惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
F
Full Disclosure
Recorded Future
Recorded Future
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
博客园_首页
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hacker News: Front Page
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 司徒正美
Webroot Blog
Webroot Blog
Google DeepMind News
Google DeepMind News
Help Net Security
Help Net Security
Cloudbric
Cloudbric
PCI Perspectives
PCI Perspectives
有赞技术团队
有赞技术团队
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
TaoSecurity Blog
TaoSecurity Blog
L
Lohrmann on Cybersecurity
量子位
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tailwind CSS Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
N
News and Events Feed by Topic
罗磊的独立博客
T
Threat Research - Cisco Blogs
Schneier on Security
Schneier on Security
T
Tor Project blog
IT之家
IT之家
M
MIT News - Artificial intelligence
S
Security @ Cisco Blogs
O
OpenAI News
AI
AI
S
Securelist
Simon Willison's Weblog
Simon Willison's Weblog
The Last Watchdog
The Last Watchdog
月光博客
月光博客
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 热门话题

Technology – Silicon Republic

Quantexa opens new Dublin office and R&D centre EU agrees to simpler AI rules and complete ‘nudification’ ban Tissue repair therapy Substrato wins best pitch at EI Start-Up Day Major European markets still lagging on salary transparency, finds report Anthropic joins forces with SpaceX for Colossus capacity Enterprise Ireland pumped €33m into home-grown start-ups in 2025 Coimisiún na Meán opens investigation into Meta’s content promotion German quantum computing start-up Eleqtron raises €57m Dublin’s GridBeyond to support energy efficiency with new global headquarters What’s the difference between IT and OT security? Coinbase cuts 14pc of jobs to save costs and embrace AI National research partnership to examine flexible work and Ireland’s economy Anthropic, Blackstone, Goldman Sachs to create AI services company Meta bags Assured Robot Intelligence to further humanoid plans Spotify unveils verified badge to distinguish humans from AI Cork’s Nexalus teams with TuffTek for next-gen cooling systems Dublin’s Version 1 to acquire CreateFuture consultancy Apple posts ‘best March quarter’ with iPhone sales up 21.6pc Cork HQ for new onshore renewables company Perigus Energy What EU Inc really means for Europe’s start-ups – a legal view Meta, Microsoft, Amazon and Alphabet post positive quarterlies Oracle reportedly cutting up to 150 Irish jobs The Leaders’ Room: Boston Scientific’s Sean Gayer on a meaningful mission Report: Medical device cyberattacks on the rise EU finds Meta not doing enough to keep underage users at bay TSMC $231m share sale marks full exit from UK chip designer Arm Datavant opens new global R&D centre in Galway’s Bonham Quay Revolut plans a physical store in Barcelona UK's IoT Tribe launches Dublin base with two new hires Report: Meta to undo Manus acquisition after Chinese block David Silver's Ineffable Intelligence raises $1.1bn 700 fear job cuts at Meta contractor Covalen Vinted hits €8bn valuation in oversubscribed €880m share sale China blocks Meta’s $2bn Manus acquisition After Amazon, Google commits up to $40bn in Anthropic Cohere buys Aleph Alpha to forge sovereign AI alternative to US Big Tech Bloomberg: Bezos’ Project Prometheus bags $10bn at $38bn value Meta to lay off 10pc of its workforce amid an AI push Intel’s shares soar as Q1 results signal brighter future Swedish legal-tech Legora buys AI legal research start-up Qura Belfast’s Cloudsmith eyes ‘massive growth’ with $72m raise France's Univity raises €27m to allow European telecoms to