<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Governa Blogg</title>
    <link>https://governa.no</link>
    <description>Engineering Governance — teknologi, sikkerhet og GRC.</description>
    <language>nb</language>
    <atom:link href="https://governa.no/rss.xml" rel="self" type="application/rss+xml" />

    <item>
      <title>The 10 Mandatory Security Measures</title>
      <link>https://governa.no/articles/the-10-mandatory-security-measures</link>
      <guid isPermaLink="true">https://governa.no/articles/the-10-mandatory-security-measures</guid>
      <description>These are the minimum measures every in-scope entity must implement: 1. Risk analysis and information system security policies Formal, documented policies covering how the organisation identifies, assesses, and manages cybersecurity risks. 2. Incident handling Procedures for prevention, detection, a...</description>
      <pubDate>Sat, 04 Apr 2026 09:45:00 GMT</pubDate>
      
    </item>

    <item>
      <title>From Phishing to NIS2: Detecting and Responding to Modern Email Compromise</title>
      <link>https://governa.no/articles/from-phishing-email-to-nis2-incident-turning-real-attacks-into-compliance-evidence</link>
      <guid isPermaLink="true">https://governa.no/articles/from-phishing-email-to-nis2-incident-turning-real-attacks-into-compliance-evidence</guid>
      <description>Threat You’ve probably heard about the large phishing campaign in Norway recently. While phishing campaigns are nothing new, this one stood out for a few important reasons. First, parts of the attack leveraged Norwegian infrastructure. This meant that both the phishing emails and the subsequent logi...</description>
      <pubDate>Fri, 20 Mar 2026 03:26:00 GMT</pubDate>
      <author>Andrius</author>
    </item>
  </channel>
</rss>