<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Spot Suite blog</title>
    <link>https://spot-suite.com/blog/</link>
    <description>Operating notes for regulated teams — identity, audit, residency, and vendor risk.</description>
    <language>en</language>
    <lastBuildDate>Thu, 16 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Conditional Access for workload identities: what it can and cannot do</title>
      <link>https://spot-suite.com/blog/conditional-access-for-workload-identities/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/conditional-access-for-workload-identities/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>Entra Conditional Access can block service principals by location and risk — but only single-tenant ones, only with block as the grant control, and only with Workload ID Premium. The limits matter as much as the feature.</description>
    </item>
    <item>
      <title>A DPA register for your SaaS stack: tracking the agreements you already signed</title>
      <link>https://spot-suite.com/blog/dpa-register-for-your-saas-stack/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/dpa-register-for-your-saas-stack/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>Every SaaS vendor processing personal data for you needs an Article 28 data processing agreement — and every one of those DPAs changes over time. What a working DPA register records, and why a folder of PDFs is not one.</description>
    </item>
    <item>
      <title>Collecting ISO 27001 Annex A evidence: what auditors sample and what actually counts</title>
      <link>https://spot-suite.com/blog/iso-27001-annex-a-evidence-collection/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/iso-27001-annex-a-evidence-collection/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>ISO/IEC 27001:2022 Annex A lists 93 controls across four themes. Evidence means records that the control operates — not the policy that says it should. What to collect per theme, and how to make collection continuous.</description>
    </item>
    <item>
      <title>Managing Conditional Access across multiple tenants</title>
      <link>https://spot-suite.com/blog/managing-conditional-access-across-multiple-tenants/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/managing-conditional-access-across-multiple-tenants/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>Entra Conditional Access has no native cross-tenant policy sync. How MSPs and multi-tenant operators keep policies consistent: Lighthouse baselines, policy as code, drift detection, and per-tenant break-glass.</description>
    </item>
    <item>
      <title>The four ways certificate renewal breaks (and which ones monitoring catches)</title>
      <link>https://spot-suite.com/blog/certificate-renewal-failure-modes/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/certificate-renewal-failure-modes/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>A certificate breaks on a Tuesday afternoon. The reason is almost always one of four things: a delegation that expired, an ACME rate limit, drift between issuance and the system serving traffic, or a cert nobody on the team knows exists. Monitoring catches one. The others need different controls.</description>
    </item>
    <item>
      <title>Finding CIDR conflicts before the peering ships</title>
      <link>https://spot-suite.com/blog/cidr-conflicts-before-they-ship/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/cidr-conflicts-before-they-ship/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>A VNet peering ships on Friday. On Saturday, traffic from a branch office is black-holing into a range another tenant in the same subscription has been using for two years. The reason is a CIDR overlap that nobody caught, because the address space lived in three spreadsheets and one engineer\u2019s head.</description>
    </item>
    <item>
      <title>A chain of custody for file transfers that survives an audit</title>
      <link>https://spot-suite.com/blog/file-transfer-chain-of-custody/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/file-transfer-chain-of-custody/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>Email and consumer file shares do not produce evidence. A custody record for a transferred file needs identity, timing, location, content fingerprint, and a signed receipt — plus retention that does not depend on someone remembering.</description>
    </item>
    <item>
      <title>Joiner-mover-leaver when nobody owns IT</title>
      <link>https://spot-suite.com/blog/joiner-mover-leaver-without-an-it-desk/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/joiner-mover-leaver-without-an-it-desk/</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <description>A 60-person company does not have an IT desk. It has an office manager, a controller, and a founder who resets passwords on a Sunday afternoon. The leaver who keeps a license and a laptop is the failure mode that JML is supposed to prevent. The question is what JML looks like without a ticketing system behind it.</description>
    </item>
    <item>
      <title>Maintaining DORA registers of information under Article 28</title>
