Insights

Analysis, guidance and practitioner perspectives.

Field-tested thinking on the certification, risk and compliance challenges our clients face.

Analysis, guidance and practitioner perspectives.
Security Standards

GSMA audit: what to expect on the day and how to prepare

A practical walkthrough of a GSMA SAS audit day — who attends, what auditors examine first, and the evidence gaps that most often become findings.

September 2026 · 11 min read
Security Standards

PCI DSS certification in Kenya: scope, cost drivers and a practical path

How cardholder-data environments in Kenya should scope PCI DSS, what drives cost, and how to combine PCI with ISO 27001 without duplicating effort.

September 2026 · 10 min read
ISO Management Systems

Transitioning to ISO/IEC 27001:2022. A practitioner's roadmap

The 2022 revision consolidates Annex A controls and introduces new attributes. Here is how to plan a defensible transition without disrupting your operations.

May 2026 · 8 min read
Governance

Board reporting on cyber risk: moving beyond heat maps

Boards are asking for quantified, comparable and decision-useful cyber risk reporting. We outline a practical model that works in mid-market organisations.

April 2026 · 6 min read
Compliance

Two years of Kenya's Data Protection Act. Enforcement lessons for global operators

The ODPC has issued a growing number of enforcement decisions. Here is what compliance leaders should be prioritising in 2026.

February 2026 · 7 min read
Security Standards

GSMA SAS: Preparing for Your First Scheme Audit

First-time SAS-UP and SAS-SM applicants consistently underestimate the physical and personnel control requirements. This practical guide walks through the scheme, the timeline, the evidence and the findings we see most often.

January 2026 · 12 min read
ISO Management Systems

The business case for integrated management systems

Organisations running three or more standards routinely duplicate effort. Integration reduces audit fatigue and unlocks measurable efficiency.

November 2025 · 5 min read
Risk

Third-party risk in financial services: a maturity model

Third parties now underpin most customer-facing services. A structured maturity model helps banks focus assurance where it matters.

October 2025 · 6 min read
WhatsAppSignalThreemaCall now