Refined metadata scheme and applied it to posts

This commit is contained in:
Richard Kranendonk 2026-06-02 17:54:44 +02:00
parent e806e6764b
commit 831590bc72
19 changed files with 703 additions and 47 deletions

View file

@ -1,3 +1,36 @@
---
title: "IT is not going to fix your security problem"
language: en
proposition: advisory
series-id: s01
series-title: "Security as an organisational challenge"
series-part: 1
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-13T17:30:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-activity-7460380869439016960-G-7x"
notetype: publication
isotags: []
tags: []
---
`Posted on 13 May 2026 19:30 CEST to LinkedIn personal stream`
# IT is not going to fix your security problem
@ -5,10 +38,10 @@ IT is not going to fix your security.
Not because they don't want to. Not because they lack technical skills. But because essential parts of information security are out of scope for the IT department.
Heres what I see in practice:.
Here's what I see in practice:.
- A website developer temporarily shares admin rights with an external consultant to troubleshoot an integration.
- The account of the maintenance engineer that left the company last year is still being used.
- A sales agent in Brazil gets full access to the companys CRM, despite operating under a different legal framework.
- A sales agent in Brazil gets full access to the company's CRM, despite operating under a different legal framework.
Examples of non-trivial information security risks arising in day-to-day operations. They cannot be fixed by technical solutions. Why? Because they're management issues, not IT problems.
@ -21,4 +54,4 @@ Which questions are not being asked in your organization?
— Security as an organizational challenge — post 1/3
**#managingsecurity**
**#managingsecurity**

View file

@ -1,3 +1,36 @@
---
title: "De IT afdeling gaat jouw beveiliging niet op orde krijgen"
language: nl
proposition: advisory
series-id: s01
series-title: "Security als managementvraagstuk"
series-part: 1
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-13T08:30:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-activity-7460245060933136384-IiMo"
notetype: publication
isotags: []
tags: []
---
`posted on 13 May 2026 10:30 CEST to LinkedIn personal stream`
# De IT afdeling gaat jouw beveiliging niet op orde krijgen
@ -15,4 +48,4 @@ Welke vragen worden in jouw organisatie niet gesteld?
— Security als managementvraagstuk — post 1/3
**#managingsecurity**
**#managingsecurity**

View file

@ -1,3 +1,36 @@
---
title: "All security risks start with a decision"
language: en
proposition: advisory
series-id: s01
series-title: "Security as an organisational challenge"
series-part: 2
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-14T17:15:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-activity-7460739462822592512-sZ68"
notetype: publication
isotags: []
tags: []
---
`Posted on 14 May 2026 19:15 CEST to LinkedIn personal stream`
# All security risks start with a decision
@ -22,4 +55,4 @@ Don't just ask the question: "How will we make this a success?", but also ask: "
— Security as an organizational challenge — post 2/3
**#managingsecurity**
**#managingsecurity**

View file

@ -1,3 +1,36 @@
---
title: "Een beveiligingsrisico begint met een beslissing"
language: nl
proposition: advisory
series-id: s01
series-title: "Security als managementvraagstuk"
series-part: 2
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-18T08:15:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-activity-7462053131720413185-S-oH"
notetype: publication
isotags: []
tags: []
---
`posted on 18 May 2026 10:15 CEST to LinkedIn personal stream`
# Een beveiligingsrisico begint met een beslissing
@ -22,4 +55,4 @@ Stel niet alleen de vraag: "hoe maken we dit tot een succes?", maar vraag ook: "
— Security als managementvraagstuk — 2/3
\#managingsecurity
\#managingsecurity

View file

@ -1,3 +1,36 @@
---
title: "Security isn't an IT problem, it's a management issue"
language: en
proposition: advisory
series-id: s01
series-title: "Security as an organisational challenge"
series-part: 3
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-15T17:30:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-iso27001-resilience-activity-7461105663067283456-E_-F"
notetype: publication
isotags: []
tags: []
---
`Posted on 15 May 2026 19:30 CEST to LinkedIn personal stream`
# Security isn't an IT problem, it's a management issue.
@ -15,4 +48,4 @@ I'd be curious to hear how that's arranged in your organization. Feel free to se
— Security as an organizational challenge — 3/3
\#managingsecurity \#iso27001 \#resilience
\#managingsecurity \#iso27001 \#resilience

