Blog · Dated, sourced analyses
The Sentrix blog
Short, dated analyses of threats, regulatory obligations and compliance practice, written by the Sentrix team with their primary sources cited every time.
latest on September 20, 2026RSS feed
FeaturedAnalysis · Identity3 min read
Non-human identities: the blind spot of your access reviews
Service accounts, API keys, tokens and AI agents are now the attackers' first way in. Why access reviews miss them, and where to start in two weeks.
Read the article →
01
Analysis
A threat or a news item, what it changes for a regulated organization, and what we think about it.
02
Regulatory breakdown
A requirement or a deadline, explained plainly, with how to prepare for it.
03
Field notes
A lesson from an engagement, anonymized, with what we would do again and what we would avoid.
The blog publishes what the team learns in contact with threats, frameworks and auditors: a threat that changes the game, a regulatory deadline to prepare for, a lesson from the field. Every article is dated, cites its primary sources and ends with what we think at Sentrix. For official advisories in continuous time, the Watch page does the rest.
All articles
Breakdown · NIS24 min read
NIS2: what transposition changes for your suppliers
NIS2 requires essential and important entities to manage their supply chain risk. What a North American supplier must prepare before the questionnaires arrive.
Learn more →
Breakdown · Law 254 min read
Law 25: when the PIA is mandatory and how to document it
The privacy impact assessment is required by Quebec's Law 25 in specific cases. What the Commission d'accès à l'information says about its content and form.
Learn more →
Breakdown · CPCSC4 min read
CPCSC Level 1: preparing the self-assessment
Level 1 of the Canadian Program for Cyber Security Certification rests on an annual self-assessment based on ITSP.10.171. What to prepare beforehand.
Learn more →
Breakdown · ISO 270014 min read
ISO 27001:2022 after the transition: what the auditor checks
The transition period to ISO/IEC 27001:2022 is closed. What changed compared with 2013, the 93 controls of Annex A, and what the auditor now looks at.
Learn more →
Breakdown · DORA4 min read
DORA: the register of information and what banks demand
DORA requires EU financial entities to keep a register of all their ICT contracts. What that register contains and what banks now ask of their ICT suppliers.
Learn more →
Analysis · Compliance4 min read
SOC 2 Type 1 or Type 2: which one your customers ask for
Type 1 describes controls at a date, Type 2 proves they operated over a period. What customers actually ask for, how the observation period works, how to plan.
Learn more →
Analysis · Vulnerabilities4 min read
Prioritizing patches with the KEV catalog and EPSS
CVSS tells you severity, not urgency. How CISA's KEV catalog and FIRST's EPSS change the order of your patches, and what directive BOD 26-04 now requires.
Learn more →
Analysis · Exposure4 min read
CTEM: the five stages explained
Scoping, discovery, prioritization, validation, mobilization: what each stage of the CTEM cycle produces, and what sets it apart from vulnerability management.
Learn more →
Field notes · Ransomware4 min read
Ransomware: the backup that holds
Immutability, an offline copy, restoration tests: three field lessons on the backups that held against ransomware, and the ones that gave way when it mattered.
Learn more →
Analysis · Identity4 min read
Phishing-resistant MFA: FIDO2 and passkeys
Why SMS codes and push notifications are no longer enough, what CISA and NIST call phishing-resistant MFA, and where to start the migration.
Learn more →
Analysis · Software supply chain4 min read
SBOM: what to ask a vendor
An SBOM is only useful if it is complete, machine-readable and delivered with every release. What the CISA and NTIA minimum elements let you require.
Learn more →
Field notes · TGV4 min read
TGV: lessons from the Performance group
Seven controls, PF01 to PF07, and one kind of evidence expected by the certification office: measurements, not estimates. What we see in the files we support.
Learn more →
Breakdown · Third-party risk4 min read
Vendor questionnaires: answer once, reuse
The SIG from Shared Assessments and the CAIQ from the Cloud Security Alliance: what they ask, and how to build one evidence base that answers both.
Learn more →
Field notes · Incidents4 min read
Tabletop exercise: what always comes out
A scenario, named roles, one morning: the tabletop exercise reveals the same gaps every time between the incident response plan and reality. How to run one.
Learn more →
Field notes · Cloud4 min read
The cloud misconfigurations we keep seeing
Microsoft 365, Entra ID, AWS: the same settings are missing from one assessment to the next. What we find, and why to start from the CIS Benchmarks.
Learn more →
Breakdown · AI4 min read
AI governance: ISO 42001 and the NIST AI RMF explained
ISO/IEC 42001 and the NIST AI RMF 1.0 frame how organizations use AI. What each one requires, how they complement each other, and which actions to start with.
Learn more →
Breakdown · Privacy5 min read
PIPEDA: reporting a breach of security safeguards
When a breach must be reported to the Privacy Commissioner of Canada, how to assess the real risk of significant harm, and how to keep the breach record.
Learn more →
Breakdown · Finance4 min read
OSFI B-13: what the board and the regulator expect
OSFI Guideline B-13 sets the technology and cyber risk expectations for federally regulated financial institutions. Three domains, evidence, board questions.
Learn more →
Breakdown · Defense5 min read
CMMC 2.0: levels, final rule and the real timeline
The three levels of CMMC 2.0, the 32 CFR part 170 final rule, the phased rollout in DoD contracts and the 2026 suspension of Phase 2, from the official texts.
Learn more →
Frequently asked questions
- What will I find here?
- Three formats, always dated and sourced: the analysis of a threat or a news item and what it changes for a regulated organization; the breakdown of a regulatory requirement or deadline and how to prepare for it; and anonymized lessons from our engagements. Every article cites its primary sources and gives our reading, signed Sentrix.
- How do I follow new articles?
- Through the blog's RSS feed, in French or English, or by following Sentrix on LinkedIn, where every article is posted. The Watch page complements the blog: it gathers the official advisories of Québec, Canada, the United States and Europe, refreshed every thirty minutes, while the blog takes the time to analyze.