      <link>https://spot-suite.com/blog/dora-ict-third-party-register/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/dora-ict-third-party-register/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>Financial entities must maintain an up-to-date register of ICT third-party contracts at entity and consolidated levels and supply it to supervisors on request.</description>
    </item>
    <item>
      <title>Conditional Access policies in multi-tenant regulated SaaS environments</title>
      <link>https://spot-suite.com/blog/entra-conditional-access-for-saas-operators/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/entra-conditional-access-for-saas-operators/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>Microsoft Entra Conditional Access evaluates signals at sign-in time to enforce per-tenant policies while preserving isolation between customer organisations.</description>
    </item>
    <item>
      <title>Using cloud cost data for DORA concentration risk assessments</title>
      <link>https://spot-suite.com/blog/finops-concentration-risk-dora/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/finops-concentration-risk-dora/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>DORA requires financial entities to assess concentration risk from ICT third-party providers; structured cloud spend data forms one input to that assessment.</description>
    </item>
    <item>
      <title>Operating an ISMS under ISO 27001:2022 after the 2025 transition</title>
      <link>https://spot-suite.com/blog/iso-27001-2022-after-transition/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/iso-27001-2022-after-transition/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>With the October 2025 deadline passed, certified organisations must demonstrate the 93 Annex A controls across four themes rather than the prior 14 domains.</description>
    </item>
    <item>
      <title>Turning NIS2 Article 21 into one audit export</title>
      <link>https://spot-suite.com/blog/nis2-article-21-audit-export/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/nis2-article-21-audit-export/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>NIS2 Article 21 lists ten risk-management measures. Here is how we map each one to a control you can already show an auditor, and export as a single pack.</description>
    </item>
    <item>
      <title>EU data residency without splitting your operating record</title>
      <link>https://spot-suite.com/blog/eu-data-residency-operating-record/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/eu-data-residency-operating-record/</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <description>Keeping data in the EU usually means standing up a second stack and reconciling two sets of records. It does not have to. Here is how region choice and one audit trail coexist.</description>
    </item>
    <item>
      <title>One Customer Environment for identity, billing, and audit</title>
      <link>https://spot-suite.com/blog/one-customer-environment/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/one-customer-environment/</guid>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
      <description>Most suites are a logo on a login page over separate products. We tied identity, billing, and the audit trail to one record per customer. Here is why, and what it costs.</description>
    </item>
    <item>
      <title>The compliance posture that lived in a binder instead of being exportable on demand</title>
      <link>https://spot-suite.com/blog/the-compliance-binder-that-could-not-be-exported/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-compliance-binder-that-could-not-be-exported/</guid>
      <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
      <description>Across ISO 27001, DORA, NIS2 and GDPR, the GRC lead has built a binder of policies and a backlog of evidence requests. When the regulator asks for proof of one control, it takes two weeks to assemble what should be one export.</description>
    </item>
    <item>
      <title>The data processing agreement signed at onboarding and never revisited</title>
      <link>https://spot-suite.com/blog/the-dpa-signed-once-and-never-revisited/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-dpa-signed-once-and-never-revisited/</guid>
      <pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate>
      <description>The DPO has a signed DPA for every vendor and assurance from none. Subprocessors changed, sub-locations moved, and the Article 28 obligations drifted, but the agreement sits in a drawer as if signing it was the control.</description>
    </item>
    <item>
      <title>The SaaS outage that took down a business process nobody had mapped to a tool</title>
      <link>https://spot-suite.com/blog/the-saas-outage-that-took-down-a-process-nobody-mapped/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-saas-outage-that-took-down-a-process-nobody-mapped/</guid>
      <pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate>
      <description>A mid-tier SaaS tool goes dark and a regulated workflow halts. The COO discovers there was no business-impact mapping, no RTO, and no fallback, because the tool was bought as a convenience and became load-bearing without anyone noticing.</description>
    </item>
    <item>
      <title>The exit plan the contract required and nobody ever wrote</title>
