NIS2, DORA and ISO 27001 never use the words "risk register" for your internal risks, yet none of their obligations can be met without one. A walk through the actual articles.
The AI Act's high-risk deadline moved to December 2027, but some AI uses are already banned and DORA has governed your ICT since January 2025. What counts as high-risk banking AI, why DORA already covers it, and the evidence a supervisor will expect.
Almost every risk programme starts in a spreadsheet. The problems appear later: no single view, no history, no supplier oversight, no alerts. Here is why they are structural, not user errors.
Every new project restarts the same analysis: the same requirements rewritten, scoring drifting between analysts, a backlog growing faster than the team. Automation changes what the job is.
Most third-party programmes stop at onboarding: one questionnaire, filed and forgotten. Regulators now expect a lifecycle. Here is what continuous supplier oversight looks like in practice.
Risk in one tool, assets in another, findings in a tracker, exceptions in a document. Each is fine alone; together they produce reconciliation work. What changes when everything references one record.
A flat third-party programme over-assesses the trivial and under-assesses the critical. Tiering is how proportionality becomes operational.
Every endless impact debate in a risk workshop is an unresolved question about asset criticality. A case for the business impact assessment, with your own level definitions and a fourth letter: traceability.
Microsoft shipped 394 fixes in August 2026, including three zero-days. Which to patch first, and how a maintained register turns a wall of CVEs into a short list.
The Kimwolf botnet spreads through exposed Android Debug Bridge and resolves its command server through Ethereum and Tor. Why a TV-box botnet is a corporate risk.
A misconfigured certificate template lets an ordinary user request a certificate as the domain administrator. How ESC1 works, how to detect it, and how to close it.
A zero-click chain in Zoom lets one message compromise every participant. The alarming part is not the bug, it is that it was found with fewer than 20 AI prompts.
Spear phishing, whaling, smishing, vishing, quishing (QR codes) and adversary-in-the-middle: a clear map of the phishing family, and why naming them makes your defence testable.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.