Practitioner writing on security assurance, documentation and the questions Caribbean and US buyers are actually being asked.
Coming first
We publish when we have something worth reading rather than on a schedule. These are the first four pieces, in order.
| Piece | Why it matters |
|---|---|
| What a customer security questionnaire actually asks for | The strongest trigger we see. Most organizations answer from memory and cannot evidence a single line. |
| What the regional incident record actually teaches | Named, publicly reported attacks in one small market, and the control failures common to them. |
| Where data protection law really stands | Obligations that exist without an activated enforcement regime, and what that means in practice. |
| Reading a national cybersecurity framework when it lands | What to do in the first month after a framework is published, before the consultants arrive. |
If one of these would be useful before it is published, tell us and we will send a draft.
In the meantime
Four complete documents and two self-scoring workbooks, free and with no account required. They will tell you more about where you stand than anything we could write.