Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Vulnerability & Exposure Management

  • Vulnerability & Exposure Management

    Your scanner reports hundreds or thousands of issues. Nobody agrees which ones matter, who should fix them, or by when. This pack gives you ready-made documents to settle those three questions and keep them settled.

    9 documents

Security Governance & Management

  • Security Exception, Waiver & Segregation of Duties

    Every organisation has gaps it cannot close today: a server that cannot be patched, a supplier that cannot use multi-factor sign-in, an administrator who both makes changes and approves them. The danger is the gap nobody wrote down, nobody owns and nobody revisits. This pack gives you the documents to record each gap, decide who may accept it, and make sure it ends.

    9 documents

  • Security Policy Management

    Most organisations have security policies; few have policies anyone reads. They were copied from a template years ago and name people who have left. When an auditor asks who has read them, nobody can show it. This pack helps you build a smaller set of documents that people follow, keep it current, and prove it has been read.

    9 documents

Security Metrics, Reporting & Executive Communication

  • Board Cybersecurity Reporting

    Most security reports to a board list what the team did last quarter and colour each line red, amber or green. The board nods and moves on. Nothing is decided, because nothing was put to it. This pack helps you turn a technical status update into a governance conversation.

    8 documents

Cybersecurity Risk Management

  • Information Security Risk Management

    Most risk registers are a list of vague worries such as “cyber attack”, owned by IT and scored once in a workshop. Nothing is decided, so nothing changes before the next audit. This pack helps you run a process that produces decisions: who owns each risk, whether it is acceptable, and what happens next.

    9 documents

Third-Party & Supply Chain Security

  • Third-Party Security Risk Management

    Every supplier gets the same 200-question audit, whether it runs payments or delivers office plants. Nobody reads the answers, certificates are filed without checking what they cover, and the review stalls after a dozen vendors. This pack helps you assess suppliers in proportion to the harm they could do, so the process scales to all.

    9 documents

Identity & Access Management

  • User Access Review

    A manager receives a list of 200 accounts, half of them named after roles nobody recognises. The deadline is Friday, so everything is approved in four minutes. Nobody checks the few removals requested. This pack helps you run an access review that produces genuine decisions, not bulk approvals under time pressure.

    8 documents

Regulatory & Framework Implementation

  • ISO 27001 Implementation & Certification Readiness

    A customer asks for a certificate, so someone buys a toolkit, writes forty policies and books an audit. At Stage 1 the auditor finds a scope nobody can explain, controls copied from Annex A instead of chosen from risk, and no records. This pack sets realistic expectations for a first certification: what it costs, how long it takes, and which decisions determine whether it goes well.

    9 documents