New: Mondoo expands vulnerability management to shadow AI. Find and fix it · See it live at Black Hat USA, Booth 5100, AI Zone, August 1 to 6.
Log inGet Assessment
All Posts

Compliance

Regulatory frameworks, audits, and policy management

16 articles

You Can't Train People on AI You Can't See
8 min read

You Can't Train People on AI You Can't See

Enforcement of the EU AI Act's AI literacy duty starts today. The text of that duty changed eight days ago, and almost nobody has noticed. Why the softening of Article 4 makes it more interesting for security teams, not less, and why the honest response starts with an inventory of the AI you can't see.

Patrick Münch
Patrick Münch · Aug 3, 2026
A Practical Guide for Lean Security Teams Complying with DORA
6 min read

A Practical Guide for Lean Security Teams Complying with DORA

DORA does not scale with your organization's size - the core requirements apply equally to a one-person security function and a team of fifty. What changes for lean teams is how those requirements are met. This guide looks at why manual processes are the first to fail under DORA, why documentation is evidence rather than the goal, and how starting small with your existing scan results as a baseline lets small teams stay permanently audit-ready.

Dan Raywood
Dan Raywood · Jul 7, 2026
Ein praktischer Leitfaden für schlanke Security-Teams zur DORA-Compliance
6 Min. Lesezeit

Ein praktischer Leitfaden für schlanke Security-Teams zur DORA-Compliance

DORA skaliert nicht mit der Größe Ihrer Organisation – die Kernanforderungen gelten für eine Ein-Personen-Security-Funktion genauso wie für ein 50-köpfiges Team. Was sich für schlanke Teams ändert, ist die Art und Weise, wie diese Anforderungen erfüllt werden. Dieser Leitfaden zeigt, warum manuelle Prozesse unter DORA als Erstes scheitern, warum Dokumentation ein Nachweis und nicht das Ziel ist und wie kleine Teams dauerhaft audit-bereit bleiben, indem sie klein anfangen und ihre vorhandenen Scan-Ergebnisse als Baseline nutzen.

Dan Raywood
Dan Raywood · Jul 7, 2026
How DORA Has Impacted Vulnerability Management
7 min read

How DORA Has Impacted Vulnerability Management

DORA has not changed what financial institutions need to do about vulnerabilities; it has changed how consistently they must do it, how broadly they must apply it, and how clearly they must prove it. This post unpacks what Articles 9, 10, and 29 mean operationally: continuous monitoring replaces point-in-time scans, shift-left testing becomes a regulatory expectation, and supply chain risk - now including AI systems under BaFin's January 2026 guidance - sits firmly inside the compliance perimeter.

Dan Raywood
Dan Raywood · Jun 26, 2026
Wie DORA das Schwachstellenmanagement verändert hat
7 Min. Lesezeit

Wie DORA das Schwachstellenmanagement verändert hat

DORA hat nicht verändert, was Finanzunternehmen im Umgang mit Schwachstellen tun müssen. Verändert hat sich vielmehr, wie konsequent sie es tun, wie umfassend sie es anwenden und wie überzeugend sie es belegen müssen. Dieser Beitrag zeigt, was die Artikel 9, 10 und 29 in der Praxis bedeuten: Kontinuierliche Überwachung tritt an die Stelle punktueller Scans, Shift-Left-Testing wird zur regulatorischen Erwartung, und das Lieferkettenrisiko – seit der BaFin-Guidance vom Januar 2026 einschließlich KI-Systemen – rückt fest in den Compliance-Perimeter.

Dan Raywood
Dan Raywood · Jun 26, 2026
DORA nach einem Jahr – Was haben wir bisher gelernt?
5 Min. Lesezeit

DORA nach einem Jahr – Was haben wir bisher gelernt?

Sechzehn Monate nach Geltungsbeginn der DORA lautet die zentrale Lektion nicht Compliance, sondern Exposure-Management. Ein Blick auf Artikel 9, die wachsende Nachweislücke und die Frage, was der rasante Aufstieg der KI für die operationale Resilienz bedeutet.

Dan Raywood
Dan Raywood · Jun 10, 2026
DORA, 1 Year In - What Have We Learned So Far?
5 min read

DORA, 1 Year In - What Have We Learned So Far?

Sixteen months after DORA became applicable, the central lesson isn't about compliance — it's about exposure management. A look at Article 9, the widening evidence gap, and what the rapid rise of AI means for operational resilience.

Dan Raywood
Dan Raywood · Jun 10, 2026
Setting MTTR Goals: How SLAs Improve Vulnerability Management
5 min read

Setting MTTR Goals: How SLAs Improve Vulnerability Management

SLAs for vulnerability management often get a bad rap. They can sometimes be unrealistic or unenforceable. They can also create a lot of manual work if your vulnerability management tool cannot track them for you. However, SLAs are important since they help measure performance, enforce accountability, and ultimately, ensure that critical and high-priority vulnerabilities are addressed as fast as possible. Many compliance frameworks, such as PCI DSS, are now also requiring them.

