// Cyber Horizon Blog
GRC insights & guides
Practical compliance guides, security frameworks explained, and risk management insights — written by practitioners, for practitioners.
What ISO 27001 Certification Actually Costs in 2026
Five vendors will quote you five numbers between £5,000 and £100,000. The spread exists because they are quoting different things. The four separate cost buckets, a worked three-year example for a 40-person SaaS, and where teams overspend.
Vendor Tiering: Stop Assessing Every Supplier the Same Way
A practical model for tiering vendors by data access and criticality, matching due-diligence depth to tier, and scoring third-party risk — so your team stops drowning in questionnaires.
ISO 27005: Information Security Risk Management, Properly
How ISO 27005 turns ISO 27001’s “assess your risks” clause into a working method — context, identification, analysis, evaluation and treatment, with practical scales you can adopt.
How to Run a DPIA That Actually Protects You
A step-by-step Data Protection Impact Assessment walkthrough — when the UK/EU GDPR requires one, how to score risk to individuals, and the mistakes that make a DPIA worthless.
Cyber Risk Quantification: Best Tools and GRC Platforms for Understanding Financial Impact (2026)
Compare the most effective cyber risk quantification tools and GRC platforms that translate cyber risk into financial impact — FAIR, Monte Carlo and integrated CRQ approaches.
GLBA & FFIEC: Security Compliance for US Financial Services
What the Gramm-Leach-Bliley Safeguards Rule actually requires, how FFIEC guidance shapes bank examinations, and a practical control checklist for lenders and fintechs.
ISO 31000: The Risk Management Framework That Underpins Everything
ISO 31000 is the international standard for managing risk of any kind. Its principles, framework and process — and how it gives your ISO 27001, DORA and enterprise risk work a common backbone.
The NHS Data Security and Protection Toolkit (DSPT): A Practical Guide
Any organisation handling NHS patient data must complete the DSPT annually. What it assesses, how it aligns to the CAF, and how to pass without a yearly scramble.
BSI C5: Germany’s Cloud Security Standard Explained
The BSI Cloud Computing Compliance Criteria Catalogue (C5) is Germany’s benchmark for cloud-provider security. What it covers, how the auditor attestation works, and why enterprise buyers ask for it.
Want GRC insights in your inbox?
We publish practical guides regularly. No fluff, no sales pitches.