Back to all articles
Blog · Author

Articles by Darren Craig.

Latest articles

From the team.

How to implement NIS2 vendor monitoring in your organisationCompliance

How to implement NIS2 vendor monitoring in your organisation

NIS2 Article 21(2)(d) requires measures covering each direct supplier. Here is how to turn that obligation into a process that works at real supplier counts.

23 August 20265 min read
Read more
Vendor due diligence: what to assess before you signRisk Management

Vendor due diligence: what to assess before you sign

Vendor due diligence is the assessment you run before you sign, while you still have leverage. What to assess, how deep to go, and how it connects to onboarding.

23 August 20265 min read
Read more
How to get Cyber Essentials certifiedCompliance

How to get Cyber Essentials certified

The route to Cyber Essentials certification step by step — scope, the automatic-fail items, the clocks that catch people out, and how to verify a supplier’s certificate.

23 August 20265 min read
Read more
Cyber Essentials vs Cyber Essentials PlusCompliance

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials and Cyber Essentials Plus assess exactly the same five controls. The difference is who checks, and how — plus what that means when a supplier sends you a certificate.

23 August 20266 min read
Read more
How much does Cyber Essentials cost?Compliance

How much does Cyber Essentials cost?

The published IASME assessment fees for every organisation size, what Cyber Essentials Plus actually costs, what renewal costs, and the costs that never appear on the price list.

23 August 20267 min read
Read more
Small to Medium-Size Business: Top 8 Cyber Security Best Practices

Small to Medium-Size Business: Top 8 Cyber Security Best Practices

Security advice for SMBs is usually enterprise advice, shortened. Eight practices that survive being implemented by someone with another job — in order of what they remove.

22 August 20266 min read
Read more
Ways to Leverage Cyber Threat Intelligence

Ways to Leverage Cyber Threat Intelligence

Most organisations have threat intelligence. Far fewer can name a decision made differently because of it. Practical ways to close that gap.

22 August 20266 min read
Read more
What Are Some Malware Evasion Techniques?

What Are Some Malware Evasion Techniques?

Detection has to generalise; evasion only has to be unfamiliar once. A look at how malware avoids signatures, sandboxes and network monitoring, and which defences survive contact.

22 August 20266 min read
Read more
The Importance of Ethical Hacking: Maintaining Integrity in Cyber Security

The Importance of Ethical Hacking: Maintaining Integrity in Cyber Security

Ethical hacking borrows the attacker's method to close the defender's asymmetry. What it covers, who is qualified to do it, and the limitation every point-in-time test shares.

22 August 20268 min read
Read more
'Critical Supplier' Under the Cyber Security and Resilience Bill: Are You One, and What Happens Next?Risk Management

'Critical Supplier' Under the Cyber Security and Resilience Bill: Are You One, and What Happens Next?

The Cyber Security and Resilience Bill lets regulators designate individual suppliers as 'critical' — pulling them directly into scope even if they'd otherwise be unregulated. Here's what designation means, whether it could apply to you, and what suppliers and their customers should do now.

18 July 20266 min read
Read more
The Cyber Security and Resilience Bill: What It Means for Your SuppliersRisk Management

The Cyber Security and Resilience Bill: What It Means for Your Suppliers

The UK's Cyber Security and Resilience Bill has reached committee stage in the Lords — and for the first time, it brings your suppliers and managed service providers directly into scope. Here's what security and procurement leaders need to do now.

18 July 20266 min read
Read more
DORA Register of Information: A Complete Template and WalkthroughRisk Management

DORA Register of Information: A Complete Template and Walkthrough

The DORA Register of Information is the most data-intensive obligation in the framework: 15 interlinked templates, xBRL-CSV format, and validation that gets stricter every cycle. A complete walkthrough — structure, deadlines, the failure modes from two reporting rounds, and how to build a register that passes.

5 July 202610 min read
Read more
FCA Material Third-Party Reporting: Preparing for the March 2027 DeadlineRisk Management

FCA Material Third-Party Reporting: Preparing for the March 2027 Deadline

The FCA's material third-party reporting rules under PS26/2 come into force on 18 March 2027. Here's who's in scope, what counts as "material", what the register demands, and a month-by-month preparation plan that starts now.

5 July 20268 min read
Read more
What Is Agentic Third-Party Risk Management?Agentic AI

What Is Agentic Third-Party Risk Management?

Agentic third-party risk management uses autonomous AI agents to run the TPRM lifecycle — assessment, monitoring, remediation and reporting — rather than software that helps humans do it. Here's what that means in practice, and how it differs from automation.

