<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Ellipse Project blog</title>
  <link>https://ellipseproject.com/blog/</link>
  <description>Ellipse Project — independent information security risk assessment, audit, and awareness consultancy for European mid-market organisations.</description>
  <language>en</language>
  <lastBuildDate>2026-04-15</lastBuildDate>
  <atom:link href="https://ellipseproject.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>NIS2 — what is actually different, and what is repackaged</title>
      <link>https://ellipseproject.com/blog/nis2-actually-different.html</link>
      <guid isPermaLink="true">https://ellipseproject.com/blog/nis2-actually-different.html</guid>
      <pubDate>2026-03-28</pubDate>
      <description>A practical reading of the directive for organisations that already had a working ISMS, and where the genuinely new requirements bite.</description>
      <dc:creator>Anna Kowalska</dc:creator>
    </item>
    <item>
      <title>DORA's supplier register is the workstream most projects underestimate</title>
      <link>https://ellipseproject.com/blog/dora-supplier-register.html</link>
      <guid isPermaLink="true">https://ellipseproject.com/blog/dora-supplier-register.html</guid>
      <pubDate>2026-02-14</pubDate>
      <description>Of all the obligations DORA imposes, the ICT supplier register and contractual review consistently consumes the most effort. Why, and what to do about it.</description>
      <dc:creator>Tomasz Lewandowski</dc:creator>
    </item>
    <item>
      <title>ISO 27001:2022 transition — what to know one year before the deadline</title>
      <link>https://ellipseproject.com/blog/iso-27001-2022-transition.html</link>
      <guid isPermaLink="true">https://ellipseproject.com/blog/iso-27001-2022-transition.html</guid>
      <pubDate>2026-01-08</pubDate>
      <description>The transition deadline from ISO 27001:2013 to ISO 27001:2022 lands on 31 October 2025. Where remediation work tends to land in practice.</description>
      <dc:creator>Anna Kowalska</dc:creator>
    </item>
    <item>
      <title>Awareness training that survives the second year</title>
      <link>https://ellipseproject.com/blog/awareness-training-second-year.html</link>
      <guid isPermaLink="true">https://ellipseproject.com/blog/awareness-training-second-year.html</guid>
      <pubDate>2025-12-02</pubDate>
      <description>Why most awareness programmes peak in year one and decline thereafter, and what to do about it.</description>
      <dc:creator>Dr Magdalena Wójcik</dc:creator>
    </item>
    <item>
      <title>The 24-hour incident-notification clock — what "becoming aware" actually means</title>
      <link>https://ellipseproject.com/blog/incident-notification-clock.html</link>
      <guid isPermaLink="true">https://ellipseproject.com/blog/incident-notification-clock.html</guid>
      <pubDate>2025-10-15</pubDate>
      <description>NIS2 starts the early-warning clock at the moment of awareness. The definition has substantial interpretation latitude and high-stakes consequences.</description>
      <dc:creator>Pavel Novák</dc:creator>
    </item>
</channel>
</rss>
