Blog
There are no posts here yet.
Rather than fill this index with three articles written to make it look inhabited, here is the state of it: nothing published, the six subject areas it will cover set out below, and links to the checklists, templates and framework pages that are already written and considerably more useful today.
Self-service signup opens shortly — we will set you up in the meantime
The index is empty.Nothing has been published. No drafts are being staged here, and no titles are being held back — there is simply nothing yet that clears the bar set out below.
The reasoning
An empty index is information. Filler is not.
Most security blogs in this category exist to be indexed rather than read, and every reader can tell. These are the three tests a post has to clear here, and nothing we could publish this week clears them.
We have done the thing
Nothing goes up that is assembled from other people’s posts. If we have not sat in the renewal, the audit or the questionnaire being described, there is no reason for anyone to read our version of it.
It is specific enough to be wrong
A post that cannot be disagreed with is not saying anything. If the argument does not commit to a position somebody experienced might push back on, it is filler with subheadings.
It is not a product pitch in a costume
The pages that argue for the product are already on this site and they are labelled as such. A post that turns out to be one of those with a different hat on wastes the reader’s attention and their goodwill.
Three articles written to occupy a page are not content.
The cost of filler is not paid by the company that publishes it. It is paid by the reader who spends ten minutes working out that a page with five subheadings and a stock photograph had nothing in it.
Subject areas
What this will be about, when it exists.
Topics rather than headlines, deliberately, so nothing below reads as a title we are holding back. Each one is something we deal with in the product or in an advisory engagement — which is the only qualification that makes writing about it worth anybody’s time.
- Evidence that quietly expired
- The most common way a readiness position turns out to be wrong: the artefact was real, the control was real, and the date on it passed eight months ago. What to put an expiry on, and what to do when half your library has none.
- What a cyber application actually asks
- The control questions that keep appearing on applications — privileged access, backup restoration, third parties — and what an underwriter is trying to establish with each one. Worth writing about carefully rather than dramatically, which takes longer.
- ISO 27001:2022 in practice
- Where first-time programmes underestimate the work — the Statement of Applicability, internal audit, management review — and how much of the standard is about running a management system rather than about controls at all.
- Answering the same questionnaire for the fourth time
- How to build an answer set once, what to attach to it, and how to handle the question where the honest answer is currently “no” while a deal is live.
- Board reporting that survives a sceptical director
- Which figures belong in front of a board, why percentages invite the wrong argument, and how to report a gap without either alarming people or burying it.
- Where AI assistance actually helps, and where it does not
- Drafting a policy from your own records is a reasonable use. Deciding whether a control is effective is not. Worth being specific about, given how much of this category is currently selling the second thing.
If one of those is the thing standing between you and a deadline, do not wait for a post about it. The pages on this site cover most of it already, and a direct question gets a faster answer than an article ever would.
Where these come from
The first topic on that list is a screen, not a theory.
Every subject area above comes out of the same work: an evidence library with statuses and expiry dates, a control register with owners, and the gaps that surface when a date passes. That is why the topics are specific — and why there is no hurry to write a post about something the product already shows you.
- 1 expired, 1 missing — in the example workspace — the shape of the problem the first topic describes
- Accepted, Under Review, Pending, Expired, Missing — the product’s own evidence vocabulary, not a maturity model invented for a diagram
- Attached to the control and the owner — so a lapsed item reads as a gap without anybody remembering to check
Evidence status
26 controls- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
Register
Expiring first| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
| MFA enforcement — Microsoft 365 Conditional Access | A.8.5 | Priya Raman | Accepted | Valid to 14 Aug 2027 |
| EDR coverage report — 98% of endpoints | A.8.7 | Jordan Blake | Accepted | Valid to 28 Nov 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 3 more in the workspace
Example workspace used across this site. Northstar Manufacturing Ltd. is fictional and is not a customer.
If you want to know
No subscription box, for the same reason there are no posts.
A form that collects addresses for a list which cannot legitimately be mailed yet is not a form worth filling in. If you would like to be told when there is something here, say so when you write to us and it will be noted against your enquiry.
- A subscription box, then the same box again on scroll
- An address collected before there is anything to send
- Consent to be emailed, bundled into the act of asking a question
- A sequence that starts the same afternoon
- Your details shared with a platform you have never heard of
- An unsubscribe buried in a preference centre with six sliders
- No box, on this page or any other page on this site
- Nothing collected until there is something worth sending
- No marketing consent box, because there is no list to consent to
- No sequence — a person reads your message and replies to it
- Your details are used to answer you, and are not passed on for anybody else’s marketing
- One message ends any contact, with no preference centre in the way
In the meantime
What to read instead.
All of this is published, none of it is a placeholder, and the first two entries go further than a post would have. Start with whichever matches what is actually due.
- 01
Cyber insurance, ISO 27001 and customer security questionnaires — set out item by item on the guides page, alongside the six published long-form pages that go further than any of them.
- 02
Templates
2 working templates, field by field
A board cybersecurity report structure and a risk register with the fields that keep it alive. Both usable in a spreadsheet, both explained before you ask for either.
- 03
Frameworks
Which framework you actually need
ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls v8.1 compared by who asks for them, what each one produces, and where a framework is the wrong tool for the problem you have.
- 04
Insurance
Getting through a renewal
The questions underwriters ask, the evidence behind each answer, and how to handle a gap you have not closed yet without either hiding it or losing the renewal over it.
- 05
Product
How Sentinel is put together
Requirements, controls with owners, evidence with expiry dates, gaps, actions and readiness reporting — and what a normal week inside it looks like.
- 06
Data stored in Supabase in Canada (ca-central-1), application compute on Vercel in the United States, AI calls to Anthropic in the United States. Written down rather than answered on request.
Questions
Fair questions about an empty page.
Six of them, answered directly — including who writes this, and what happens to your email address if you ask to be told when something appears.
Why publish an empty blog index at all?
When will there be posts?
Will these be written by an AI?
Can I ask you to write about something?
Is there a mailing list I can join?
Do you syndicate or repost other people’s writing here?
Skip the reading. Bring the deadline.
If something is due — a renewal, a questionnaire, an audit someone has scheduled, a board meeting in the diary — a short conversation about that specific thing is worth more than anything this page could have published.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required