5 July 20267 min read
Read more
RiskXchange vs SecurityScorecard: An Honest Comparison (2026)Risk Management

RiskXchange vs SecurityScorecard: An Honest Comparison (2026)

SecurityScorecard rates your vendors. RiskXchange puts an AI workforce to work on them. We compare data, scoring, AI capability, regulatory coverage, pricing and fit — honestly, including where SecurityScorecard wins.

5 July 20269 min read
Read more
TPRM Software Pricing: What You Should Actually Expect to Pay in 2026Risk Management

TPRM Software Pricing: What You Should Actually Expect to Pay in 2026

Almost every TPRM vendor hides its pricing. Here's what buyers actually pay in 2026 — real benchmark figures for SecurityScorecard, Bitsight, UpGuard and others, the hidden cost traps to negotiate away, and RiskXchange's published prices in full.

5 July 20267 min read
Read more
Predictive Risk Intelligence Platforms: The 2026 Guide to Proactive SecurityRisk Management

Predictive Risk Intelligence Platforms: The 2026 Guide to Proactive Security

Traditional third-party risk assessments can't keep pace with today's evolving cyber threats. Discover how predictive risk intelligence platforms use AI, machine learning, and continuous attack surface monitoring to forecast vendor risk, strengthen supply chain resilience, automate third-party risk management, and support compliance with frameworks like NIST CSF 2.0 and ISO 31000 in 2026.

3 July 202616 min read
Read more
Machine Learning for Vendor Risk Scoring: Moving Beyond Static Assessments in 2026Risk Management

Machine Learning for Vendor Risk Scoring: Moving Beyond Static Assessments in 2026

Traditional vendor risk assessments can't keep pace with today's threat landscape. Discover how machine learning for vendor risk scoring replaces static questionnaires with continuous, AI-driven monitoring, real-time security insights, and predictive risk intelligence—helping organisations strengthen third-party resilience, streamline vendor oversight, and make faster, data-driven decisions in 2026.

30 June 202616 min read
Read more
Enterprise Third-Party Risk Management: The 2026 Strategic FrameworkRisk Management

Enterprise Third-Party Risk Management: The 2026 Strategic Framework

Enterprise third-party risk management has evolved beyond annual vendor assessments into a continuous, AI-driven discipline. Learn how to unify cybersecurity, ESG, compliance, and data privacy within a single framework, automate vendor monitoring, and use real-time security ratings to strengthen supply chain resilience, simplify regulatory compliance, and proactively manage third-party risk at scale.

30 June 202615 min read
Read more
Mastering Vendor Risk Assessment Workflow Automation in 2026Risk Management

Mastering Vendor Risk Assessment Workflow Automation in 2026

Discover how vendor risk assessment workflow automation helps organisations replace manual assessments with AI-driven workflows, continuous monitoring, and real-time security ratings. Learn how to automate vendor onboarding, reduce questionnaire fatigue, strengthen compliance, and build a scalable third-party risk management programme in 2026.

30 June 202616 min read
Read more
TPRM Program Implementation Guide: A Strategic Blueprint for 2026Risk Management

TPRM Program Implementation Guide: A Strategic Blueprint for 2026

Build a scalable third-party risk management programme with this 2026 TPRM implementation guide. Learn how to establish governance, tier vendors, automate assessments, integrate continuous monitoring, and leverage AI-driven risk intelligence to strengthen compliance, improve visibility, and protect your supply chain.

30 June 202615 min read
Read more
Integrating TPRM with SIEM: A Strategic Guide for the Modern SOCRisk Management

Integrating TPRM with SIEM: A Strategic Guide for the Modern SOC

Learn how integrating TPRM with SIEM helps security teams turn vendor risk data into actionable threat intelligence. Discover how real-time risk ratings, automated alerts, and AI-driven monitoring improve incident response, reduce supply chain risk, and strengthen SOC operations with continuous third-party visibility.

29 June 202616 min read
Read more
Calculating ROI on TPRM Solutions: A Strategic Guide for 2026Risk Management

Calculating ROI on TPRM Solutions: A Strategic Guide for 2026

Learn how to modernise your vendor risk assessment process in 2026 by moving beyond static questionnaires to continuous, AI-driven risk intelligence. Discover best practices for evaluating third-party security, validating vendor claims, and building a scalable assessment framework that strengthens supply chain resilience and supports regulatory compliance.

29 June 202616 min read
Read more
Vendor Risk Remediation Best Practices for 2026: A Strategic GuideRisk Management

Vendor Risk Remediation Best Practices for 2026: A Strategic Guide

Discover the vendor risk remediation best practices every organisation needs in 2026. Learn how to prioritise critical risks, automate remediation workflows, strengthen vendor accountability, and reduce third-party cyber risk through continuous, AI-driven monitoring.

29 June 202616 min read
Read more