compete with Starlink AI race intensifies with Google's new agent management platform OpenAI taps Airbnb exec as first EMEA managing director EAM platform Blue Mountain acquires Cork’s CompuCal Calibration Solutions SpaceX agrees right to buy AI coding darling Cursor for $60bn Anthropic probing reported Mythos leak on Discord Amazon investing up to $25bn in Anthropic AI infrastructure deal Vodafone Ireland to invest €360m over the next four years Tim Cook passes Apple leadership to hardware head John Ternus Stripe alum's Seapoint raises €7.5m as ‘financial home’ to start-ups Amazon gets go-ahead for subsea cable landing station in Cork Irish co-founded AI start-up Lua raises $5.8m AIM Centre strengthening medtech and life sciences link with new Galway base Kerry Group expands Cork facility as lactose-free demand grows Nearly 75pc of AI’s economic value captured by just 20pc of companies Dublin tech company Vox Talk raises €1.35m in pre-seed round Netflix shares fall on Q2 forecast as co-founder Hastings steps aside Irish-founded Ulysses raises $46m in rounds featuring A16Z Anthropic’s Mythos to bolster cybersecurity at UK banks Solidroad raises $25m as demand for QA product sparks fresh hiring Danish finance AI start-up Spektr raises $20m Dublin's Audrey AI closes $1.8m pre-seed funding round The Leaders' Room: Equinix's Peter Lantry on powering Ireland sustainably ‘No more excuses’ as EU launches free age verification app The death of ETL: Is zero-copy a ‘liberation’ for data teams? Snap cuts 16pc workforce to prioritise AI and savings Amazon buys Globalstar to bolster Leo's satellite capabilities Dublin start-up Otel AI raises €2m to expand hotel AI platform After Anthropic, OpenAI launches cyber-specific AI model ASML forecasts €36bn in 2026 net sales amid AI race chip demand The Interview: Dentons' Carlo Salizzo on three forces defining digital law Bull and Equal1 to advance next gen of hybrid quantum tech in Europe Anthropic's Mythos a game-changer, NCSC chief tells Oireachtas Klaviyo building out its engineering team at Dublin facility Mythos just first of power models to come: Anthropic co-founder UK neobank Monzo makes Irish launch after US market exit New XP95 hacker group targets Dublin recruitment platform Healthdaq OpenAI apps for MacOS exposed by threat Mythos testing begins as governments raise cyber concerns Meta to pay CoreWeave $21bn for additional cloud capacity Digital rights group EFF leaves X Alibaba leads $293m round in Chinese AI start-up after HappyHorse reveal OpenAI pauses Stargate UK over energy costs Dublin AI SaaS provider Apex B2B launches with €1.5m backing US court won't pause Anthropic ban, but wants case expedited Anthropic's Glasswing project employs Mythos to prevent AI cyberattacks Medtech start-up Vertigenius raises €2.55m for US expansion Meath ITAD provider ICT acquired by US recycling firm Paladin Is your data integrity framework just a fancy spreadsheet? Dublin start-up Zellor bags €850k for AI shopping assistant Irish co-founded Prism Layer out from stealth with $1m raise Galway-based AI start-up Octostar raises €6.1m FT: Bezos's Project Prometheus taps xAI co-founder Kyle Kosic Irish Government approves ‘next-generation sites’ for industry Ireland begins digital wallet testing and consultation OpenAI purchases online tech talk show TBPN Capacity and speed: Why TikTok shelved its second Irish data centre SpaceX confidentially files for US IPO – reports Intel repurchasing 49pc stake in Leixlip chip factory for $14.2bn
Opinion: Why ISO 27001 alone won't save your data from itself
silicon · 2026-05-01 · via Technology – Silicon Republic

