Threat analysis, guidance and product news
Practical reads on cyber risk, compliance and threat intelligence from the FortaRisks team.
RSS feed- Compliance
Understanding and applying ISO 27001 security risk analysis
Mastering security risk analysis protects your information assets. This guide walks you through applying it step by step under ISO 27001.
February 27, 2026 · 4 min read - Guidance
Executive Committee Memo: The 10 Questions That Prevent a "Cyber Surprise" in 2026
A practical, non-technical framework of 10 questions every Executive Committee should ask to turn reassuring cyber statements into measurable proof.
February 14, 2026 · 4 min read - Compliance
Quebec's Law 25: are you actually compliant?
Law 25 is fully in force in Quebec. Its key obligations, the deadlines, the penalties, and the gaps most organizations still underestimate.
December 5, 2025 · 3 min read - Third-Party Risk
Building a third-party risk management program that works
Vendor questionnaires are not a program. How to inventory, tier, assess and continuously monitor third parties, and close the gaps attackers exploit.
November 28, 2025 · 4 min read - Compliance
DORA: digital operational resilience, explained
DORA is in force for EU financial entities and their ICT providers. Its five pillars, the third-party rules, and what supervisors now expect you to prove.
November 14, 2025 · 4 min read - Compliance
SOC 2: what it takes to pass
SOC 2 is how you prove your controls to customers. The Trust Services Criteria, Type I vs Type II, and the gaps that stall a first audit.
October 31, 2025 · 4 min read - Compliance
The NIS2 Directive: are you ready?
NIS2 raises the cybersecurity bar across the EU, with management accountability and tight incident-reporting deadlines. What it requires, and where organizations fall short.
October 17, 2025 · 3 min read - Guidance
Cybersecurity Operating Model: 9 Dimensions for Resilience
The nine dimensions of a solid cybersecurity operating model, from business impact and CTI to identity and compliance, and why correlation wins.
February 20, 2025 · 3 min read - Threat Intelligence
2025: The Turning Point That Reshaped Cyber Risk
How 2025 industrialized cybercrime around access and identity: record ransomware, the infostealer surge, offensive AI, and the priorities it forces.
February 14, 2025 · 4 min read
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.