I make IT auditless intimidating.

Eight years of notes, tools, and templates from Big 4 and in-house audit. Free for anyone doing the work.
Testing DORA ICT third-party controlsReading NIST SP 800-161Building v2 of the DORA Audit Mapper
seven ways in. no gates, no logins, no email required.
DORA, without the re-reading.
652 paragraphs of the regulation, mapped so you don’t scope a DORA audit from scratch again.
Regulation · EUDORA, decoded.
the official text, the templates worth stealing, and what i’ve learned actually implementing it.
Profession · FreeThe auditor’s shelf.
IIA, ISACA, AICPA, COSO. the standards you’re actually held to.
Frameworks · CuratedThe frameworks that matter.
NIST, ISO, CIS, and the difference between the ones auditors quote and the ones you actually use.
What I read & follow.
the podcasts, communities, and people that shape how i think about audit. no affiliate links.
Guide · In progressBreaking in.
the IT audit career guide i wish i’d had at 22. writing it slowly, on purpose.
Working Papers · In progressWorking Papers.
the writing lives on LinkedIn today. moving it here properly, one post at a time.
Tool · DailyLive Feed.
AI-curated cybersecurity news, refreshed daily and tiered S to D for GRC relevance.