For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/all.md.
Insights

All articles

Every article, guide, news post, report, and press mention from the FM CyberSecurity team, newest first.

5 Jun 2026 · Compliance · Articles
What the EU Cyber Resilience Act is, and who it covers

The CRA is an EU law that ties cybersecurity rules to CE marking, so a product with digital elements cannot enter the EU market without it.

Read more
4 Jun 2026 · Strategy · Articles
What CISSP certification means when picking a cybersecurity consultant

CISSP signals broad security judgment and a five-year experience bar, but it does not promise hands-on depth in any single tool you buy.

Read more
3 Jun 2026 · Compliance · Articles
What ISO 27001 Lead Implementer certification means for your project

An ISO 27001 Lead Implementer builds your ISMS; a Lead Auditor checks it. Hire the wrong role and your certification project stalls.

Read more
2 Jun 2026 · Application Security · Articles
Which regulations require recurring pentests, and how to deliver them without manual work

Five frameworks tell Norwegian SMBs to test security regularly. Only one mandates a human red team, and most teams overpay for the rest.

Read more
1 Jun 2026 · Application Security · Guides
How we pentest apps as part of ISO 27001 work

How FM CyberSecurity produces ISO 27001-defensible app pentest evidence through Aikido AI Pentest, without a manual pentest engagement, mapped to Annex A 8.29.

Read more
29 May 2026 · Exposure Management · Guides
How to get a free Tenable One tenant from us

How to get a free trial Tenable One tenant from FM CyberSecurity, scan your own infrastructure, and walk away with a written readout you can act on.

Read more
28 May 2026 · Identity Security · Guides
How to claim a free identity check via CrowdStrike

A free CrowdStrike Falcon Identity Protection trial that shows your exposed, stale, and over-privileged accounts before you commit to anything.

Read more
27 May 2026 · Identity Security · Articles
Talk to the chief architect behind one of the world's largest CyberArk deployments

When you buy privileged access management, you should talk to the practitioner who has run CyberArk at the largest scale, not a reseller.

Read more
26 May 2026 · Exposure Management · Guides
How we run the first vulnerability assessment in Tenable One

A two-week, day-by-day walkthrough of the first vulnerability assessment FM CyberSecurity runs on Tenable One for a new Norwegian SMB customer.

Read more
25 May 2026 · Exposure Management · Guides
How we run the vulnerability program for new customers in Tenable One

The weekly, monthly, and quarterly cadence FM CyberSecurity runs on Tenable One for Norwegian SMB customers, with the people, the meetings, and the evidence trail.

Read more
22 May 2026 · Exposure Management · Articles
Exposure management vs vulnerability management, why the terms are not the same

Vulnerability management tells you what is broken. Exposure management tells you what can hurt the contract you just signed.

Read more
21 May 2026 · Industry · News · Norway
FM CyberSecurity at Arrow ECS Summer Cloud Festival 2026

Four of us on the floor at Arrow ECS Norway's Summer Cloud Festival in Oslo. A big thanks to the Arrow crew for a great event.

Read more
21 May 2026 · Exposure Management · Guides
Nessus, Tenable Vulnerability Management, or Tenable One, which fits your business

A plain-English decision guide for Norwegian SMBs choosing between Nessus, Tenable Vulnerability Management, and Tenable One.

Read more
21 May 2026 · Exposure Management · News · Norway
Tenable visits FM CyberSecurity, and a lap on Silverstone

Tenable came by our Oslo office this week. Guy March took the sim for a lap on Silverstone and clocked 1:36.052.

Read more
20 May 2026 · Exposure Management · Guides
What Nessus is, and where it fits in the Tenable portfolio

A plain-English guide to Nessus, the Tenable scanner, including the current SKUs and how it relates to Tenable Vulnerability Management and Tenable One.

Read more
19 May 2026 · AI Security · Press · Norway
Fredrik Standahl in Digi.no on shadow AI in Norway

Digi.no published a Fredrik Standahl op-ed on treating AI as critical infrastructure and the Lovable breach as a warning sign.

Read more
19 May 2026 · AI Security · Press · Norway
Fredrik Standahl in E24 on shadow AI in Norway

E24 published a Fredrik Standahl op-ed on shadow AI in Norwegian workplaces and the data exposure pattern behind it.

Read more
19 May 2026 · AI Security · Guides
How we handle Shadow AI with Falcon AIDR

A six-step FM CyberSecurity engagement that takes a Norwegian SMB from no Shadow AI visibility to a written policy and Falcon AIDR detection rules in one quarter.

Read more
18 May 2026 · AI Security · Articles
What Shadow AI is, and why Norwegian SMBs struggle to see it

Shadow AI is unsanctioned AI use on company data. Norwegian SMBs miss it because policy without detection is faith, and usage moves to personal devices.

