Blog

We write about
things that happen.

Featured The latest
Compliance NIS2

NIS2 for an Italian SME: what really changes in 2026

The transposition dates to 2024, but real enforcement arrives now. Strip away the noise and six concrete obligations and two dates remain. Here's what the regulation demands of a company with 80 to 500 employees, and what you can ignore.

by Team P3·14 May 2026·7 min
[NIS2]
Archive All the notes

The other notes.

Sovereignty

Sovereign cloud: how the EU actually measures it

"Sovereign cloud" is not an adjective: the EU has a yardstick — eight objectives and SEAL levels 0-4 — and in April 2026 it used it on a €180 million tender.

Team P3read →
Cyber · technical

What HUGIN finds on your domain in 90 seconds

Anatomy of a real passive scan: forgotten subdomains, expired certificates, an open RDP port and three keys on GitHub. How it happens and how to close it.

Team P3read →
Compliance · DORA

DORA: ICT resilience isn't a document

DORA (Reg. EU 2022/2554) demands real digital operational resilience, not paperwork: the 5 pillars, the dates and what a financial SME must actually do.

Team P3read →
Operations

A SOC in 48 hours: what it really takes

We state it in the price list, but what does it operationally mean to spin up a SOC for an SME in two days? The diary of a real onboarding. Coming soon on this blog.

Team P3coming soon
AI Act

AI Act: classifying risk without panic

The AI Act (Reg. EU 2024/1689) classifies AI by risk: bans, high-risk, transparency. The new dates after the 2026 Omnibus and where an SME should start.

Team P3read →
Stay updated One email a month, maybe

When we write,
we tell you.

No automated newsletter, no sales sequence. One email when a note worth reading goes out. EU address, one-click unsubscribe.

We handle your address per our privacy notice · EU servers · zero spam