View file

@ -1,3 +1,36 @@
---
title: "Security is geen IT-probleem, maar een managementvraagstuk"
language: nl
proposition: advisory
series-id: s01
series-title: "Security als managementvraagstuk"
series-part: 3
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-19T08:00:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-iso27001-cyberweerbaarheid-activity-7462411782574452736-VfjA"
notetype: publication
isotags: []
tags: []
---
`posted on 19 May 2026 10:00 CEST to LinkedIn personal stream`
# Security is geen IT-probleem, maar een managementvraagstuk.
@ -15,4 +48,4 @@ Ik ben benieuwd hoe dat in jouw organisatie geregeld is. Stuur me gerust een ber
— Security als managementvraagstuk — 3/3
\#managingsecurity \#iso27001 \#cyberweerbaarheid
\#managingsecurity \#iso27001 \#cyberweerbaarheid

View file

@ -1,4 +1,30 @@
`posted on XX May 2026 XX:XX CEST to LinkedIn personal stream`
---
title: "Good intentions don't scale"
language: en
proposition: advisory
series-id: s01
series-title: "Security as an organisational challenge"
series-part: 4
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
# Good intentions don't scale
Good intentions don't scale.
@ -13,4 +39,4 @@ The real question isn't whether your current team is taking security seriously.
How does your organization make sure security holds up when people and circumstances change? I'm curious — feel free to send me a message.
\#managingsecurity \#iso27001
\#managingsecurity \#iso27001

View file

@ -1,3 +1,36 @@
---
title: "Op 1 juli treedt de Cbw in werking"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 1
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-21T08:03:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-share-7463137163187171328-OQMx/"
notetype: publication
isotags: []
tags: []
---
`posted on 21 May 2026 10:03 CEST to LinkedIn personal stream`
Als bestuurder wordt jij op 1 juli 2026 persoonlijk verantwoordelijk voor informatiebeveiliging.
@ -14,4 +47,4 @@ Dat betekent dat je betrokken moet zijn bij de keuzes die op hoofdlijnen gemaakt
In de komende vier posts geef ik de acht stappen die je als directie moet zetten om aan de Cbw te voldoen. Aan het eind heb je een concreet en direct uitvoerbaar stappenplan, en weet je wat er van jou als bestuurder verwacht wordt.
— Cbw-compliance in 8 stappen — 1/5 \#managingsecurity \#Cbw \#NIS2
— Cbw-compliance in 8 stappen — 1/5 \#managingsecurity \#Cbw \#NIS2

View file

@ -1,3 +1,36 @@
---
title: "Je cybersecurity hoeft niet perfect te zijn"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 2
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-26T08:40:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-share-7464958267241267200-rCSz/"
notetype: publication
isotags: []
tags: []
---
`posted on 26 May 2026 10:40 CEST to LinkedIn personal stream`
# Je cybersecurity hoeft niet perfect te zijn
@ -13,4 +46,4 @@ De uitkomst van de Cbw is dat informatiebeveiliging niet langer 'een IT-feestje'
In de volgende post de eerste vier stappen om dit in te richten.
— Cbw-compliance in 8 stappen — 2/5 \#managingsecurity \#Cbw \#NIS2
— Cbw-compliance in 8 stappen — 2/5 \#managingsecurity \#Cbw \#NIS2

View file

@ -1,3 +1,36 @@
---
title: "De Cbw voor bestuurders: waar begin je?"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 3
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-27T08:22:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-share-7465316450682011650-lg9O/"
notetype: publication
isotags: []
tags: []
---
`posted on 27 May 2026 10:22 CEST to LinkedIn personal stream`
# De Cbw voor bestuurders: waar begin je?
@ -17,4 +50,4 @@ Stap 4: Incident response — Als er iets misgaat, moet er een plan liggen. Dan
Deze vier stappen zorgen voor inzicht en vertrouwen. In de volgende post de vier stappen die informatiebeveiliging compliant en aantoonbaar maken.
— Cbw-compliance in 8 stappen — 3/5 \#managingsecurity \#Cbw \#NIS2
— Cbw-compliance in 8 stappen — 3/5 \#managingsecurity \#Cbw \#NIS2

