Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN · FR
Test access Book a demo
Blog

Notes from the field

Practical writing on risk management, third-party risk, the threat landscape and EU compliance, by the consultants who build and run SynapseRM / TPRM.

REGULATION
The risk register: the document every framework assumes you have

NIS2, DORA and ISO 27001 never use the words "risk register" for your internal risks, yet none of their obligations can be met without one. A walk through the actual articles.

5 MIN READ  →
AI ACT & DORA
The EU AI Act, DORA and your AI: what a bank actually has to prove

The AI Act's high-risk deadline moved to December 2027, but some AI uses are already banned and DORA has governed your ICT since January 2025. What counts as high-risk banking AI, why DORA already covers it, and the evidence a supervisor will expect.

6 MIN READ  →
RISK MANAGEMENT
Four things a spreadsheet will never do for your risk programme

Almost every risk programme starts in a spreadsheet. The problems appear later: no single view, no history, no supplier oversight, no alerts. Here is why they are structural, not user errors.

2 MIN READ  →
RISK ASSESSMENT
Your analysts should review risk assessments, not retype them

Every new project restarts the same analysis: the same requirements rewritten, scoring drifting between analysts, a backlog growing faster than the team. Automation changes what the job is.

2 MIN READ  →
THIRD-PARTY RISK
Your next breach may arrive through a supplier

Most third-party programmes stop at onboarding: one questionnaire, filed and forgotten. Regulators now expect a lifecycle. Here is what continuous supplier oversight looks like in practice.

2 MIN READ  →
PLATFORM
Twelve modules, one data model: why integration beats tooling

Risk in one tool, assets in another, findings in a tracker, exceptions in a document. Each is fine alone; together they produce reconciliation work. What changes when everything references one record.

2 MIN READ  →
THIRD-PARTY RISK
Vendor tiering: stop sending the same questionnaire to every supplier

A flat third-party programme over-assesses the trivial and under-assesses the critical. Tiering is how proportionality becomes operational.

6 MIN READ  →
BUSINESS IMPACT
Before you score the risk, score the asset

Every endless impact debate in a risk workshop is an unresolved question about asset criticality. A case for the business impact assessment, with your own level definitions and a fourth letter: traceability.

5 MIN READ  →
PATCH MANAGEMENT
Patch Tuesday, August 2026: 394 fixes and three zero-days

Microsoft shipped 394 fixes in August 2026, including three zero-days. Which to patch first, and how a maintained register turns a wall of CVEs into a short list.

12 AUGUST 2026 · 2 MIN READ  →
BOTNET / IoT
Kimwolf: the botnet that hides its brain on the blockchain

The Kimwolf botnet spreads through exposed Android Debug Bridge and resolves its command server through Ethereum and Tor. Why a TV-box botnet is a corporate risk.

13 AUGUST 2026 · 2 MIN READ  →
ACTIVE DIRECTORY
One certificate to rule them all: how ESC1 turns a user into a domain admin

A misconfigured certificate template lets an ordinary user request a certificate as the domain administrator. How ESC1 works, how to detect it, and how to close it.

14 AUGUST 2026 · 2 MIN READ  →
ZERO-DAY
Zoomsday: a zero-click RCE, and the day exploit development got cheap

A zero-click chain in Zoom lets one message compromise every participant. The alarming part is not the bug, it is that it was found with fewer than 20 AI prompts.

14 AUGUST 2026 · 2 MIN READ  →
SOCIAL ENGINEERING
The phishing family tree, from spear phishing to QR codes

Spear phishing, whaling, smishing, vishing, quishing (QR codes) and adversary-in-the-middle: a clear map of the phishing family, and why naming them makes your defence testable.

15 AUGUST 2026 · 7 MIN READ  →
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Careers Labs Privacy & cookies
Brussels, Belgium