Insights
Written by the people who do the work
Guides, templates and tech notes with enough specific detail to be useful on their own. If a piece here could have been written by someone who has never run the engagement, it does not go up.
In short
Cloudgap publishes practitioner guides, assessment templates and technical notes covering AI governance, security certification, penetration testing and supply chain assurance, alongside a maintained regulatory horizon tracking UK and EU obligations with their sources and verification dates.
Guides and notes
6 pieces worth your time
- Template3 min
ISO 42001 Gap Analysis Checklist
A clause-by-clause self-assessment against the AI management system standard, with the questions an auditor will actually ask at Stage 2.
- Insight3 min
Harvest Now, Decrypt Later: Where to Start
Why data with a long confidentiality requirement is already exposed to the quantum threat, and why the first task is an inventory rather than a migration.
- Guide4 min
The SME Guide to AI Governance
A practical route to governing AI adoption without a compliance team: find the shadow AI, tier by risk, and write a policy people will actually follow.
- Guide2 min
The Agile Security Manifesto
Four positions on how security should be delivered: embedded guardrails over gatekeeper sign-offs, continuous assurance over annual audits, and why it matters.
- Executive brief3 min
The vCISO Business Case
How to argue fractional security leadership to a board or a CFO: the four dimensions that actually decide it, and where hiring is the better answer.
- Tech note3 min
Five Logic Flaws Automated Scanners Miss
IDOR, business logic bypass, race conditions, broken access control and chained low findings - why each one is invisible to a scanner and how to test for it.
Case studies
Engagements, written up honestly
- Insight3 min
Supplier Assurance After a Breach
A supplier was breached and the board asked which other suppliers could do the same. The questionnaire programme could not answer, and the reason is structural.
- Insight3 min
Scoping the EU AI Act for a SaaS Platform
A UK software company with EU customers had to establish which parts of the AI Act reached it, and by when, before it could answer a procurement questionnaire.
- Insight2 min
Securing a Fintech Scale-Up
A London payments company needed certification inside six months to close a banking partnership, with no internal security team. What the engagement covered.
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours