<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
    <title>Azbers Innovations articles</title>
    <link>https://azbers.com/articles/</link>
    <description>Writing on compliance, security operations and resilient infrastructure from Azbers Innovations.</description>
    <language>en</language>
    <item>
      <title>What we tell people who ask whether AI belongs in compliance work</title>
      <link>https://azbers.com/articles/article.html?a=does-ai-belong-in-compliance</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=does-ai-belong-in-compliance</guid>
      <description>The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.</description>
      <category>AI</category>
      <pubDate>2026-09-16</pubDate>
    </item>
    <item>
      <title>ISO 27001 or NIST CSF, which one should you start with</title>
      <link>https://azbers.com/articles/article.html?a=iso-27001-or-nist-csf</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=iso-27001-or-nist-csf</guid>
      <description>They are not competing standards and you are not really choosing between them. One is a certifiable management system, the other is a way of describing where you stand. Here is how to tell which you need first.</description>
      <category>Frameworks</category>
      <pubDate>2026-09-15</pubDate>
    </item>
    <item>
      <title>What continuous compliance actually means</title>
      <link>https://azbers.com/articles/article.html?a=what-is-continuous-compliance</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=what-is-continuous-compliance</guid>
      <description>The phrase is used to sell dashboards. What it really describes is a change in when evidence is produced, and that change is the only part that matters.</description>
      <category>Compliance</category>
      <pubDate>2026-09-12</pubDate>
    </item>
    <item>
      <title>The access review nobody reads</title>
      <link>https://azbers.com/articles/article.html?a=the-access-review-nobody-reads</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=the-access-review-nobody-reads</guid>
      <description>Quarterly access reviews are one of the most widely performed controls in security, and one of the least effective. The reason is not laziness. It is how we ask the question.</description>
      <category>Identity</category>
      <pubDate>2026-09-10</pubDate>
    </item>
    <item>
      <title>What happens to compliance in the six months after the audit</title>
      <link>https://azbers.com/articles/article.html?a=compliance-after-the-audit</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=compliance-after-the-audit</guid>
      <description>The assessment is almost never where a compliance programme fails. It fails quietly afterwards, in the gap between an action being agreed and anyone being able to prove it was done.</description>
      <category>Compliance</category>
      <pubDate>2026-09-08</pubDate>
    </item>
    <item>
      <title>How to answer a security questionnaire without losing a week</title>
      <link>https://azbers.com/articles/article.html?a=answering-security-questionnaires</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=answering-security-questionnaires</guid>
      <description>Two hundred rows arrive from a customer, due Friday, and the person who knows the answers is on leave. There is a way to make this a two hour job instead, and it starts long before the questionnaire arrives.</description>
      <category>Compliance</category>
      <pubDate>2026-09-05</pubDate>
    </item>
    <item>
      <title>Stop patching by severity and start patching by evidence</title>
      <link>https://azbers.com/articles/article.html?a=patching-what-is-actually-being-exploited</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=patching-what-is-actually-being-exploited</guid>
      <description>A CVSS score describes how bad a vulnerability could be in theory. It says nothing about whether anyone is using it against you. There are better signals, and they are free.</description>
      <category>Vulnerability</category>
      <pubDate>2026-09-02</pubDate>
    </item>
    <item>
      <title>Shadow AI is already in your organisation</title>
      <link>https://azbers.com/articles/article.html?a=shadow-ai-at-work</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=shadow-ai-at-work</guid>
      <description>Your staff are pasting company information into AI tools today. A ban will not stop it, it will only stop you seeing it. Here is the position that actually works.</description>
      <category>AI</category>
      <pubDate>2026-08-30</pubDate>
    </item>
    <item>
      <title>What a regulator actually wants to see</title>
      <link>https://azbers.com/articles/article.html?a=what-a-regulator-actually-wants-to-see</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=what-a-regulator-actually-wants-to-see</guid>
      <description>Most teams prepare for the wrong conversation. A regulator is not testing whether you are perfect. They are testing whether you know where you stand and can show your working.</description>
      <category>Compliance</category>
      <pubDate>2026-08-27</pubDate>
    </item>
    <item>
      <title>How to run a tabletop exercise people take seriously</title>
      <link>https://azbers.com/articles/article.html?a=how-to-run-a-tabletop-exercise</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=how-to-run-a-tabletop-exercise</guid>
      <description>Most tabletops are a meeting where everyone agrees the plan is good. A useful one finds the three decisions nobody can make, in ninety minutes, without anybody being embarrassed.</description>
      <category>Incident Response</category>
      <pubDate>2026-08-22</pubDate>
    </item>
    <item>
      <title>Critical infrastructure does not fail alone</title>
      <link>https://azbers.com/articles/article.html?a=infrastructure-fails-in-chains</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=infrastructure-fails-in-chains</guid>
      <description>Every organisation in a dependency chain can be individually compliant while the chain as a whole is assured by nobody. That gap is where national scale outages actually come from.</description>
      <category>Resilience</category>
      <pubDate>2026-08-19</pubDate>
    </item>
    <item>
      <title>The incident you will actually have</title>
      <link>https://azbers.com/articles/article.html?a=the-incident-you-will-actually-have</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=the-incident-you-will-actually-have</guid>
      <description>Most incident plans are written for a dramatic breach. The one that arrives is usually smaller, slower and more confusing, and it tests things the plan never mentions.</description>
      <category>Incident Response</category>
      <pubDate>2026-08-12</pubDate>
    </item>
    <item>
      <title>MFA is not the finish line</title>
      <link>https://azbers.com/articles/article.html?a=mfa-is-not-the-finish-line</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=mfa-is-not-the-finish-line</guid>
      <description>Multi factor authentication stopped being a complete answer some time ago. Attackers adapted, and most organisations have not. What still works, and what to fix first.</description>
      <category>Identity</category>
      <pubDate>2026-08-06</pubDate>
    </item>
    <item>
      <title>Twelve questions to answer before ransomware arrives</title>
      <link>https://azbers.com/articles/article.html?a=ransomware-readiness-questions</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=ransomware-readiness-questions</guid>
      <description>Not a product list. Twelve questions that take an afternoon to work through, and whose answers decide almost everything about how the bad week goes.</description>
      <category>Resilience</category>
      <pubDate>2026-07-30</pubDate>
    </item>
    <item>
      <title>You implemented the control once. Why are you evidencing it ten times?</title>
      <link>https://azbers.com/articles/article.html?a=one-control-many-frameworks</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=one-control-many-frameworks</guid>
      <description>Multi framework compliance multiplies paperwork rather than security. The control never changed between regimes, and treating that overlap as real is the difference between a manageable year and an impossible one.</description>
      <category>Frameworks</category>
      <pubDate>2026-07-24</pubDate>
    </item>
    <item>
      <title>Starting a Qatar information assurance programme without starting at the controls</title>
      <link>https://azbers.com/articles/article.html?a=qatar-nia-compliance-where-to-start</link>
      <guid isPermaLink="true">https://azbers.com/articles/article.html?a=qatar-nia-compliance-where-to-start</guid>
      <description>Most teams open the control list first. The framework does not expect that, and beginning there is why programmes stall six months in. The right order costs less and finishes sooner.</description>
      <category>Compliance</category>
      <pubDate>2026-07-15</pubDate>
    </item>
  </channel></rss>
