Insights

Plain-English notes on where the risk actually is

Short, practical pieces on the E8 → Essentials transition, AI governance, and Microsoft security. No filler, no fear-mongering.

E8 / Essentials Sentragon Insights Team

The Essential Eight is becoming Essentials — here's what actually changes

A plain-English explainer for non-technical readers: what the Essentials framework is, why it's replacing the Essential Eight, what stays the same, and what organisations should check first.

  • What the Essentials framework is, and why it's replacing the Essential Eight
  • What stays the same vs what genuinely changes
  • What organisations should check first
Soft CTA: link to the E8 → Essentials Transition Assessment.
Microsoft Security Sentragon Insights Team

What Copilot can see: the oversharing risk no one configured for

How Copilot surfaces existing SharePoint/OneDrive permissions issues that were previously low-risk because no one was searching across them.

  • How Copilot surfaces existing SharePoint/OneDrive permissions issues
  • Why this changes the calculus on file permissions
  • What a sensible first check looks like
Soft CTA: link to the M365 & Copilot Security Health Check.
AI Governance Sentragon Insights Team

AI governance in plain English: what ISO 42001 and the NIST AI RMF actually ask for

A non-technical walkthrough of what these two frameworks require in practice, and where most SMBs are already falling short.

  • What each framework requires in practice
  • Why it matters even without pursuing formal certification
  • Where most SMBs are already falling short
Soft CTA: link to the AI Governance & Security Rapid Assessment.
General Sentragon Insights Team

Would you actually catch it? A plain-English look at detection maturity

Detection engineering and MITRE ATT&CK concepts for a non-specialist audience, framed around whether current monitoring would catch a realistic attack path.

  • Detection engineering and MITRE ATT&CK, explained for non-specialists
  • Whether current monitoring would catch a realistic attack path
  • Not a vendor feature comparison
Soft CTA: link to the SOC / Detection Maturity Assessment.