GSDC

ISO Standards at the Speed of Tech: A Thousand Audits a Day

December 2025 · Online webinar

This talk built on the LeadDev Berlin argument and applied it to the ISMS as a whole. An information security management system has to define controls, monitor them, evaluate whether they work, track risk, and close the gap between policy and what actually happens in production. Most organisations pour their effort into the first one or two of those and treat the rest as an annual exercise.

The session looked at what happens when automation covers the mechanical parts (monitoring, evidence collection, control testing) so that people can spend their time on the parts that need judgement: interpreting risk, deciding what matters, and making the call when something doesn’t fit the pattern.

Back to Talks