Blog

There are no posts here yet.

Rather than fill this index with three articles written to make it look inhabited, here is the state of it: nothing published, the six subject areas it will cover set out below, and links to the checklists, templates and framework pages that are already written and considerably more useful today.

Self-service signup opens shortly — we will set you up in the meantime

PublishedTitle

The index is empty.Nothing has been published. No drafts are being staged here, and no titles are being held back — there is simply nothing yet that clears the bar set out below.

0 entries
0
Posts published — the index above is the whole index
0
Newsletters, mailing lists or drip sequences on this site
6
Subject areas this will cover when it exists
No form
Every long-form page on this site is published in the open

The reasoning

An empty index is information. Filler is not.

Most security blogs in this category exist to be indexed rather than read, and every reader can tell. These are the three tests a post has to clear here, and nothing we could publish this week clears them.

  1. We have done the thing

    Nothing goes up that is assembled from other people’s posts. If we have not sat in the renewal, the audit or the questionnaire being described, there is no reason for anyone to read our version of it.

  2. It is specific enough to be wrong

    A post that cannot be disagreed with is not saying anything. If the argument does not commit to a position somebody experienced might push back on, it is filler with subheadings.

  3. It is not a product pitch in a costume

    The pages that argue for the product are already on this site and they are labelled as such. A post that turns out to be one of those with a different hat on wastes the reader’s attention and their goodwill.

Three articles written to occupy a page are not content.

The cost of filler is not paid by the company that publishes it. It is paid by the reader who spends ten minutes working out that a page with five subheadings and a stock photograph had nothing in it.

Subject areas

What this will be about, when it exists.

Topics rather than headlines, deliberately, so nothing below reads as a title we are holding back. Each one is something we deal with in the product or in an advisory engagement — which is the only qualification that makes writing about it worth anybody’s time.

Evidence that quietly expired
The most common way a readiness position turns out to be wrong: the artefact was real, the control was real, and the date on it passed eight months ago. What to put an expiry on, and what to do when half your library has none.
What a cyber application actually asks
The control questions that keep appearing on applications — privileged access, backup restoration, third parties — and what an underwriter is trying to establish with each one. Worth writing about carefully rather than dramatically, which takes longer.
ISO 27001:2022 in practice
Where first-time programmes underestimate the work — the Statement of Applicability, internal audit, management review — and how much of the standard is about running a management system rather than about controls at all.
Answering the same questionnaire for the fourth time
How to build an answer set once, what to attach to it, and how to handle the question where the honest answer is currently “no” while a deal is live.
Board reporting that survives a sceptical director
Which figures belong in front of a board, why percentages invite the wrong argument, and how to report a gap without either alarming people or burying it.
Where AI assistance actually helps, and where it does not
Drafting a policy from your own records is a reasonable use. Deciding whether a control is effective is not. Worth being specific about, given how much of this category is currently selling the second thing.

If one of those is the thing standing between you and a deadline, do not wait for a post about it. The pages on this site cover most of it already, and a direct question gets a faster answer than an article ever would.

Talk to an advisor

Where these come from

The first topic on that list is a screen, not a theory.

Every subject area above comes out of the same work: an evidence library with statuses and expiry dates, a control register with owners, and the gaps that surface when a date passes. That is why the topics are specific — and why there is no hurry to write a post about something the product already shows you.

  • 1 expired, 1 missingin the example workspace — the shape of the problem the first topic describes
  • Accepted, Under Review, Pending, Expired, Missingthe product’s own evidence vocabulary, not a maturity model invented for a diagram
  • Attached to the control and the ownerso a lapsed item reads as a gap without anybody remembering to check

See evidence workflows

EvidenceSentinel interface, reproduced

Evidence status

26 controls
  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1

Register

Expiring first
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 3 more in the workspace

Example workspace used across this site. Northstar Manufacturing Ltd. is fictional and is not a customer.

If you want to know

No subscription box, for the same reason there are no posts.

A form that collects addresses for a list which cannot legitimately be mailed yet is not a form worth filling in. If you would like to be told when there is something here, say so when you write to us and it will be noted against your enquiry.

What a blog page usually asks of you
  • A subscription box, then the same box again on scroll
  • An address collected before there is anything to send
  • Consent to be emailed, bundled into the act of asking a question
  • A sequence that starts the same afternoon
  • Your details shared with a platform you have never heard of
  • An unsubscribe buried in a preference centre with six sliders
What this page does
  • No box, on this page or any other page on this site
  • Nothing collected until there is something worth sending
  • No marketing consent box, because there is no list to consent to
  • No sequence — a person reads your message and replies to it
  • Your details are used to answer you, and are not passed on for anybody else’s marketing
  • One message ends any contact, with no preference centre in the way

In the meantime

What to read instead.

All of this is published, none of it is a placeholder, and the first two entries go further than a post would have. Start with whichever matches what is actually due.

  1. 01

    Cyber insurance, ISO 27001 and customer security questionnaires — set out item by item on the guides page, alongside the six published long-form pages that go further than any of them.

    See the guides

  2. 02

    A board cybersecurity report structure and a risk register with the fields that keep it alive. Both usable in a spreadsheet, both explained before you ask for either.

    See the templates

  3. 03

    ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls v8.1 compared by who asks for them, what each one produces, and where a framework is the wrong tool for the problem you have.

    Compare the frameworks

  4. 04

    The questions underwriters ask, the evidence behind each answer, and how to handle a gap you have not closed yet without either hiding it or losing the renewal over it.

    Prepare for a renewal

  5. 05

    Requirements, controls with owners, evidence with expiry dates, gaps, actions and readiness reporting — and what a normal week inside it looks like.

    See the workflow

  6. 06

    Data stored in Supabase in Canada (ca-central-1), application compute on Vercel in the United States, AI calls to Anthropic in the United States. Written down rather than answered on request.

    How we protect data

Questions

Fair questions about an empty page.

Six of them, answered directly — including who writes this, and what happens to your email address if you ask to be told when something appears.

Why publish an empty blog index at all?
Because the navigation points here and a link that goes nowhere is worse. This page tells you the state of things in one sentence and then sends you to material that exists. The alternative — three articles written to fill a grid — would cost you the ten minutes it takes to work out they say nothing.
When will there be posts?
When there is something worth your time that is not better said on one of the framework or product pages. We are not going to print a publication schedule here and then quietly miss it, which is the usual fate of that promise.
Will these be written by an AI?
Drafting help is a normal part of how we work and we are not going to be coy about it — the product has AI assistance in it and the AI Features Notice says how it is used in the application. What will not happen is a post generated about work nobody here has done. A person is accountable for every claim on this site, and that does not change because a draft started somewhere else.
Can I ask you to write about something?
Yes, and it is the most likely reason anything gets written first. support@cyberwave.ca reaches a person. A question from somebody in the middle of a renewal or an audit is worth more than a keyword list.
Is there a mailing list I can join?
No — there is no subscription box on this page and no newsletter anywhere on this site. Commercial email is on hold until we can send it to the Canadian standard properly, which includes carrying a real postal address in every message. Collecting addresses now, for a list that cannot legitimately be mailed yet, would be collecting them for nothing. If you want to be told when something is published, say so when you write to us and it will be noted against your enquiry.
Do you syndicate or repost other people’s writing here?
No. If somebody else has already written the definitive thing, the useful act is to link to it in a conversation rather than to reprint it with our name on top. That is also why the first test below is whether we have actually done the work being described.

Skip the reading. Bring the deadline.

If something is due — a renewal, a questionnaire, an audit someone has scheduled, a board meeting in the diary — a short conversation about that specific thing is worth more than anything this page could have published.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required