Insights

Articles, blog & news

Perspectives on Agentic Assurance, NCSC CAF programmes, product updates, and the evolving practice of evidence-led cyber assurance.

CyConex AI Assurance Platform diagram showing AI adoption gaps flowing into evidence-based governance and a ready AI Assurance Pack
Article14 min read

The EU AI Act Is Now Enforceable: Can You Prove Your AI Is Governed?

On 2 August 2026, applicable EU AI Act provisions became enforceable. This article explains why UK organisations still need evidence-based AI governance, how obligations depend on context and classification, and how CyConex supports the full AI Act compliance lifecycle with a defensible Assurance Pack.

Read more
Illustration contrasting a frozen annual audit with a live continuous CAF assurance dashboard and timeline
Article8 min read

CAF as a Continuous Programme, Not a Point-in-Time Audit

Most organisations still treat NCSC CAF as a once-a-year deliverable. This article explains why continuous assurance is a better fit for how cyber risk actually behaves, and how scheduled runs, an assurance history, and shareable live posture turn CAF into a programme you run rather than an event you survive.

Read more
Illustration of security evidence screened and sanitised before reaching a secure UK-hosted AI model
Article7 min read

Is It Safe to Use AI on Security Evidence? How CyConex Screens and Sanitises

The most common objection to AI-assisted assurance is a reasonable one: nobody wants to hand their security policies to a black box. This article explains the real risks of pointing AI at security evidence, and how CyConex screens for prompt-injection, sanitises sensitive data before it reaches a model, and keeps everything auditable and in the UK.

Read more
Illustration of a maturity path from Cyber Essentials to NCSC CAF on one shared evidence platform
Article7 min read

From Cyber Essentials to CAF: A Maturity Path

Cyber Essentials and NCSC CAF are often treated as separate worlds. This article shows how they fit on a single maturity path, and why starting with Cyber Essentials on the same platform you will later use for CAF saves rework, preserves evidence, and makes growth manageable.

Read more
Frozen paper-based audit records transforming into a live, continuous cyber assurance dashboard
Article12 min read

The End of Point-in-Time Assurance

Cyber risk does not move in annual cycles. This article explains why periodic, document-heavy assurance is no longer enough, and how continuous, evidence-driven and risk-informed assurance gives boards a living view of whether controls remain sufficient for the risks they cannot accept.

Read more
Infographic showing the agentic assurance workflow from evidence ingestion through AI analysis to human review, with review, challenge, justify, and validate steps
Blog15 min read

Agentic Assurance Still Needs the Human Assessor

Agentic assurance can ingest evidence, map controls, and highlight gaps at scale — but it changes the role of the human assessor rather than removing it. Professional judgement, risk context, and accountability must remain with qualified assessors.

Read more
Diagram of the Agentic Assessment Engine: evidence flows from policies and audit logs through AI analysis with human validation to control status, gap analysis, and audit readiness dashboards
Blog8 min read

Introducing Agentic Assurance and Compliance Assessments

Compliance assessments are slow, manual, and resource intensive. Agentic assurance uses AI agents to interpret control requirements, review evidence, and explain whether requirements are met — transforming how organisations prepare for NCSC CAF, ISO 27001, and similar frameworks.

Read more
CyConex assessment workspace with NCSC CAF control selection
Blog4 min read

What is Agentic Assurance?

Agentic Assurance combines AI agents with human expert judgement across the assurance lifecycle — orchestrating evidence work while assessors retain sign-off authority.

Read more