ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

smb-it

  • Top 5 Cloud Misconfigurations SMBs Make

    8 min read

    The five cloud misconfigurations that breach SMBs most often — public storage buckets, over-permissive IAM, open SSH/RDP, disabled logging, and orphaned disks — each mapped to an ISO 27001:2022 Annex A control and fixed with CIS Benchmarks and CSPM.

    Read →

  • Generative AI Phishing: What It Is and How an SMB Defends

    8 min read

    Generative AI made phishing fluent, targeted, and scalable. An SMB cannot block its way out. Here is what AI-crafted phishing looks like, why the old signals fail, and the human-plus-technical defense that still works.

    Read →

  • ISO 27001 for SMBs: Why Now

    8 min read

    A pragmatic, zero-GRC-platform introduction to ISO 27001 for solo and small-team IT admins — the 2022 Annex A, the five controls that matter most, and a 90-day roadmap.

    Read →

  • How to Run Your First Tabletop Exercise: An SMB Walkthrough

    8 min read

    ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.

    Read →

  • How to Run Your First Tabletop Exercise: An SMB Walkthrough

    8 min read

    ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.

    Read →

  • Comment lire un CVE (et que faire ensuite)

    8 min read

    Arrêtez de courir après chaque alerte « Critique ». Apprenez à décoder un CVE et à prioriser les correctifs en fonction du risque réel pour votre environnement PME.

    Read →

  • A Practical SMB Patch Cadence: Risk-Based Triage Without a SOC

    8 min read

    A one- to three-person IT team cannot patch every CVE. Here is a risk-based cadence using CISA KEV and EPSS, mapped to ISO 27001:2022 controls A.8.8 and A.8.9, that keeps the business stable and the auditor satisfied.

    Read →

  • Running GDPR and ISO 27001 Together: One Program, Not Two

    8 min read

    An SMB subject to GDPR and pursuing ISO 27001 often runs the work twice. The two overlap on risk, security measures, incident response, and vendor management. Here is how to merge them into one program with shared evidence.

    Read →