What we tell people who ask whether AI belongs in compliance work
The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the articleNot a product list. Twelve questions that take an afternoon to work through, and whose answers decide almost everything about how the bad week goes.

Ransomware preparation usually gets discussed as a shopping list. It is much more usefully discussed as a set of questions, because the organisations that come through it well are not the ones with the most tooling. They are the ones that had already answered these.
Work through them with the right people in a room. It takes an afternoon. Write down what you cannot answer, because that list is your actual plan.
1. Which systems must come back first, and who decided that? Not a list of everything. An ordered list, agreed by the business rather than by IT, of what gets recovered in what sequence. Arguing about this during an incident costs days.
2. When did you last restore from backup, rather than check that the backup job succeeded? Backup jobs report success far more reliably than restores actually work. Restore one important system into an isolated environment this month and record how long it took and what was missing. That number is your real recovery time.
3. Can your backups be reached from a compromised administrator account? This is the question that decides whether you have backups at all in the scenario that matters. If domain administrator can delete or encrypt them, they are not a recovery path, they are a convenience.
4. How long do your logs actually survive? Most organisations find out their real retention period during an incident, and it is usually shorter than the policy says. The activity you will care about is often older than the window you kept.
5. Who can take production offline, and what if they are unreachable at 2am? Name the person and the deputy. Write it down. This single decision, made in advance, is worth more than most of the technology on the list.
6. Who declares an incident, and on what evidence? Most plans begin after the declaration, which skips the hardest decision in the sequence. Make it safe to be wrong about calling one, because a team that fears overreacting will always underreact.
7. Who preserves evidence before anyone rebuilds? The instinct is to fix it. Rebuilding the host destroys the answer to how it started, and that answer is what your insurer and your regulator will ask for. Agree now who has authority to image first.
8. How do you communicate if your own systems are down? Email and chat may be unavailable or untrusted. An out of band channel with the numbers already in it, tested, is a ten minute job that nobody does until the first time they need it.
9. Who talks to staff, customers and press, and who approves it? Silence gets filled. If you have not decided who speaks, somebody will speak anyway and it will not be coordinated.
10. Could you produce a timeline of what happened? Built during the response rather than reconstructed from memory and chat history weeks later. This is the single most useful artefact in the months of explaining that follow.
11. Do you know your reporting obligations and the clock on them? Find out before, not during. The window is often shorter than people assume, and it starts before you have finished understanding the incident.
12. What would stop the same path working twice? The technical response ends long before the incident does. The change that closes the entry point is the part that decides whether you meet this again.
None of these twelve questions require a purchase. Most of them require an afternoon and somebody with the authority to decide.
Worth stating plainly, because it comes up in every one of these conversations.
Paying is a business decision with legal consequences that vary considerably by jurisdiction, and it is one to take advice on rather than improvise under pressure. What can be decided in advance is who would make that call, who advises them, and what the organisation's position is. Deciding that during the worst week of the year, with a countdown running, is how organisations end up somewhere they did not intend to be.
CISA publishes practical ransomware guidance, the NIST guide to computer security incident handling is the most useful public structure for the response process, and the UK National Cyber Security Centre writes some of the plainest material available on the subject regardless of where you operate.
The cheapest way to test your answers to all twelve is a tabletop exercise. Ninety minutes, the right people, and a scenario that starts ambiguously rather than dramatically. We also run DFIR engagements, including readiness work, which is considerably cheaper than the alternative.
Backups that a compromised administrator account cannot reach or delete. Almost every other control reduces the chance of an incident. That one decides whether an incident is a bad week or an existential event.
Once a quarter for the systems at the top of your recovery order, and at least once a year for everything else. The value is in the number it produces, which is how long recovery genuinely takes, not in the fact that the test happened.
That is a legal and business decision that varies by jurisdiction and circumstance, and it is one to take advice on rather than decide under pressure. What you can settle in advance is who makes the call, who advises them, and what your position is.
It can be, but read what it requires of you. Policies commonly expect specific controls to be in place and specific steps to be taken during an incident, and claims get complicated when the response destroyed the evidence needed to substantiate them.

The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the article
They are not competing standards and you are not really choosing between them. One is a certifiable management system, the other is a way of describing where you stand. Here is how to tell which you need first.
Read the article
The phrase is used to sell dashboards. What it really describes is a change in when evidence is produced, and that change is the only part that matters.
Read the articleIf this raises a question about your own compliance position or your security operations, the quickest route is a direct conversation.