Field notes
Blog
Long-form pieces on the work of doing compliance and security inside a small company.
Evergreen and updated as the underlying regulations and practices change.
Cyber Insurance · Last reviewed 2026-07-18 · ~7 min read
The renewal form is underwriting, not admin: your answers shape your premium, your cover, and whether a claim is paid without a fight. What each control question is really asking, why an optimistic yes is the expensive kind, the evidence to keep for the worst day, and the sixty-day clock that makes next year's form an hour's work.
Read →
Product Security · Last reviewed 2026-07-01 · ~8 min read
If you sell software into the European Union, the Cyber Resilience Act's reporting duty starts 11 September 2026 — and it covers products already on the market. What counts as a product with digital elements, the 24-hour early warning, the 2027 main obligations, and the five things a small vendor can do this quarter without a compliance department.
Read →
GDPR · Live Breach · Last reviewed 2026-07-01 · ~8 min read
The regulator's 72-hour filing is one letter; the harder audience is the customers whose data it was. The three notification duties and their different clocks — including the contract clauses that often run shorter than the law — the five questions every good notice answers, the failure modes everyone recognises, and the holding-statement pattern that buys trust back.
Read →
SOC 2 · Last reviewed 2026-07-01 · ~7 min read
“Send us your SOC 2” stopped the deal — but SOC 2 is the most commonly premature purchase in small-company security. What the report actually is, what buyers actually want, Type I versus Type II in plain terms, a three-question test with real numbers, and what to build while the answer is still “not yet”.
Read →
SOC 2 · ISO 27001 · Last reviewed 2026-07-01 · ~7 min read
One produces a confidential report, the other a public certificate — and which one your buyer wants is mostly determined by facts you already know. The geography rule and its exceptions, why the underlying work overlaps more than the paperwork does, and a four-step decision path for choosing your first credential.
Read →
AI Security · Last reviewed 2026-07-01 · ~9 min read
Someone at your company pasted something into an Artificial Intelligence chatbot today. Why bans fail, the four kinds of data that should stay out of unapproved tools, what “trains on your data” actually means across account tiers, and the one-page AI-use policy you can write this afternoon.
Read →
Cloud Security · Last reviewed 2026-07-01 · ~7 min read
The account was built by a contractor who left, it runs production, and now it is yours. A first week for an inherited cloud account: find every account through billing, take the root credentials, remove leavers and dormant keys, turn the audit logs on, find what is public — and the three things not to do in week one.
Read →
Vulnerability Management · Last reviewed 2026-07-01 · ~7 min read
A first vulnerability scan always produces a wall of red — the number is normal. Why raw counts and severity scores mislead, the three questions that shrink four thousand findings to the forty that matter, the one-fix-many pass that collapses the count, and the four-part programme reviewers actually ask about.
Read →
Live Incident · Last reviewed 2026-07-01 · ~8 min read
The follow-up to the first-hour piece: how to actually run the exercise. The 60-minute format with three injects, a ready-to-use first scenario, why the person who can spend money must be in the room, and the traps — fixing the scenario instead of the process, lectures disguised as exercises, and action items with no names on them.
Read →
GDPR · Last reviewed 2026-05-30 · ~10 min read
Every activity that touches personal data needs one of six General Data Protection Regulation lawful bases — and most teams reach for consent when they shouldn't. A plain-English walk through all six (consent, contract, legal obligation, vital interests, public task, legitimate interests), the extra Article 9 condition that special-category data needs on top, and a single-question test for picking the right one. For founders, privacy leads, fractional Data Protection Officers, and anyone mapping their Records of Processing Activities.
Read →
Product Security · Last reviewed 2026-05-30 · ~9 min read
A security researcher just emailed you about a flaw in your product. The one workflow that handles every report: the eight stages from acknowledgement to disclosure, the 24-hour clock that prevents most disclosure conflicts, where the path branches, and the three cases that need special handling. For founders and product teams standing up a Product Security Incident Response Team for the first time.
Read →
Small-Business Security · Last reviewed 2026-05-30 · ~9 min read
Five concrete fixes, in priority order, that address the most common ways small businesses actually get compromised: Multi-Factor Authentication on email and finance, removing dormant accounts, a password manager, an offboarding checklist, and backups you have actually tested. No security team required; most of it fits in a single afternoon.
Read →
Security Questionnaires · Last reviewed 2026-05-30 · ~9 min read
A customer sent two hundred security questions before they will buy. How to answer well, fast, and reusably: read before you write, build an answer bank you keep, the four honest answers that beat a fake "yes," and when to publish a public overview so buyers stop sending the questionnaire at all.
Read →
Live Incident · Last reviewed 2026-05-30 · ~9 min read
What to do, what not to do, and what most people get wrong in the first 60 minutes after the page goes off. For on-call engineers, IT leads, and founder-CISOs at small teams. Covers the first ten minutes (is this real / outage vs compromise / who needs to know), the next twenty (open the log), thirty-to-forty-five (containment decision), forty-five-to-sixty (communications and regulatory clock check), and what good looks like at the sixty-minute mark.
Read →
GDPR · Live Breach · Last reviewed 2026-05-30 · ~10 min read
The General Data Protection Regulation Article 33 deadline. The awareness moment. The four most common ways the clock is mis-started — and a careful walk through phased notification under Article 33(4). For Data Protection Officers, fractional DPOs, privacy leads, and founder-CISOs handling their first GDPR breach response.
Read →
Each Sylvan Assurance toolkit comes with the evergreen content that is its companion (the 72-hour-clock piece is the public companion to the GDPR Breach Response toolkit; the first-hour piece is the public companion to First 4 Hours).