惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LangChain Blog
Blog — PlanetScale
Blog — PlanetScale
A
About on SuperTechFans
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
M
MIT News - Artificial intelligence
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
Application and Cybersecurity Blog
Application and Cybersecurity Blog
NISL@THU
NISL@THU
aimingoo的专栏
aimingoo的专栏
T
Tor Project blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
T
Troy Hunt's Blog
U
Unit 42
Forbes - Security
Forbes - Security
J
Java Code Geeks
P
Privacy International News Feed
W
WeLiveSecurity
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
H
Heimdal Security Blog
量子位
Martin Fowler
Martin Fowler
G
Google Developers Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Docker
罗磊的独立博客
Security Archives - TechRepublic
Security Archives - TechRepublic
Engineering at Meta
Engineering at Meta
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
Simon Willison's Weblog
Simon Willison's Weblog
N
News and Events Feed by Topic
D
DataBreaches.Net
V2EX - 技术
V2EX - 技术
AWS News Blog
AWS News Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Attack and Defense Labs
Attack and Defense Labs
S
SegmentFault 最新的问题
MongoDB | Blog
MongoDB | Blog
S
Secure Thoughts
Apple Machine Learning Research
Apple Machine Learning Research

Portfolio – Silicon Republic

Report: 60pc of large companies report mental health issues among IT workers China blocks Meta’s $2bn Manus acquisition Ireland’s solar sector hits 1GW of energy for first time After Amazon, Google commits up to $40bn in Anthropic Cohere buys Aleph Alpha to forge sovereign AI alternative to US Big Tech 4 easy ways to stay on top of cybersecurity in the workplace 15 companies you’ll see at NIBRT Careers in Biopharma 2026 Bloomberg: Bezos’ Project Prometheus bags $10bn at $38bn value Meta to lay off 10pc of its workforce amid an AI push China's DeepSeek unveils long-awaited V4 AI model Intel’s shares soar as Q1 results signal brighter future MongoDB to create 200 new jobs as it invests €74m into Irish operations Why it's full STEAM ahead for young people upskilling in Ireland's west Swedish legal-tech Legora buys AI legal research start-up Qura Belfast’s Cloudsmith eyes ‘massive growth’ with $72m raise France's Univity raises €27m to allow European telecoms to compete with Starlink AI race intensifies with Google's new agent management platform Government launches new AI initiative for greater access to essential skills Free and inexpensive cybersecurity courses to undertake in 2026 UL looking for ‘changemakers’ amid Research Week 2026 OpenAI taps Airbnb exec as first EMEA managing director EAM platform Blue Mountain acquires Cork’s CompuCal Calibration Solutions SpaceX agrees right to buy AI coding darling Cursor for $60bn Anthropic probing reported Mythos leak on Discord Professional job openings across Ireland increased in Q1, finds report Contract hiring evidence of a cautious jobs market, finds report Can you rely on AI chatbots for medical advice? €6.9m awarded to final four National Challenge Fund winners Amazon investing up to $25bn in Anthropic AI infrastructure deal Vodafone Ireland to invest €360m over the next four years Tim Cook passes Apple leadership to hardware head John Ternus Stripe alum's Seapoint raises €7.5m as ‘financial home’ to start-ups When it comes to leadership, do companies know what they are doing? Amazon gets go-ahead for subsea cable landing station in Cork Communication and storytelling key skills, finds strategy manager Space-tech Mbryonics plans new production facility in Shannon Irish co-founded AI start-up Lua raises $5.8m AIM Centre strengthening medtech and life sciences link with new Galway base Kerry Group expands Cork facility as lactose-free demand grows Are electric vehicles about to take off for good? Nearly 75pc of AI’s economic value captured by just 20pc of companies Major gap between leaders' traits and employee expectations, finds report Dublin tech company Vox Talk raises €1.35m in pre-seed round Netflix shares fall on Q2 forecast as co-founder Hastings steps aside OpenAI to rival Google’s AlphaFold with new AI model for life sciences research Irish-founded Ulysses raises $46m in rounds featuring A16Z How are balance, inclusion and skills critical to the workforce of the future? Anthropic’s Mythos to bolster cybersecurity at UK banks Solidroad raises $25m as demand for QA product sparks fresh hiring Are we ready to place lab experiments in non-human hands? Danish finance AI start-up Spektr raises $20m What