Tim SmithDeborah Galea
Tim Smith, Deborah Galea · Jan 7, 2026
Why You Need Unified Policy as Code for Terraform Workflows
5 min read

Why You Need Unified Policy as Code for Terraform Workflows

Terraform, HashiCorp's Infrastructure as Code (IaC) tool, has become the de facto standard for provisioning and managing cloud infrastructure. From startups to Fortune 10 enterprises, it powers the provisioning of cloud resources at scale. But with this power comes risk: a single misconfiguration in Terraform can expose sensitive data, inflate cloud costs, or create compliance gaps and replicate this across hundreds of assets. That's why Policy as Code is essential when using Terraform. By expressing rules as code, organizations can set guardrails directly into their IaC workflows. This ensures that security, compliance, and operational best practices are enforced automatically, without relying on manual reviews or tribal knowledge. However, many existing Policy as Code tools for Terraform come with significant limitations.

Scott Ford
Scott Ford · Aug 28, 2025
Styra OPA Alternative for Infrastructure Security and Compliance Policies
6 min read

Styra OPA Alternative for Infrastructure Security and Compliance Policies

In case you haven't heard yet, the creators of Open Policy Agent (along with many team members from Styra) are leaving to join Apple. Styra's Enterprise OPA customers have received news that their subscriptions will be ending. The news sent a shockwave through the OPA and Rego communities. It's uncertain what this means for the future of OPA; will the code still be maintained, will it remain available as open source in the long run, will the license be changed? In this blog we'll share our perspective and take a look at alternatives for Policy as Code use cases.

Dominik Richter
Dominik Richter · Aug 21, 2025
Microsoft 365 CIS Benchmark 5.0: What You Need to Know
8 min read

Microsoft 365 CIS Benchmark 5.0: What You Need to Know

On April 30th, 2025, the Center for Internet Security (CIS) released version 5.0 of its popular Microsoft 365 Foundations Benchmark, introducing a host of new best practices and refinements to help organizations secure their cloud-based collaboration and productivity environments. For security researchers and practitioners, understanding these updates is crucial for maintaining a robust security posture against evolving threats. This article delves into the key aspects of the CIS Microsoft 365 Foundations benchmark, what's new in 5.0, and what you need to do to remain compliant.

Dimitar Ganev
Dimitar Ganev · Jun 23, 2025
Why Vulnerability Automation Is the Smart Way to Tackle NIS2
3 min read

Why Vulnerability Automation Is the Smart Way to Tackle NIS2

The NIS2 Directive brings stricter cybersecurity requirements for organizations across the EU. However, because EU companies must ensure that their suppliers are NIS2 compliant as well, any company doing business in the EU is ultimately also required to comply with NIS2. This means that many organizations globally need to implement enhanced risk management, more rigorous incident reporting, and a greater focus on overall cybersecurity resilience.

Deborah Galea
Deborah Galea · Mar 6, 2025
Security and Compliance: Addressing Poor Tooling
2 min read

Security and Compliance: Addressing Poor Tooling

Security and compliance play integral roles in maintaining a healthy IT environment. While security safeguards an organization from breaches and threats, compliance ensures adherence to specific regulatory requirements. However, many organizations face a significant disconnect between these two functions, largely due to what we term as 'poor security tooling'. In this blog post, we will unpack the impact of this issue and illustrate how Mondoo can help bridge this gap.

Timon Lanzendörfer
Timon Lanzendörfer · Aug 21, 2023
Simplifying Compliance: Introducing the Mondoo Compliance Hub
3 min read

Simplifying Compliance: Introducing the Mondoo Compliance Hub

Compliance isn't just about passing audits; it forms the core of your relationships with customers, stakeholders, and collaborators. As a CISO, GRC professional, or a Security Engineer, you're all too familiar with the challenges: complex regulations, resource constraints, and a perpetually changing threat landscape.

Dominik Richter
Dominik Richter · Aug 9, 2023
Streamlining Compliance: Best Practices for GRC Pros
2 min read

Streamlining Compliance: Best Practices for GRC Pros

In today's global economy, governance, risk, and compliance (GRC) is more critical than ever. Regulations change constantly, and keeping up can feel like an insurmountable task. Businesses that fail to meet these regulatory requirements face penalties, damaged reputations, and potential operational disruptions. But it's not just about avoiding negative consequences.

Patrick Münch
Patrick Münch · Jul 13, 2023
A DevOps Approach to AWS Security: Policy as Code
10 min read

A DevOps Approach to AWS Security: Policy as Code

As DevOps practitioners ourselves, we know securing your AWS environments is complicated. Have you thought about approaching security the same way DevOps teams build and manage their AWS infrastructure? If not, then you should.

Scott Ford
Scott Ford · Mar 21, 2022

Ready to Transform Your Security?

See how Mondoo can help you find and fix vulnerabilities faster.