Operations | Monitoring | ITSM | DevOps | Cloud

How Federal IT Teams Move to FIPS 140-3 Without Disrupting Authorization or Service Continuity

A credible FIPS 140-3 transition does more than replace an operating system. It protects authorization timelines, service continuity, rollback options, and accountability across the operational boundary.

What Is DORA Compliance? The Digital Operational Resilience Act Explained

The Digital Operational Resilience Act has applied to EU financial firms since 17 January 2025. The first year was mostly paperwork. In year two, supervisors want proof, and most of that proof sits with IT operations. DORA joins the other rules on your cybersecurity compliance list, with much tighter clocks. A major incident needs its first report within 4 hours of classification. In this blog, you will: By the end, you will know what DORA compliance asks of your IT team and where to begin.

From SOCI Compliance to Continuous Infrastructure: How Puppet Helps Protect Critical Infrastructure

Australia’s critical infrastructure landscape has changed significantly. The Security of Critical Infrastructure Act 2018 (SOCI Act) has evolved from a framework focused primarily on identifying critical assets and reporting incidents into a broader risk-management and operational-resilience regime. The 2024 reforms reinforced that direction, increasing the focus on the systems, data, and technology dependencies that underpin Australia’s essential services.

Digital ID Arrives at the Till: What the Alcohol Rule Change Means for Checkout Integrations

For years, proof of age at an alcohol till in England and Wales meant something you could hold in your hand: a passport, a photocard driving licence, a PASS card. That's no longer the whole list. Since mid-September 2026, licensed premises can accept certified digital proof of age from a customer's phone.

Compliance guardrails for regulated delivery

One multinational running on Upsun operates more than 400 websites. Each subsidiary has its own sites, its own team, its own release schedule, and its own local requirements. What they share is one infrastructure control layer: the same access model, the same encryption defaults, the same activity records, the same region and backup policy on every project. Adding the 401st site does not add a 401st set of infrastructure controls for someone to review.

ISO 20000 Certification: Prerequisites, Process, and Cost

ISO 20000 certification means two different things depending on who is asking. One is an audit of your organization against ISO 20000. The other is an exam that one person sits. Search results mix the two together, and teams lose weeks to it. A service desk manager hunting a company certificate lands on a training catalog. They book a course nobody needed. In this blog, you will: You will finish able to scope the project and brief a certification body.

ISO 20000 in ITSM: What the Standard Actually Requires From Your Service Desk

Certification against ISO 20000 puts your service desk under audit. That audit runs on what your team wrote down at the time. The standard does not care how your team describes its process. It does not care which ITIL 4 practices you adopted. It cares what your records show, so auditors spend their time in your tickets, approvals, and review minutes. In this blog, you will: You will finish knowing which of your records would survive an audit.

The Essential Eight: Patching Applications and Operating Systems at Maturity Level Two

Why do so many patching programs pass every internal check and still come back from an Essential Eight assessment rated at Maturity Level One? The answer is rarely speed. Teams that miss the mark are usually patching their servers, browsers, and office suites on schedule, then losing the rating on the fifty applications nobody put on a list. Maturity Level Two is where the Essential Eight stops asking how fast you patch and starts asking how much you can see.

The Best B2B Cross-Border Payment Solutions in 2026

Moving money across borders is not one problem. There are four, and most buyers discover the other three after signing. Reach, meaning whether a provider can pay into the markets and instrument types your recipients actually use. Settlement speed, where correspondent banking still fails. Cost transparency, since intermediary fees stay invisible until reconciliation. And compliance, the one that stops a launch rather than slowing it.

Data residency in 2026: what regulators now expect from your cloud, and how to prove it

Ask a compliance team where their EU customer data lives, and most will point confidently at a dashboard showing a Frankfurt or Dublin region. Ask their legal counsel whether that data is beyond the reach of a foreign government demand, and the confidence usually drops. Those are two different questions. Since 12 September 2025 there has been a dated EU obligation that turns on the second one rather than the first.