Blog
What Is GRC? Governance, Risk and Compliance Explained
Gaute Wangen

What is GRC, and how does it work in practice? Explore how governance, risk and compliance help organizations make informed decisions, manage uncertainty and meet their obligations—with clear definitions, practical examples and answers to common questions.
Read more
What else is affected? Understanding your IT systems and supplier dependencies
Gaute Wangen

Dependency analysis maps the connections between your IT systems, suppliers and critical services to show the real-world impact of a system failure. This helps you uncover hidden dependencies, identify single points of failure and find clear ways to strengthen your operational resilience.
Read more
The Digital Security Act: 7 requirements your business should implement
Gaute Wangen

The Digital Security Act and the Digital Security Regulations set new standards for how businesses manage cyber security. Here are seven key areas to address – from risk assessment and basic security measures to supply chain monitoring, incident response, and reporting.
Read more
Security in small businesses
Gaute Wangen

Where should a small business start with IT security and data privacy? Practical answers to the ten most common questions, complete with a three-level checklist.
Read more
Risk assessment using the bowtie method
Gaute Wangen

The Bowtie model is a diagram that visualises the connection between the cause and consequence of unwanted events. Crucially, it shows how many different causes and consequences a single event can have. Above, we see an example of a bowtie diagram. The traditional Bowtie analysis consists of an adverse event (in the middle) combined with the possible causes and consequences of that event. The safeguards in the Bowtie analysis are put in place to reduce either the cause (probability) or the outcome (consequence).
Read more
Cyber security terms
Gaute Wangen

Information security, IT security, cyber security, or digital security? These terms are often used interchangeably and mean the same thing to most people. If you find it hard to tell these digital security concepts apart, you are not alone!
Read more
Achieved Compliance
Grethe Østby

“Previously, we managed compliance across spreadsheets, which made it difficult to maintain a shared overview. Now our risks, processing activities and open tasks are all in one system, so everyone on the team can see where we stand and what needs to happen next.” - Lars Andreas Kolflaath, CEO, Future Ready AS
Read more
Training and Awareness
Grethe Østby

Cyrigo has partnered with Moxso to offer their security awareness training directly through our platform. Based in Copenhagen, Moxso designs awareness training as it should be — an engaging, ongoing experience rather than a tedious annual box-ticking exercise. Delivered as bite-sized micro-learning, it takes just ten minutes a month per employee. This interactive training combines short videos and practical exercises with realistic phishing simulations, making it highly effective and easy to digest.
Read more