View file

@ -1,3 +1,36 @@
---
title: "Hoe kun je als bestuurder aantonen dat je voldoet aan de Cbw?"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 4
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-05-28T08:33:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-share-7465681697880035329-E7VV/"
notetype: publication
isotags: []
tags: []
---
`posted on 28 May 2026 10:33 CEST to LinkedIn personal stream`
# Hoe kun je als bestuurder aantonen dat je voldoet aan de Cbw?
@ -16,4 +49,4 @@ Stap 8: Borging in de organisatie — Voldoen aan de Cbw is geen eenmalig projec
In de volgende post: Cbw compliance heeft geen finishlijn, maar vraagt wel voortdurende aandacht.
— Cbw-compliance in 8 stappen — 4/5 \#managingsecurity \#Cbw \#NIS2 \#Compliance
— Cbw-compliance in 8 stappen — 4/5 \#managingsecurity \#Cbw \#NIS2 \#Compliance

View file

@ -1,3 +1,36 @@
---
title: "De Cbw is geen project!"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 5
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: published
publish-dates:
linkedin: 2026-06-01T13:31:00Z
published-urls:
linkedin: "https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-activity-7467206197365030912-E-pn"
notetype: publication
isotags: []
tags: []
---
`posted on 1 June 2026 15:31 CEST to LinkedIn personal stream`
# De Cbw is geen project!
@ -16,4 +49,4 @@ Als je wilt weten waar jouw organisatie staat, praat ik graag een uur met je.
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2
Vorige post hier: https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-activity-7465681698601566209-Do6v
Vorige post hier: https://www.linkedin.com/posts/richardkranendonk_managingsecurity-cbw-nis2-activity-7465681698601566209-Do6v

View file

@ -1,3 +1,28 @@
---
title: "Bonus post: Cbw en ISO 27001"
language: nl
proposition: advisory
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: 6
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2

View file

@ -1,3 +1,30 @@
---
title: "Er is geen diploma voor Cbw-compliance"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: null
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
Er is geen diploma voor Cbw-compliance, but the ISO 27001 comes pretty close.
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2

View file

@ -1,3 +1,30 @@
---
title: "Toch een Cbw checklist"
language: nl
proposition: advisory
series-id: s02
series-title: "Cbw-compliance in 8 stappen"
series-part: null
audience:
- leadership
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
# De Cbw voor bestuurders: weten waar je staat vóór 1 juli 2026
In mijn vorige post schreef ik, dat je de minimummaatregelen uit artikel 21 van de Cyberbeveiligingswet moet zien als een kader om te sturen in een voortdurend veranderende omgeving, en niet als een checklist voor eenmalig gebruik.
@ -13,4 +40,3 @@ Als je na de checklist graag een uurtje wilt sparren over hoe nu verder, dan pra
— Cbw-compliance in 8 stappen — 5/5 \#managingsecurity \#Cbw \#NIS2
https://iso27diy.com/assets/cbw-checklist.html

View file

@ -1,3 +1,26 @@
---
title: "Do you supply EU customers in vital sectors?"
language: en
proposition: advisory
audience:
- msp
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
**Do you supply EU customers in vital sectors? They will send you this checklist.**
The EU Cybersecurity Act (NIS2) is now being implemented across member states of the European Union. One of its core requirements: supply chain responsibility. Organizations that fall under the law are legally obligated to assess the security posture of their suppliers — and to contractually enforce minimum standards.

View file

@ -1,3 +1,26 @@
---
title: "Sorry, but you can't automate ISO 27001 compliance"
language: en
proposition: advisory
audience:
- general
channels:
- linkedin
linkedin-account: personal
content-type:
- post
status: draft
notetype: publication
isotags: []
tags: []
---
**Sorry, but you can't automate ISO 27001 compliance**
Some vendors promise ISO 27001 certification at next to nothing, through the use of AI. Cheap, fast, and effortless. If it sounds too good to be true, it probably is.