<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>Pelican Tech Blog</title>
  <subtitle>Cybersecurity, AI governance, and MedTech regulatory writing from the practice</subtitle>
  <link href="https://www.pelican-tech.com/blog/feed.xml" rel="self"/>
  <link href="https://www.pelican-tech.com/blog/"/>
  <updated>2026-04-30T00:00:00.000Z</updated>
  <id>https://www.pelican-tech.com/blog/</id>
  <entry>
    <title>NIS2 Compliance Beyond Checkboxes: A 2026 Implementation Playbook</title>
    <link href="https://www.pelican-tech.com/blog/nis2-compliance-2026.html"/>
    <id>https://www.pelican-tech.com/blog/nis2-compliance-2026.html</id>
    <updated>2026-04-30T00:00:00.000Z</updated>
    <summary>A practitioner&#39;s guide to NIS2 implementation that goes beyond control catalogs. It covers what regulators actually look for, where mid-market security teams stall, and how to build a defensible programme in 90 days.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>Cloud Security for Boards That Still Need Engineering Detail</title>
    <link href="https://www.pelican-tech.com/blog/cloud-security-boards.html"/>
    <id>https://www.pelican-tech.com/blog/cloud-security-boards.html</id>
    <updated>2026-04-28T00:00:00.000Z</updated>
    <summary>A practical translation between what boards ask about cloud risk and what engineering teams actually have to build. No fluff, no maturity-model bingo, just the controls that move the loss curve.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>Identity Is the New Perimeter: Practical Zero-Trust for Mid-Size Companies</title>
    <link href="https://www.pelican-tech.com/blog/identity-zero-trust.html"/>
    <id>https://www.pelican-tech.com/blog/identity-zero-trust.html</id>
    <updated>2026-04-25T00:00:00.000Z</updated>
    <summary>What zero-trust actually means at the implementation layer when you don&#39;t have a Google-scale budget. The four moves that close 80 percent of the realistic attack surface, and the trap that swallows the rest.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>SIEM and SOAR Without Alert Fatigue: A Detection Engineering Approach</title>
    <link href="https://www.pelican-tech.com/blog/siem-soar-detection-engineering.html"/>
    <id>https://www.pelican-tech.com/blog/siem-soar-detection-engineering.html</id>
    <updated>2026-04-22T00:00:00.000Z</updated>
    <summary>How to run a SIEM and SOAR programme that produces actionable detections rather than a 200-deep Slack channel of high-severity noise. The detection-engineering practices that separate functional SOCs from theatrical ones.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>The CISO&#39;s $4M Question: Which Pre-Breach Investments Actually Move the Loss Curve</title>
    <link href="https://www.pelican-tech.com/blog/ciso-4m-question.html"/>
    <id>https://www.pelican-tech.com/blog/ciso-4m-question.html</id>
    <updated>2026-04-19T00:00:00.000Z</updated>
    <summary>The IBM Cost of a Data Breach number is famous. The decisions a CISO can make today to bend that number down are less famous. The four investment categories that demonstrably reduce loss expectancy and the popular ones that mostly do not.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>Implementing ISO/IEC 42001: An AI Governance Roadmap That Doesn&#39;t Stall</title>
    <link href="https://www.pelican-tech.com/blog/iso-42001-ai-governance.html"/>
    <id>https://www.pelican-tech.com/blog/iso-42001-ai-governance.html</id>
    <updated>2026-04-16T00:00:00.000Z</updated>
    <summary>ISO 42001 is the first AI management system standard with audit teeth. This is how to actually implement it, where the typical programmes get stuck, and what the EU AI Act overlap saves you.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>OWASP LLM Top 10 in Production: Hardening RAG, Agents, and the Vectors Most Teams Miss</title>
    <link href="https://www.pelican-tech.com/blog/owasp-llm-top-10.html"/>
    <id>https://www.pelican-tech.com/blog/owasp-llm-top-10.html</id>
    <updated>2026-04-13T00:00:00.000Z</updated>
    <summary>The OWASP LLM Top 10 isn&#39;t a checklist. It&#39;s a threat model that maps cleanly onto product security work if you know how to read it. Where the real risks live in production GenAI deployments and what to actually build.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>Prompt Injection Is a Product Security Problem, Not a Model Limitation</title>
    <link href="https://www.pelican-tech.com/blog/prompt-injection-product-security.html"/>
