1. Compliance as code diagram showing systems and people and process converging into rules and workflows, which produce continuous compliance proof.
    Viimane

    Compliance as Code Is More Than Checking if MFA Is Enabled

    Compliance as code usually means scanning infrastructure against benchmarks. This post covers the other half: automating the organisational obligations no scanner can check (risk assessments, supplier reviews, management sign-off) without pretending a machine can perform them.

  2. E-ITSi auditit tähistav illustratsioon koos kontrollnimekirja, sertifikaadi ja turbeikoonidega.

    E-ITS ja ISO 27001 audiitorid ning konsultandid Eestis

    Ülevaade E-ITS ja ISO 27001 sertifitseerimisasutustest, audiitoritest ja konsultatsioonifirmadest Eestis — kes mida pakub ja kontaktid.

  3. E-ITSi tähistav illustratsioon küsimärkidega.

    Mis on E-ITS? Eesti infoturbestandardi praktiline juhend

    Mis on E-ITS, kellele see kohaldub ja kuidas rakendamisega alustada? Praktiline ülevaade etalonmeetmetest, auditist, ISO 27001-st ja töövahenditest.

  4. Illustration of policies, controls, risks, evidence, and tasks connected in one GRC system.

    What Is a GRC Tool? A Guide to the GRC Software Landscape

    GRC tool, GRC software, GRC platform — same category, different vendors. What they do, the three types on the market, and how to pick the right one.

  5. Two security leaders seen from behind: one struggling with scattered GRC documents and unidentified archive boxes, and the other using an organised, connected GRC system.

    Why your GRC platform might matter more to the CEO than the CISO

    A GRC platform does more than help the security team manage compliance. It protects institutional knowledge and keeps the security program running when people change.

  6. Illustratsioon AI-agendist, kes saab inimese käest API-võtme ja on ühendatud Kordoni GRC objektimudeliga: meetmed, riskid, varad, tarnijad, ülesanded ja tõendid.

    AI-agendid on uued kasutajad: kuidas neile tooteid disainida

    API kasutuskogemus on muutunud sama oluliseks kui visuaalne UX. Mida tähendab toote disainimine AI-agentidele? Mõned näited API-võtmete haldamisest ja arendaja esmakogemusest.

  7. Illustration for a blog post about canary tokens and early breach detection.

    Canary Tokens for Early Breach Detection

    Canary tokens are lightweight tripwires that alert you when someone touches data, files, or credentials they should never access. Here is what they are, which types exist, and how to align them with ISO 27001 and SOC 2 controls.

  8. Illustratsioon, mis näitab äriprotsesse ühendamas varasid, tarnijaid ja riske infoturbeprogrammis.

    Kuidas äriprotsessid ühendavad infoturbe päris eluga

    Enamik infoturbeprogramme on üles ehitatud raamistike ja meetmete ümber, mitte äritegevuse enda ümber. Selles artiklis selgitame, miks varade, riskide ja tarnijate sidumine äriprotsessidega on just see samm, mis paneb turvahalduse päriselt tööle.

  9. Access That Follows Responsibility, Not Org Charts

    Most platforms manage access by restricting it. Kordon does the opposite — access is earned by assignment and revoked the moment that assignment ends. No legacy visibility, no periodic cleanups.

  10. Illustratsioon E-ITS varade ja teenusepakkujate registri loomisest.

    Detailne juhend: Kuidas luua E-ITS varade ja teenusepakkujate register

    Praktiline juhend, kuidas kaardistada E-ITS või ISO 27001 rakendamisel varasid ja teenusepakkujaid ning luua registrid, mis toetavad päriselt riskijuhtimist ja kaitsemeetmete valikut.

  11. Illustratsioon äriprotsesside sidumisest varadega E-ITS raamistikus.

    Detailne juhend: Kuidas määratleda E-ITS äriprotsesse?

    E-ITS äriprotsesside kaardistamine ja määratlemine: praktiline samm-sammult juhend. Õpi, kuidas dokumenteerida äriprotsesse ja alustada infoturbejuhtimist.

  12. Hero image for No Warrant, No Problem: How Governments Are Building the Surveillance Super App.

    No Warrant, No Problem: How Governments Are Building the Surveillance Super App

    The U.S. Government is building a super app to monitor everyone without warrants. Where are they getting the data from and how can we protect ourselves?

  13. Illustration for an article about practical vendor tiering.

    Vendor Tiering in Practice: How to Calibrate Vendor Levels Without Overkill

    This post is about making vendor tiering meaningful, so that each tier reflects the vendor’s real exposure and operational importance and efforts can be scaled accordingly.

  14. Illustration for building a vendor risk management framework.

    How to Build a Vendor Risk Management Framework

    A practical guide to the core pieces of a vendor risk management framework and how to shape them into a repeatable, auditable process.

