Blog

Notes from the Aquil team

Product updates, practical ISMS guidance and lessons from building security tooling for real organizations.

ComplianceVictor Pettersson

How to get ISO 27001 certified (step by step)

The path to ISO 27001 certification, step by step: management mandate, a tight scope, gap analysis, the risk assessment, your SoA, internal audit and the two-stage external audit, with realistic timelines and costs.

Read article
SecurityVictor Pettersson

Why we added an AI embedding model (and where it runs)

We added text-embedding-3-small so Aquil can find your documents by meaning, not just by keyword. It runs in our own Azure region in Sweden, your text is never sent to OpenAI, and only a numeric vector is ever stored.

Read article
ComplianceVictor Pettersson

NIS2 vs ISO 27001: what's the difference?

One is binding EU law, the other a voluntary standard, yet they overlap more than they differ. How NIS2 relates to ISO 27001, and how to use one to satisfy the other.

Read article
EfterlevnadVictor Pettersson

Cybersäkerhetslagen är här – en praktisk checklista för NIS2 i Sverige

Den nya cybersäkerhetslagen gör NIS2 till svensk lag och omfattar långt fler verksamheter än tidigare. Vilka berörs, vad kräver lagen och var börjar man? En praktisk checklista i sex steg.

Read article
ComplianceVictor Pettersson

The Statement of Applicability (SoA): what it is and how to write one

What the Statement of Applicability is, why ISO 27001 certification hinges on it, what every row must contain, how it connects to your risk assessment, and how to keep it current instead of rebuilding it before every audit.

Read article
ProductVictor Pettersson

Let AI agents into your ISMS without handing over the keys

AI agents are good at exactly the work an ISMS is full of: drafting reports, walking through procedures, updating registers. The hard part was always access. Aquil's API and MCP service makes an agent a faithful stand-in for you, never a superset of you.

Read article
ComplianceVictor Pettersson

How to run an ISO 27001 gap analysis (free template)

A practical guide to the ISO 27001 gap analysis, with a free Excel template covering clauses 4–10 and all 93 Annex A controls: how to run it, prioritize the gaps, and turn the result into a plan.

Read article
SalesVictor Pettersson

Know in minutes whether you can win the deal

A procurement questionnaire lands and its security section quietly decides whether you can even bid. Instead of forwarding it to compliance and waiting days, get an honest per-requirement verdict the same day.

Read article
ProductVictor Pettersson

Answer once, reuse everywhere: the capability ledger for service providers

Software and service providers answer the same security questions forever: one ISO audit, every customer's procurement questionnaire, the next framework. Answer each one once and reuse it everywhere.

Read article
ComplianceVictor Pettersson

Compliance you can prove

Auditors want evidence, a name against it, and a date. How Aquil's capability ledger turns compliance into answers you can actually prove, and keeps proving them as evidence ages.

Read article
ProductVictor Pettersson

How Aquil keeps teams in sync: inside the process workflow engine

Security work is a team sport: incident response, onboarding and supplier reviews all cross team boundaries. How Aquil turns process diagrams into executable workflows, with handoffs that don't drop the ball.

Read article
ComplianceVictor Pettersson

Your gap analysis should be a living thing

A gap analysis in a spreadsheet is out of date the day after the workshop. How the Compliance Assistant keeps all 93 Annex A controls (and the frameworks next to them) continuously current.

Read article
ProductVictor Pettersson

Stop writing your ISMS from a blank page

Policies shouldn't start in an empty document. How AI-assisted drafting, honest document conversion and built-in ownership turn ISMS documentation into a habit instead of a project.

Read article