ISO27K

The Compliance Brief for ISO 27001 teams

Every Tuesday, the supplier incidents, AI risk stories and security events from the past week that belong in an ISO 27001 or ISO 42001 risk register.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

An ISMS is only as current as its risk register, and most registers are updated once a year. The Compliance Brief is a weekly prompt: the supplier breaches, AI agent incidents and supply chain attacks that a surveillance auditor would expect you to have noticed.

Below are the stories from recent issues that bear on ISO 27001 and ISO 42001, each with the short version and a link to the full take.

Latest on ISO 27001, ISO 42001 and supplier risk

Every issue on ISO27K

Every issue in full, including the stories outside ISO 27001, ISO 42001 and supplier risk, is in the archive on traztech.ca. Issues with nothing on ISO 27001, ISO 42001 and supplier risk are listed there and not here.

Questions

How often does The Compliance Brief arrive?

Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for teams running an ISO 27001 or ISO 42001 management system.

What does it cost?

Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates ISO27K. There is no paid tier.

Will signing up here send me anything else?

No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.

How do I stop it?

Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.