  15. Illustration comparing vendor management with vendor risk management.

    Vendor Management vs. Vendor Risk Management: What's the Difference?

    Clearly defining the difference between vendor management and vendor risk management helps you assign ownership correctly and avoid gaps as your organisation grows.

  16. Illustration comparing an on-premises GRC platform with a vendor-hosted cloud deployment.

    On-Premises GRC Platform: Pros, Cons, and When It Makes Sense

    Explore the practical pros and cons of choosing an on-premises GRC platform instead of a vendor-hosted cloud deployment.

  17. Illustration for an article about spam bombing and social engineering.

    How an Attacker Used 'Spam Bombing' to Gain Remote Access

    A short breakdown of how spam bombing can be used in social engineering and what teams can do to spot and resist it.

  18. Illustration for an article about security leaders being forced into reminder duty.

    You're an InfoSec Professional Not a Kinderkarten Teacher

    Every minute you spend chasing other people for security work is a minute stolen from actual security work.

  19. Illustration for making policy training more engaging.

    How To Do Policy Training Better

    Because nobody learns from a snoozefest. List of actionable small adjustments to make your trainings less boring.

  20. Illustration for essential KPIs to track the effectiveness of an information security program.

    19 Essential KPIs to Track Your ISMS's Effectiveness

    List of universal KPIs and metrics to measure the progress and effectiveness of any information security management program.

  21. Illustration for a guide about choosing useful GRC metrics and KPIs.

    GRC Metrics & KPIs Checklist with Example KPIs

    A practical checklist for choosing GRC KPIs that support risk reduction, compliance progress, and measurable improvement over time.

  22. Illustration for an article about writing clearer risk statements.

    Risk Management Fail: Mixing Causes with the Risk Itself

    People often mix up the risk itself with its potential cause or mitigation. This mistake can significantly impact how risks are understood and managed.

  23. Illustration representing a likely direction from NIS2 toward broader NIS3-style expectations.

    NIS 2 Just Came Out But We Already Know What NIS 3 Will Bring

    NIS 2 is already shifting expectations for smaller organizations. Based on current regulatory and resilience trends, we can already see what a likely NIS 3 direction would demand from SMBs.

  24. Illustration for an article about vendor drift after onboarding.

    The Highest Vendor Risk Happens AFTER Onboarding: Vendor Drift

    Vendor risk does not stop at onboarding. This post explains vendor drift, the signals to watch for, and how to monitor third-party risk over time.

  25. Illustration of scales to illustrate the idea of hidden biases in risk scoring.

    Choosing the Right Risk Matrix: Hidden Biases and How to Overcome Them

    Overview of hidden biases in risk scoring and practical ways to overcome them.

  26. Is “We Don’t Use Your Data for AI Training” Enough?

    What other ways besides training could your data be used by an AI provider and how to mitigate risks that come with that.

  27. Illustration for collaborating across the organisation to capture assets.

    How to Collaborate within the Organisation to Capture All Assets?

    Learn how to collaborate across teams, engage key stakeholders, and streamline asset discovery for a complete inventory. Simple, effective, and practical tips!

  28. How to Guide: Mapping Assets to Business Processes

    Map assets to business processes to improve security, manage risks, and prioritize protection. Learn how to uncover dependencies and avoid common pitfalls.

  29. Risk Management Software: What to Look For + 6 Tools

    Compare risk management software by what actually matters for security and compliance programs — see 6 tools, free options, and how to choose.

  30. Illustration for the ultimate guide to asset inventory management.

    The Ultimate Guide to Asset Inventory Management

    Ultimate guide on asset inventory management focusing on practical steps you can take to move beyond basic inventory tracking, using modern tools, processes, and collaboration to turn asset management into a strategic asset that continuously supports security, compliance, and operational resilience.

  31. Illustration highlighting top information security risks in 2025.

    Top Information Security Risks to monitor in 2025

    Explore the top 10 information security risks for 2025, featuring real-world examples of each threat.

  32. Illustration representing operational risks for modern organisations.

    25 Essential Operational Risks with Practical examples

    Practical real world examples of operational risks for every modern organisation to consider. Includes downloadable example risk registry CSV.

  33. Illustration showing five categories of risk modern companies should consider.

    5 categories of risk modern companies need to consider

    A deep dive into different categories of risk a modern company needs to consider, with real world examples.

  34. Illustration for asset inventory best practices in ISO 27001 compliance.

    Asset Inventory Best Practices to Build Resilience and Security

    A solid asset inventory is key to meeting ISO 27001 requirements and strengthening your security management. In this article, we’ll cover practical tips for building and maintaining an asset inventory that keeps your compliance on track and your security robust. Get ready for actionable steps you can implement right away.

Halda oma GRC programmi selgusega

Alusta tasuta ja vii meetmed, riskid ja ülesanded ühte töötavasse süsteemi.