azure NIS2
De Cyberbeveiligingswet geldt sinds 15 augustus 2026. Er is nog geen toezichtpraktijk, maar ketenrisicobeheer zorgt dat de eerste vraag over uw zorgplicht uit de inkoopafdeling van uw klant komt, niet van een toezichthouder. Wat u op Azure en Microsoft 365 moet kunnen aantonen voordat die vragenlijst binnenkomt.
azure DORA
Why an untested Azure backup is worth nothing under DORA Article 12, how to set RTO and RPO per workload, and why the quarterly test failover report is the artifact a supervisor actually asks for.
azure DORA
A DORA exit strategy for Azure is proven by your dependency graph, not by the document. Portability assessment, exit triggers, timeline, cost, and the risk-accepted conclusion.
azure NIS2
A category-by-category comparison of NIS2 compliance tooling for Azure in 2026: GRC automation, CSPM, Azure-native services, and architecture assessment. Written for Dutch buyers who have to evidence NIS2.
azure NIS2
Tussen 27 juli en 3 augustus 2026 publiceerde het NCSC vier adviezen over authenticatiebypass, telkens in software die andere systemen beheert. Op 15 augustus treedt de Cyberbeveiligingswet in werking. Voor Nederlandse beheerpartijen op Azure verandert daarmee de vraag die gesteld wordt.
azure networking
An Azure VNet is metadata and policy enforced at each NIC. No Layer 2, no router, no isolating subnet boundary. Your segmentation is the NSG, and your security is the layering on top of it. What Azure networking actually does, and how to design for it.
azure NIS2
NIS2 vs ISO 27001 on Azure: a control-by-control map of Article 21 to Annex A, plus the three gaps certification doesn't close. For compliance leads and CISOs.
azure DORA
How to register Microsoft as a critical ICT third party under DORA Article 28, run the criticality test, and review Azure contracts against Article 30. For ICT risk leads.
azure NIS2
NIS2 incident reporting on Azure means a 24-hour early warning, 72-hour notification, and one-month final report. Build the capability in Microsoft Sentinel. For SecOps leads.
azure DORA
DORA Article 11 requires a continuous ICT risk-management framework tied to your live Azure tenant: current asset register, per-workload recovery objectives, and Microsoft on your Article 28 register. What DNB actually asks to see.
azure SOC 2
SOC2 auditors ask for Azure architecture evidence. Not diagrams — evidence of controls implemented, assessed, and documented. This post explains what that evidence must contain and how a pre-audit assessment produces it.
azure Zero Trust
Zero trust on Azure is an architecture you have to document and maintain, not a product you switch on. The evidence a NIS2 supervisor wants is the design rationale - and it drifts. For Azure architects and compliance leads.
azure CNAPP
A CNAPP tells you which resources are exploitable right now. It does not tell you whether your architecture should have been built that way. This is where runtime detection ends and design-time assessment begins.
azure NIS2
De Rijksoverheid heeft bevestigd: de Cyberbeveiligingswet en de Wet weerbaarheid kritieke entiteiten treden op 15 augustus 2026 in werking. Vanaf die datum gelden NCSC-registratie, zorgplicht, meldplicht, aantoonbare bestuurderskennis en ketenrisicobeheer. Voor Nederlandse bestuurders en Cloud Architects op Azure.
azure NIS2
NIS2-meldplicht voor Azure: vroege waarschuwing binnen 24 uur, melding binnen 72 uur, eindrapport binnen een maand. Detecteren met Microsoft Sentinel. Voor Nederlandse CISO's.
azure Zero Trust
An Azure Zero Trust assessment scores six pillars with concrete Microsoft signals — Conditional Access, Intune, EIDSCA — mapped to NIS2. For security architects.
azure NIS2
A fair read on Microsoft Defender for Cloud NIS2 compliance: strong first-party standards, real gating and scope limits. For security leads. With a coverage table.
azure compliance
Turn Microsoft Entra ID conditional access and PIM into NIS2 and DORA access-control evidence — exact policies, audit logs, artifacts. For identity leads.
azure NIS2
NIS2 supply chain security on Azure means governing OAuth apps, service principals, and SaaS dependencies under Article 21(2)(d). What to configure and evidence. For CISOs.
azure compliance
A 35-item checklist covering architecture documentation, compliance mapping, and operational governance for Dutch organisations running Azure. Specific enough to audit against. Built for CTOs and Platform Leads who need to close gaps before 2026 ends.
azure architecture
Azure infrastructure drift is not a single event. It is continuous — and most organisations do not detect it until an audit or incident makes it visible. This post maps the categories of drift that create compliance and security risk, and what each category costs when it goes undetected.
azure NIS2
The Cyberbeveiligingswet takes effect on 15 August 2026. Its hardest obligation is a board-level duty of care — personal, continuous, non-delegable — that vulnerability scanners cannot evidence. For directors and Cloud Architects at Dutch regulated organisations.
azure NIS2
NIS2 Article 21 requires demonstrable Azure configuration evidence across ten security measure domains. This post maps each domain to specific Azure services and configuration settings. For Platform Engineers and Cloud Architects at Dutch regulated organisations.
azure security
The WAF security pillar assessment surfaces the same findings in nearly every Azure environment. This walkthrough names them specifically — so Platform Engineers know what to expect, and what to address before the assessment runs.
azure NIS2
NIS2 Artikel 21 stelt concrete eisen aan uw Azure-configuratie. Deze gids vertaalt de tien technische maatregelen naar specifieke Azure-services en instellingen — voor IT-risicomanagers en compliance-professionals bij Nederlandse organisaties.
architecture strategy
Most organizations treat architecture reviews as a compliance checkbox. That's a mistake. Here's what they should be instead.
architecture engineering
Technical debt isn't just about code quality. It's about the decisions you can't make because of the decisions you made before.
azure architecture
Microsoft's WAF provides a structured approach to evaluating cloud architectures. Here's how to use it effectively without getting lost in the documentation.