      <link>https://spot-suite.com/blog/the-exit-plan-the-contract-required-and-nobody-wrote/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-exit-plan-the-contract-required-and-nobody-wrote/</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate>
      <description>DORA Article 28 expects documented exit strategies for critical ICT providers. The vendor-management lead has the clause in every contract and the plan in none, until a price hike forces a migration they cannot execute.</description>
    </item>
    <item>
      <title>The penetration test that only covered the flagship app, not the eight around it</title>
      <link>https://spot-suite.com/blog/the-pen-test-that-only-covered-the-flagship-app/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-pen-test-that-only-covered-the-flagship-app/</guid>
      <pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate>
      <description>The annual pen test scopes the main product because that is what the budget bought. The regulated customer&apos;s security team asks for estate-wide assurance, and the IT director has coverage for one tool out of nine.</description>
    </item>
    <item>
      <title>The board report that had a revenue number but no operational resilience number</title>
      <link>https://spot-suite.com/blog/the-board-report-with-no-resilience-number/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-board-report-with-no-resilience-number/</guid>
      <pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate>
      <description>DORA put digital operational resilience on the board agenda, but the CTO walks in with uptime stats per tool and no estate-level view of concentration, recovery, or exposure. The board cannot govern a risk nobody can summarize.</description>
    </item>
    <item>
      <title>The MFA everyone assumed was on everywhere, except the three apps with local logins</title>
      <link>https://spot-suite.com/blog/the-mfa-everyone-assumed-was-on-everywhere/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-mfa-everyone-assumed-was-on-everywhere/</guid>
      <pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate>
      <description>Conditional access enforces MFA at the IdP, so leadership reports &apos;100% MFA coverage.&apos; Three legacy SaaS tools authenticate locally and bypass it entirely. The gap surfaces in a credential-stuffing incident, not the dashboard.</description>
    </item>
    <item>
      <title>The DPIA that skipped the four tools sitting behind the one it assessed</title>
      <link>https://spot-suite.com/blog/the-dpia-that-skipped-the-tools-behind-the-tool/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-dpia-that-skipped-the-tools-behind-the-tool/</guid>
      <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
      <description>A data protection impact assessment scopes the headline application and misses the analytics, support, backup, and notification subprocessors feeding off it. The DPO signs off on a processing map that is missing half the data flows.</description>
    </item>
    <item>
      <title>The audit trail your SaaS vendor could quietly edit</title>
      <link>https://spot-suite.com/blog/the-audit-trail-the-vendor-could-edit/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-audit-trail-the-vendor-could-edit/</guid>
      <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
      <description>Forensic readiness assumes your logs are tamper-evident. When each tool keeps its own mutable activity log with a 90-day retention, the &apos;append-only&apos; audit trail you promised the regulator is neither append-only nor complete.</description>
    </item>
    <item>
      <title>The internal mover who accumulated every role they ever held</title>
      <link>https://spot-suite.com/blog/the-mover-who-kept-every-role-they-ever-had/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-mover-who-kept-every-role-they-ever-had/</guid>
      <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
      <description>Joiner-mover-leaver everyone budgets for the joiner and the leaver. The mover is the one who quietly amasses entitlements across five departments over four years, until a privilege-creep finding turns into a segregation-of-duties failure.</description>
    </item>
    <item>
      <title>The 24-hour incident clock that started before anyone in the org noticed</title>
      <link>https://spot-suite.com/blog/the-incident-clock-that-started-before-anyone-noticed/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-incident-clock-that-started-before-anyone-noticed/</guid>
      <pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate>
      <description>DORA and NIS2 both impose tight initial-notification windows. When a SaaS subprocessor is breached, the regulated entity&apos;s reporting clock runs from detection, and a fragmented estate detects late, reports late, and explains it badly.</description>
    </item>
    <item>
      <title>The NIS2 obligations the IT director assumed did not apply to them</title>
      <link>https://spot-suite.com/blog/the-nis2-scope-the-it-director-thought-did-not-apply/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-nis2-scope-the-it-director-thought-did-not-apply/</guid>
      <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
