About Field Notes — short, practical writing from the Operational Trust practice. No opinion pieces. No thought leadership. Notes from what we see in reviews, written to be useful to the people doing the work. Operational Trust · Lead Reviewer

FN-001 · May 2026

The supplier dependency map most SMEs don't have

Most organisations can name their top suppliers. Fewer can answer: what happens if that supplier fails on a Tuesday afternoon, and your IT lead is on leave? The dependency map is the document that answers that question.

FN-002 · May 2026

What NIS2 actually requires of your suppliers

NIS2 is not just a regulation for large enterprises. If you supply to an entity in scope, you are likely in scope too. Here is what that means in practice — and what your enterprise clients are starting to ask for.

FN-003 · May 2026

Why tabletop exercises fail (and how to run one that doesn't)

Most SMEs treat tabletop exercises as IT drills. That is why they fail. A useful exercise tests the business decisions your leadership team must make under pressure — not just the technical responses your IT team already knows.

FN-004 · May 2026

Board liability under NIS2: ignorance is no longer a defence

Under Article 20 of NIS2, executives can be held personally liable for cybersecurity failures. Ignorance is not a defence. Here is what board members must do to demonstrate governance — and protect themselves.

FN-005 · May 2026

The Supplier Squeeze: Why your largest customer is about to audit your resilience

NIS2 does not only affect the large enterprises it names directly. If you supply services to an entity in scope, their compliance obligations flow downstream — arriving on your desk as a supplier-readiness audit. Here is what the Article 21 cascade means in practice, and three concrete steps to take tonight.

Further reading

Primary sources and reference documents referenced across our Field Notes.

NIS2 Directive — full text
EU law · External link
Open ↗
NCSC — Resilience guidance for organisations
NCSC · External link
Open ↗
ISO 22301 — business continuity overview
ISO · External link
Open ↗

Get new notes by email

New Field Notes are published monthly. No marketing. Unsubscribe at any time.

We do not share your address. GDPR compliant.