    <id>https://www.pelican-tech.com/blog/prompt-injection-product-security.html</id>
    <updated>2026-04-10T00:00:00.000Z</updated>
    <summary>The framing of prompt injection as a model-quality problem misdirects attention. The realised attacks land in production because of architecture decisions, not because the model is gullible. The product-security pattern that closes the class.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>AI Risk Assessment for Regulated Industries: A Working Template</title>
    <link href="https://www.pelican-tech.com/blog/ai-risk-regulated-industries.html"/>
    <id>https://www.pelican-tech.com/blog/ai-risk-regulated-industries.html</id>
    <updated>2026-04-07T00:00:00.000Z</updated>
    <summary>What an AI risk assessment looks like when it has to satisfy a financial-services regulator, a healthcare auditor, or an industrial safety body. The structure that holds up under scrutiny and the sections that turn into evidence.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>RAG vs Fine-Tuning vs Tool Use: When Each Wins, and What It Costs</title>
    <link href="https://www.pelican-tech.com/blog/rag-finetune-toolcall.html"/>
    <id>https://www.pelican-tech.com/blog/rag-finetune-toolcall.html</id>
    <updated>2026-04-04T00:00:00.000Z</updated>
    <summary>The three patterns most GenAI applications now combine, with the trade-offs that matter at scale. Latency, cost, evaluation difficulty, governance burden — the parts of the decision that don&#39;t show up in the demo.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>FDA 510(k) for SaMD: Cybersecurity Documentation That Won&#39;t Get Returned</title>
    <link href="https://www.pelican-tech.com/blog/fda-510k-cyber-docs.html"/>
    <id>https://www.pelican-tech.com/blog/fda-510k-cyber-docs.html</id>
    <updated>2026-04-01T00:00:00.000Z</updated>
    <summary>The FDA&#39;s 2025 cybersecurity guidance for Software as a Medical Device tightened the documentation bar materially. The artefacts that actually get a 510(k) cleared on the first cycle and the ones that trigger Refuse to Accept letters.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>EU AI Act Meets MDR: What Medical SaMD Vendors Should Be Doing Right Now</title>
    <link href="https://www.pelican-tech.com/blog/eu-ai-act-mdr.html"/>
    <id>https://www.pelican-tech.com/blog/eu-ai-act-mdr.html</id>
    <updated>2026-03-29T00:00:00.000Z</updated>
    <summary>The EU AI Act&#39;s high-risk obligations now sit on top of the existing MDR/IVDR framework for medical SaMD. The overlap saves work; the gaps create new compliance debt. The combined posture vendors need by mid-2026.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>IEC 62304 + ISO 14971: A Combined Software Lifecycle Risk Strategy</title>
    <link href="https://www.pelican-tech.com/blog/iec-62304-iso-14971.html"/>
    <id>https://www.pelican-tech.com/blog/iec-62304-iso-14971.html</id>
    <updated>2026-03-26T00:00:00.000Z</updated>
    <summary>The two standards medical software teams are required to follow are usually run as separate processes. Treating them as one integrated lifecycle saves duplicated work and produces evidence that holds up under scrutiny.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>Clinical Validation Pathways for AI/ML SaMD: A Step-by-Step Map</title>
    <link href="https://www.pelican-tech.com/blog/clinical-validation-saas-ml.html"/>
    <id>https://www.pelican-tech.com/blog/clinical-validation-saas-ml.html</id>
    <updated>2026-03-23T00:00:00.000Z</updated>
    <summary>Clinical validation for AI/ML SaMD is where many vendors lose six to twelve months they did not plan for. The pathway choices, the evidence each pathway requires, and the order of operations that gets you to launch fastest.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
  <entry>
    <title>ISO 13485 Beyond the Audit: Building a QMS That Speeds Up Releases</title>
    <link href="https://www.pelican-tech.com/blog/iso-13485-speed.html"/>
    <id>https://www.pelican-tech.com/blog/iso-13485-speed.html</id>
    <updated>2026-03-20T00:00:00.000Z</updated>
    <summary>Most medical-device QMS implementations slow product releases. The ones that don&#39;t share three operational disciplines that the standard does not require but does not preclude. The pattern that turns a QMS from a tax into a multiplier.</summary>
    <author><name>Pelican Tech</name></author>
  </entry>
</feed>