      <description>NIS2 widened essential and important entity scope and pushed accountability onto management bodies. The IT director who assumed &apos;we&apos;re too small&apos; discovers the supply-chain and reporting duties land anyway, with personal liability attached.</description>
    </item>
    <item>
      <title>The renewal that auto-charged for 200 licenses, half of them assigned to leavers</title>
      <link>https://spot-suite.com/blog/the-renewal-that-auto-charged-for-licenses-nobody-used/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-renewal-that-auto-charged-for-licenses-nobody-used/</guid>
      <pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate>
      <description>The annual SaaS renewal lands at last year&apos;s seat count. The finance director approves it because reconciling actual usage across a dozen tools is harder than just paying. License leakage is a budget line nobody owns.</description>
    </item>
    <item>
      <title>The enterprise deal lost on a security questionnaire you could not answer in time</title>
      <link>https://spot-suite.com/blog/the-deal-lost-on-a-security-questionnaire/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-deal-lost-on-a-security-questionnaire/</guid>
      <pubDate>Wed, 04 Jun 2025 00:00:00 GMT</pubDate>
      <description>A regulated buyer sends a 300-line vendor assessment with a two-week deadline. The COO can answer for the flagship product but not for the eight tools behind it, and the deal slips to a competitor who could.</description>
    </item>
    <item>
      <title>The ISO 27001 evidence pack assembled by hand the night before the surveillance audit</title>
      <link>https://spot-suite.com/blog/the-iso-27001-evidence-assembled-the-night-before/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-iso-27001-evidence-assembled-the-night-before/</guid>
      <pubDate>Wed, 14 May 2025 00:00:00 GMT</pubDate>
      <description>Ten exports, three spreadsheets, and a folder of screenshots stitched together at midnight. The 2025 transition raised the bar on evidence quality, and a binder of stale screenshots no longer passes a competent auditor.</description>
    </item>
    <item>
      <title>The EU data residency claim your subprocessor quietly broke</title>
      <link>https://spot-suite.com/blog/the-data-residency-claim-the-subprocessor-broke/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-data-residency-claim-the-subprocessor-broke/</guid>
      <pubDate>Tue, 22 Apr 2025 00:00:00 GMT</pubDate>
      <description>Sales told the regulated prospect &apos;all data stays in the EU.&apos; One SaaS tool&apos;s support tier routes through a US team, and the DPO finds out during the due-diligence questionnaire that loses the deal.</description>
    </item>
    <item>
      <title>The fourth-party concentration risk nobody mapped until the subprocessor went down</title>
      <link>https://spot-suite.com/blog/the-vendor-concentration-nobody-mapped-until-it-failed/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-vendor-concentration-nobody-mapped-until-it-failed/</guid>
      <pubDate>Thu, 03 Apr 2025 00:00:00 GMT</pubDate>
      <description>Five of your critical SaaS vendors run on the same cloud region and the same auth provider. DORA Article 30 now expects you to know that before the outage, not during it.</description>
    </item>
    <item>
      <title>The shadow SaaS estate that finance found on the corporate card, not in the CMDB</title>
      <link>https://spot-suite.com/blog/the-shadow-saas-bought-on-a-corporate-card/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-shadow-saas-bought-on-a-corporate-card/</guid>
      <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
      <description>The finance director reconciles the card statement and finds 40 SaaS subscriptions IT never approved, half of them processing customer data. Shadow IT is a procurement control failure before it is a security one.</description>
    </item>
    <item>
      <title>The access review that took six weeks of spreadsheet exports and still failed the audit</title>
      <link>https://spot-suite.com/blog/the-access-review-that-took-six-weeks-and-still-failed/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-access-review-that-took-six-weeks-and-still-failed/</guid>
      <pubDate>Sun, 23 Feb 2025 00:00:00 GMT</pubDate>
      <description>When identity lives in twelve apps, the annual access certification is a hand-merged spreadsheet that is stale before it is signed. ISO 27001 control 5.18 and SOC 2 CC6 expect a review you can reproduce, not reconstruct.</description>
    </item>
    <item>
      <title>The leaver who still has access to three SaaS apps, 90 days after their last day</title>
      <link>https://spot-suite.com/blog/the-leaver-who-still-has-access-to-three-saas-apps/</link>
      <guid isPermaLink="true">https://spot-suite.com/blog/the-leaver-who-still-has-access-to-three-saas-apps/</guid>
      <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
      <description>31% of former employees keep access to at least one company app, and the CISO only finds out when one of them logs in. Deprovisioning that stops at the HR system and the IdP is not deprovisioning.</description>
    </item>
  </channel>
</rss>