Nahla Davies looks at the blind spot between information security controls and genuine data integrity governance.

There’s a strange kind of confidence that comes with getting ISO 27001 certified. The audit’s done, the certificate’s on the wall, and suddenly everyone in the building sleeps a little better at night. It feels like you’ve handled the security question once and for all.

But here’s what nobody talks about at the celebration dinner: most of the data risks that actually burn companies in 2026 have very little to do with whether you passed an audit. They’re messier than that.

They live in the mundane, everyday chaos of how teams create, move, copy and forget about data. And that’s exactly where ISO 27001, for all its value, starts running out of answers.

The certification covers the framework, not the mess

ISO 27001 is genuinely useful. Let’s get that out of the way. It gives organisations a structured approach to information security management, and it forces leadership to actually think about risk in a systematic way. For companies that had nothing before, it’s a massive step forward.

But the standard was designed to assess whether you have the right policies, controls and processes in place. It’s checking that the architecture exists. What it can’t do is follow your data around on a Tuesday afternoon when someone in marketing copies a client list into a personal Google Sheet to ‘just quickly check something’.

That’s where the gap lives. The certification tells auditors you’ve built the walls. It doesn’t tell anyone what’s happening inside the rooms. And in most organisations, what’s happening inside the rooms is borderline chaotic.

Think about how data actually moves through people in a modern company. It starts in one system, gets exported into a spreadsheet, emailed to a colleague, uploaded to a shared drive, duplicated across three departments, and eventually forgotten in a folder nobody’s opened since last quarter. None of that necessarily violates your ISO 27001 controls. All of it creates risk.

The standard asks whether you have an asset inventory and data classification policy. Most certified companies do. But the reality of enforcing classification at scale, across thousands of files and dozens of tools, is a completely different problem. It’s like having a fire evacuation plan pinned to the wall while half the exits are blocked with furniture. Technically compliant, but practically dangerous.

Data governance is the part everyone skips

There’s a reason data governance keeps coming up in security conversations, even though it sounds painfully boring. It’s because governance is the layer that sits between policy and reality. It’s the part that answers questions like: who actually owns this dataset? When was it last reviewed? Does anyone know it’s still being stored in three places?

ISO 27001 touches on some of this. Annex A has controls around information classification, access management and asset ownership. But the standard treats these as boxes to check during an audit cycle. In practice, data governance requires constant, active attention. It’s operational, not periodic.

Most companies that get certified build their documentation, assign their roles, and move on. Six months later, the data landscape has shifted entirely. New tools get adopted, teams reorganise, people leave and their access lingers. The certificate stays valid. The risks multiply.

And this is particularly true with unstructured data, which makes up the vast majority of what most organisations hold. Emails, documents, chat logs, shared files. ISO 27001 doesn’t have a great answer for the sheer volume and unpredictability of unstructured data. It assumes you can classify and control it. Anyone who’s tried knows that’s optimistic at best.

What’s really needed alongside certification is a living, breathing data governance practice. One that maps where sensitive data actually resides (not just where it’s supposed to), monitors how it moves, and flags when something drifts outside acceptable boundaries. That’s not an audit exercise. It’s an ongoing operational function.

Compliance creates a floor, not a ceiling

There’s a broader point here that applies beyond ISO 27001. Compliance frameworks, by their nature, set a minimum bar. They define what ‘acceptable’ looks like at a given point in time, even with edge cases like using AI for software testing. But threats evolve, technology changes, and the way people work shifts constantly. A standard that’s reviewed every few years simply can’t keep pace with how quickly the data landscape moves.

This is especially relevant as AI tools become embedded in everyday workflows. Employees are feeding company data into large language models, using AI assistants to summarise internal documents, and generating content based on proprietary information. ISO 27001 wasn’t written with that reality in mind. The 2022 update made strides, sure, but the speed of AI adoption has outpaced what any standard can reasonably address.

Companies that treat certification as the finish line tend to develop blind spots in exactly these areas. They’re compliant on paper but exposed in practice. The data risks they face aren’t coming from sophisticated external attacks (though those matter too). They’re coming from inside the house, from the everyday, unglamorous ways people interact with information.

The smartest organisations use ISO 27001 as a foundation and then build upward. They invest in data discovery tools that map shadow data. They implement real-time monitoring for sensitive information. They train employees not just on policy, but on the practical habits that keep data from wandering into places it shouldn’t be. Certification becomes the starting point of the security conversation, not the conclusion.

Final thoughts

ISO 27001 deserves its reputation as a serious, credible framework. Getting certified takes real effort, and it signals that an organisation takes information security seriously.

But there’s a growing disconnect between what the certificate proves and what modern data environments actually demand. The biggest risks today come from data sprawl, from duplication and drift and the quiet entropy of information that nobody’s actively managing.

Addressing that takes more than a framework. It takes a culture of continuous governance, practical tooling, and an honest look at the gap between how data should behave and how it actually does. The certificate opens the door. What you build behind it is what actually matters.

By Nahla Davies

Nahla Davies is a software developer and tech writer. Before devoting her work full time to technical writing, she managed – among other intriguing things – to serve as a lead programmer at an Inc 5,000 experiential branding organisation, where clients include Samsung, Time Warner, Netflix and Sony.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.