interview mistakes are jobseekers still making in 2026? Irish space AI start-up Ubotica on board for NASA’s FAME Dublin's Audrey AI closes $1.8m pre-seed funding round The Leaders' Room: Equinix's Peter Lantry on powering Ireland sustainably ‘No more excuses’ as EU launches free age verification app Waterford's HCS unveils €13.2m investment, plans 125 new jobs The death of ETL: Is zero-copy a ‘liberation’ for data teams? Snap cuts 16pc workforce to prioritise AI and savings Do data and AI talent needs conflict with a workforce seeking stability? Amazon buys Globalstar to bolster Leo's satellite capabilities Dublin start-up Otel AI raises €2m to expand hotel AI platform Boston Scientific announces €75m R&D investment in Galway After Anthropic, OpenAI launches cyber-specific AI model ASML forecasts €36bn in 2026 net sales amid AI race chip demand The Interview: Dentons' Carlo Salizzo on three forces defining digital law How this master’s programme is building tech leadership talent Nvidia unveils open-source quantum AI model Ising Bull and Equal1 to advance next gen of hybrid quantum tech in Europe Anthropic's Mythos a game-changer, NCSC chief tells Oireachtas Klaviyo building out its engineering team at Dublin facility Stanford: China ‘effectively’ closes AI model performance gap to US Mythos just first of power models to come: Anthropic co-founder Ireland to invest €17m in leading facilities for AI, medtech and more UK neobank Monzo makes Irish launch after US market exit How can you make your memory work more effectively? Cork Airport to get Ireland's largest solar carport next year New XP95 hacker group targets Dublin recruitment platform Healthdaq OpenAI apps for MacOS exposed by threat Mythos testing begins as governments raise cyber concerns The biopharma senior associate whose career was fuelled by FUEL Opinion: The future of insurance is AI, so why the hesitation? Meta to pay CoreWeave $21bn for additional cloud capacity Investing in part of the workforce creates an AI skills gap, finds report Digital rights group EFF leaves X Alibaba leads $293m round in Chinese AI start-up after HappyHorse reveal Anthropic reportedly mulls designing own chips amid shortage How are software engineering graduates adjusting to AI? OpenAI pauses Stargate UK over energy costs The diverse responsibilities of a principal software engineer Dublin AI SaaS provider Apex B2B launches with €1.5m backing Equal1 partners with Q-Ctrl for quantum data centre deployment Meta’s Superintelligence Labs debuts first product Muse Spark US court won't pause Anthropic ban, but wants case expedited Agentic commerce and purchase disputes: Did you mean to buy that? New Artemis II images give fresh look at our lunar neighbour Circuléire makes fresh call for 2026 accelerator applicants ‘Positive workplace culture starts with respect, trust and communication' Anthropic's Glasswing project employs Mythos to prevent AI cyberattacks Medtech start-up Vertigenius raises €2.55m for US expansion
Opinion: Why ISO 27001 alone won't save your data from itself
silicon · 2026-05-01 · via Portfolio – Silicon Republic

Nahla Davies looks at the blind spot between information security controls and genuine data integrity governance.

There’s a strange kind of confidence that comes with getting ISO 27001 certified. The audit’s done, the certificate’s on the wall, and suddenly everyone in the building sleeps a little better at night. It feels like you’ve handled the security question once and for all.

But here’s what nobody talks about at the celebration dinner: most of the data risks that actually burn companies in 2026 have very little to do with whether you passed an audit. They’re messier than that.

They live in the mundane, everyday chaos of how teams create, move, copy and forget about data. And that’s exactly where ISO 27001, for all its value, starts running out of answers.

The certification covers the framework, not the mess

ISO 27001 is genuinely useful. Let’s get that out of the way. It gives organisations a structured approach to information security management, and it forces leadership to actually think about risk in a systematic way. For companies that had nothing before, it’s a massive step forward.

But the standard was designed to assess whether you have the right policies, controls and processes in place. It’s checking that the architecture exists. What it can’t do is follow your data around on a Tuesday afternoon when someone in marketing copies a client list into a personal Google Sheet to ‘just quickly check something’.

