Insights

    We publish when there is something to say, which is not the same as publishing on a schedule. Three things tend to prompt it: a regulation changing under people's feet, a pattern we keep meeting in engagements, and a claim in this market that does not survive contact with practice.

    What we write about

    • Regulation, as it actually applies to you. NIS2 and the Cyberbeveiligingswet, DORA, the EU AI Act and its recent amendment, the Cyber Resilience Act, and the Moroccan regime — written as what you owe and when, rather than as a summary of the text.
    • AI that reaches production. What separates the systems that survive month nine from the pilots that impressed a room, and the governance that makes the difference.
    • Sovereignty, concretely. Where a workload may run, what a provider's terms actually say, and what changes when the answer has to be defensible to a client rather than comfortable internally.

    Articles

    AIGovernance

    The Quiet Risk in Pharma's AI Rush: Nobody Owns the Governance

    Everyone in pharma is talking about AI adoption. Far fewer are talking about who is accountable when an AI system gets a decision wrong, and regulators have already started asking.

    3 August 2026Read article
    AIGovernance

    AI Transformation Is an Operating Model Change, not a Software Purchase

    Most AI efforts die between a successful pilot and a real shift in how work gets done. The technology is rarely the constraint, the operating model is.

    3 August 2026Read article
    AIGovernance

    Nobody's Been Fined Under the EU AI Act Yet. People Are Already Losing Deals Because of It.

    Enforcement is slow, but procurement is not. The EU AI Act quietly rewrote the due diligence checklist in RFPs and term sheets, and most companies still cannot answer it in under a week.

    3 August 2026Read article
    AICloud

    AI and Cloud Transformation

    AI and cloud technologies are increasingly inseparable in modern digital transformation initiatives. Together, they form the foundation for intelligent, adaptive, and scalable enterprises.

    11 February 2026Read article
    CybersecurityThreat Hunting

    Threat Hunting: The Future of Cyber Resilience

    For a long time, cybersecurity was limited to detecting and then reacting. Security Operations Centers (SOCs) have relied on solutions such as SIEM, EDR and next-generation antivirus.

    5 September 2025Read article
    CybersecurityCTI

    Cyber Threat Intelligence (CTI): From Monitoring to Action

    Digital transformation, the widespread use of remote work and the industrialization of threats have profoundly disrupted the traditional balances of cybersecurity.

    9 July 2025Read article
    CybersecurityMonitoring

    What is Cyberthreat Monitoring?

    Cyberthreat monitoring refers to all practices, tools and methods aimed at detecting computer threats likely to target an information system in real time.

    23 June 2025Read article
    Enterprise ArchitectureDigital Strategy

    Enterprise Architects: Discreet Yet Essential Pillars of Strategic Transformation

    In an era where the alignment of IT and business strategies is no longer optional but a core driver of competitiveness, the role of Enterprise Architects has never been more critical.

    27 May 2025Read article
    CybersecurityInsider Threats

    Insider Risks: What If the Real Threat Came From Within?

    Cyberattacks are often referred to as an external danger. Yet a much quieter, but equally dangerous, reality persists internally.

    13 May 2025Read article
    CybersecurityISS

    ISS ≠ Cybersecurity: Why Confusing the Two Leaves You Exposed

    One of the most common mistakes organizations make is treating Information Systems Security (ISS) and cybersecurity as interchangeable.

    22 April 2025Read article

    Everything here is written by the people who do the work. Where we state a regulatory position we give the instrument and the date, because a claim you cannot check is a claim you should not act on — and because this material changes: the EU AI Act's literacy duty was rewritten in July 2026, and a good deal of what is published elsewhere has not caught up.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.