We’ll only use your email for these updates. See our Privacy Policy.