That’s where the gap lives. The certification tells auditors you’ve built the walls. It doesn’t tell anyone what’s happening inside the rooms. And in most organisations, what’s happening inside the rooms is borderline chaotic.

Think about how data actually moves through people in a modern company. It starts in one system, gets exported into a spreadsheet, emailed to a colleague, uploaded to a shared drive, duplicated across three departments, and eventually forgotten in a folder nobody’s opened since last quarter. None of that necessarily violates your ISO 27001 controls. All of it creates risk.

The standard asks whether you have an asset inventory and data classification policy. Most certified companies do. But the reality of enforcing classification at scale, across thousands of files and dozens of tools, is a completely different problem. It’s like having a fire evacuation plan pinned to the wall while half the exits are blocked with furniture. Technically compliant, but practically dangerous.

Data governance is the part everyone skips

There’s a reason data governance keeps coming up in security conversations, even though it sounds painfully boring. It’s because governance is the layer that sits between policy and reality. It’s the part that answers questions like: who actually owns this dataset? When was it last reviewed? Does anyone know it’s still being stored in three places?

ISO 27001 touches on some of this. Annex A has controls around information classification, access management and asset ownership. But the standard treats these as boxes to check during an audit cycle. In practice, data governance requires constant, active attention. It’s operational, not periodic.

Most companies that get certified build their documentation, assign their roles, and move on. Six months later, the data landscape has shifted entirely. New tools get adopted, teams reorganise, people leave and their access lingers. The certificate stays valid. The risks multiply.

And this is particularly true with unstructured data, which makes up the vast majority of what most organisations hold. Emails, documents, chat logs, shared files. ISO 27001 doesn’t have a great answer for the sheer volume and unpredictability of unstructured data. It assumes you can classify and control it. Anyone who’s tried knows that’s optimistic at best.

What’s really needed alongside certification is a living, breathing data governance practice. One that maps where sensitive data actually resides (not just where it’s supposed to), monitors how it moves, and flags when something drifts outside acceptable boundaries. That’s not an audit exercise. It’s an ongoing operational function.

Compliance creates a floor, not a ceiling

There’s a broader point here that applies beyond ISO 27001. Compliance frameworks, by their nature, set a minimum bar. They define what ‘acceptable’ looks like at a given point in time, even with edge cases like using AI for software testing. But threats evolve, technology changes, and the way people work shifts constantly. A standard that’s reviewed every few years simply can’t keep pace with how quickly the data landscape moves.

This is especially relevant as AI tools become embedded in everyday workflows. Employees are feeding company data into large language models, using AI assistants to summarise internal documents, and generating content based on proprietary information. ISO 27001 wasn’t written with that reality in mind. The 2022 update made strides, sure, but the speed of AI adoption has outpaced what any standard can reasonably address.

Companies that treat certification as the finish line tend to develop blind spots in exactly these areas. They’re compliant on paper but exposed in practice. The data risks they face aren’t coming from sophisticated external attacks (though those matter too). They’re coming from inside the house, from the everyday, unglamorous ways people interact with information.

The smartest organisations use ISO 27001 as a foundation and then build upward. They invest in data discovery tools that map shadow data. They implement real-time monitoring for sensitive information. They train employees not just on policy, but on the practical habits that keep data from wandering into places it shouldn’t be. Certification becomes the starting point of the security conversation, not the conclusion.

Final thoughts

ISO 27001 deserves its reputation as a serious, credible framework. Getting certified takes real effort, and it signals that an organisation takes information security seriously.

But there’s a growing disconnect between what the certificate proves and what modern data environments actually demand. The biggest risks today come from data sprawl, from duplication and drift and the quiet entropy of information that nobody’s actively managing.

Addressing that takes more than a framework. It takes a culture of continuous governance, practical tooling, and an honest look at the gap between how data should behave and how it actually does. The certificate opens the door. What you build behind it is what actually matters.

By Nahla Davies

Nahla Davies is a software developer and tech writer. Before devoting her work full time to technical writing, she managed – among other intriguing things – to serve as a lead programmer at an Inc 5,000 experiential branding organisation, where clients include Samsung, Time Warner, Netflix and Sony.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.