// Cyber Horizon Blog
GRC insights & guides
Practical compliance guides, security frameworks explained, and risk management insights — written by practitioners, for practitioners.
How to Choose a GRC Platform: An Honest Buyer’s Checklist
We sell one of these, so read accordingly — these are the questions we would want asked of us, including the ones where our answer is no. Pricing traps, integration claims worth testing, and the signals a platform will not survive month four.
Compliance When You’re the Only One Doing It
Every guide assumes a security team. Most companies that need one have a single person doing this alongside another job. A different order of operations built around that constraint — scope hard, automate evidence, write policy last.
DORA for Suppliers: What ICT Providers to EU Financial Firms Must Do
DORA’s sharpest effect lands on the software companies that sell to banks, not on the banks. The contract terms your customer is obliged to extract, the register of information they will ask you to fill, and what to have ready first.
What ISO 27001 Certification Actually Costs in 2026
Five vendors will quote you five numbers between £5,000 and £100,000. The spread exists because they are quoting different things. The four separate cost buckets, a worked three-year example for a 40-person SaaS, and where teams overspend.
Vendor Tiering: Stop Assessing Every Supplier the Same Way
A practical model for tiering vendors by data access and criticality, matching due-diligence depth to tier, and scoring third-party risk — so your team stops drowning in questionnaires.
ISO 27005: Information Security Risk Management, Properly
How ISO 27005 turns ISO 27001’s “assess your risks” clause into a working method — context, identification, analysis, evaluation and treatment, with practical scales you can adopt.
How to Run a DPIA That Actually Protects You
A step-by-step Data Protection Impact Assessment walkthrough — when the UK/EU GDPR requires one, how to score risk to individuals, and the mistakes that make a DPIA worthless.
Cyber Risk Quantification: Best Tools and GRC Platforms for Understanding Financial Impact (2026)
Compare the most effective cyber risk quantification tools and GRC platforms that translate cyber risk into financial impact — FAIR, Monte Carlo and integrated CRQ approaches.
GLBA & FFIEC: Security Compliance for US Financial Services
What the Gramm-Leach-Bliley Safeguards Rule actually requires, how FFIEC guidance shapes bank examinations, and a practical control checklist for lenders and fintechs.
Want GRC insights in your inbox?
We publish practical guides regularly. No fluff, no sales pitches.