Blog
What Is GRC? Governance, Risk and Compliance Explained
Gaute Wangen

What is GRC, and how does it work in practice? Explore how governance, risk and compliance help organizations make informed decisions, manage uncertainty and meet their obligations—with clear definitions, practical examples and answers to common questions.
See full text
What else stops? Understanding IT system and supplier dependencies
Gaute Wangen

Dependency analysis connects IT systems, suppliers and critical services to show what actually happens when something fails — revealing hidden dependencies, single points of failure and opportunities to improve operational resilience.
See full text
Digitalsikkerhetsloven: 7 krav virksomheten bør få på plass
Gaute Wangen

Digitalsikkerhetsloven og digitalsikkerhetsforskriften stiller nye krav til hvordan virksomheter arbeider med digital sikkerhet. Her er syv områder å få på plass – fra risikovurdering og grunnsikring til leverandøroppfølging, beredskap og varsling.
See full text
Sikkerhet i små virksomheter
Gaute Wangen

Hvor skal en liten bedrift begynne med IT-sikkerhet og personvern? Praktiske svar på de ti vanligste spørsmålene, med sjekkliste i tre nivåer.
See full text
RISK ASSESSMENT WITH BOWTIE
Gaute Wangen

The Bowtie model is a diagram that visualises the connection between the cause and consequence of unwanted events. And not least, it shows how many different causes and consequences an event can have. Above, we see an example of a bowtie diagram. The traditional Bowtie analysis consists of an adverse event (in the middle) combined with possible causes and consequences of said event. The safeguards in the Bowtie analysis are in place to reduce the cause (probability) or the outcome (consequence).
See full text
CYBER SECURITY TERMINOLOGIES
Gaute Wangen

Information security, ICT/IT security, cyber security, or digital security? These terms are often used interchangeably and are synonyms for most people in everyday language. Do you find it difficult to distinguish all the concepts within digital security from each other? You are not alone!
See full text
COMPLIANCE SUCCESS
Grethe Østby

“Before, we managed compliance across spreadsheets, which made it difficult to maintain a shared overview. Now our risks, processing activities and open tasks are all in one system, so everyone on the team can see where we stand and what needs to happen next.” - Lars Andreas Kolflaath, CEO, Future Ready AS
See full text
TRAINING AND AWARENESS
Grethe Østby

Cyrigo has established a partnership with Moxso, and their security awareness training is available directly through us. Moxso is a Copenhagen-based company that builds awareness training the way it should have been built all along — as something people actually do, rather than something they endure once a year. The format is micro-learning: Roughly ten minutes a month per employee, delivered through short videos and interactive exercises, with possibilities to combine with phishing simulations well suited for learning.
See full text