Read more
15 May 2026 · Endpoint Security · Guides
What a SOC is, and when you need your own

A plain-English guide to what a Security Operations Centre really does, what one costs to run, and why most Norwegian SMBs should rent rather than build.

Read more
14 May 2026 · Endpoint Security · Guides
What SIEM is, and when an SMB needs one

Most Norwegian SMBs do not need a standalone SIEM. Here is when you do, when your EDR already covers it, and what to do next.

Read more
13 May 2026 · Endpoint Security · Articles
EDR and antivirus, what the difference is, and what you need

Antivirus names a known bad file. EDR shows what the attacker did next. Against modern attacks you need the second answer.

Read more
12 May 2026 · Strategy · Articles
How we publish to our website with no admin login

FM CyberSecurity publishes through a Cloudflare Workers MCP server, gated by Microsoft Entra. No admin login, no user table, no CMS, no /forgot-password page.

Read more
12 May 2026 · Endpoint Security · Articles
What CrowdStrike Falcon is, the platform behind modern MDR

CrowdStrike Falcon is one lightweight agent and a cloud console that together replace a rack of separate endpoint security tools.

Read more
11 May 2026 · Compliance · Articles
From compliance burden to competitive advantage

How leadership teams move from compliance uncertainty to documented control, evidence that holds up under investor, customer, or regulatory due diligence.

Read more
11 May 2026 · Compliance · Articles
SOC 2 compliance for Norwegian SMBs selling into the US

SOC 2 can win you a US deal or burn six figures you did not need. Here is how to tell which, and how it fits ISO 27001.

Read more
8 May 2026 · Compliance · Articles
What SOC 2 Type 2 is, and why US customers ask for it

A US prospect asks for your SOC 2 Type 2 report, you do not have one, and the deal stalls. Here is what it is and the decision it forces.

Read more
7 May 2026 · Compliance · Articles
What Norway's Digital Security Act is, and how it relates to NIS2

If Norway counts your firm as critical, you have had legal digital-security duties since October 2025, and most boards have not noticed.

Read more
6 May 2026 · Compliance · Articles
What ISO 27001 is, and why you lose tenders without it

Buyers increasingly require ISO 27001 certification to even let you bid, so missing it quietly drops you from shortlists you would have won.

Read more
5 May 2026 · Compliance · Guides
ISO 27001 checklist for Norwegian SMBs

A practical ISO 27001 checklist that takes a Norwegian small or mid-size business from "we should get certified" to a Stage 2 audit.

Read more
4 May 2026 · Compliance · Guides
DORA checklist for Norwegian financial firms

A ten-step DORA checklist for Norwegian banks, insurers, payment firms and asset managers, with Finanstilsynet deadlines and what to do this quarter.

Read more
1 May 2026 · Compliance · Guides
NIS2 checklist for Norwegian SMB leaders

A leader-facing NIS2 checklist for Norwegian SMBs, the scope self-test, who owns what, the reporting clock, what to budget, and the board questions to ask.

Read more
30 Apr 2026 · Compliance · Articles
What NIS2 is, and which Norwegian businesses fall under it

NIS2 obligations flow down through contracts, so you can be asked to prove security maturity even before the rule reaches Norwegian law.

Read more
29 Apr 2026 · Application Security · Articles
Why Aikido is our only pentest provider

We deliver every pentest through Aikido AI Pentest because the annual manual report lands in a drawer and the application ships again the next week.

Read more
28 Apr 2026 · Exposure Management · Articles
Why we picked Tenable for exposure management

We standardised on Tenable because boards buy one map of business risk, not a longer list of CVEs no one has time to read.

Read more
27 Apr 2026 · Endpoint Security · Articles
Why we picked CrowdStrike Falcon for modern MDR

We run client MDR on CrowdStrike Falcon because the platform does the detection and response work a small security team cannot cover alone.

Read more
22 Apr 2026 · Compliance · Guides
How Nordic SMBs prepare for NIS2

Practical compliance steps for the new EU directive, what to do this quarter, and what can wait.

Read more
15 Apr 2026 · Strategy · Articles
Charlotte AI: what does agentic SOC mean for you?

A look at how CrowdStrike's agentic SOC changes the economics of 24/7 monitoring for SMBs.

Read more
14 Apr 2026 · AI Security · Press · Norway
Fredrik Standahl in Shifter on startup AI security

Shifter published a Fredrik Standahl commentary on the security failures common in AI-driven startup development.

Read more
5 Mar 2026 · Strategy · Press · Norway
FM CyberSecurity in VG, cybersecurity is booming

VG Dine Penger interviewed Fredrik Standahl on starting a cybersecurity firm in Norway and the niche's hiring boom.

Read more
1 Mar 2026 · Strategy · Press · Norway
FM CyberSecurity in Norwegian Cybersecurity Cluster

Norwegian Cybersecurity Cluster profiled FM CyberSecurity's founders and our first months building the firm in Oslo.

Read more
Questions or inquiry? [email protected] Contact us →