<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GRC &amp; Compliance on Microsoft 365 Security Insights</title><link>https://thecybersec.gr/categories/grc-compliance/</link><description>Recent content in GRC &amp; Compliance on Microsoft 365 Security Insights</description><generator>Hugo</generator><language>el-gr</language><lastBuildDate>Sun, 30 Aug 2026 21:10:00 +0300</lastBuildDate><atom:link href="https://thecybersec.gr/categories/grc-compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>Localized Mark and Notify στο Microsoft Defender for Office 365: Γιατί ένα notification email στη σωστή γλώσσα είναι θέμα Security Awareness (MC1387578)</title><link>https://thecybersec.gr/posts/generally-available/mdo-mark-and-notify-localization/</link><pubDate>Tue, 25 Aug 2026 09:15:00 +0300</pubDate><guid>https://thecybersec.gr/posts/generally-available/mdo-mark-and-notify-localization/</guid><description>Ένα notification email που φτάνει στον χρήστη στα Αγγλικά ενώ αυτός δουλεύει σε Ελληνικό Outlook δεν είναι απλώς αισθητικό ζήτημα. Είναι ένα μικρό, αλλά υπαρκτό, ρήγμα στην αλυσίδα security awareness. Το MC1387578 έρχεται να το κλείσει, και αξίζει να δούμε γιατί δεν είναι απλώς ένα cosmetic feature.</description></item><item><title>Τι κάνουν οι CISOs με το Microsoft Secure Score που δεν βλέπεις στα whitepapers</title><link>https://thecybersec.gr/posts/microsoft-secure-score-grc-programma-ciso/</link><pubDate>Tue, 25 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/microsoft-secure-score-grc-programma-ciso/</guid><description>Ήμουν καλεσμένος στο live του Χρήστου Σπανουγάκη για να μιλήσω για το Gold Award GRC πρόγραμμα πάνω στο Microsoft Secure Score. Αυτό το άρθρο δεν επαναλαμβάνει τη σειρά, κρατάει μόνο ό,τι ειπώθηκε εκεί για πρώτη φορά: το board pitch σε τρία slides, τι θα έκανα διαφορετικά, και ένα bonus live demo στο Power BI.</description></item><item><title>Purview Auto-labeling: Από 100.000 σε 500.000 αρχεία την ημέρα, τι αλλάζει πραγματικά για το labeling backlog σου</title><link>https://thecybersec.gr/posts/purview-autolabeling-500k-scale-increase/</link><pubDate>Fri, 14 Aug 2026 08:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/purview-autolabeling-500k-scale-increase/</guid><description>Ένα νούμερο που έμενε σταθερό τόσο καιρό που το είχαμε ενσωματώσει σαν δεδομένο στον σχεδιασμό μας, αλλάζει. Το πενταπλάσιο όριο auto-labeling δεν είναι απλώς ένα technical bump, είναι ευκαιρία να ξανακοιτάξεις το labeling backlog σου και να το συνδέσεις με το πώς τεκμηριώνεις classification στο ISO 27001 και στο NIS2.</description></item><item><title>Microsoft Entra Tenant Governance: Το «GA» που δεν είναι πλήρως GA, και γιατί αυτό έχει σημασία για το compliance σου</title><link>https://thecybersec.gr/posts/entra-tenant-governance-ga/</link><pubDate>Wed, 12 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/entra-tenant-governance-ga/</guid><description>Η ανακοίνωση λέει «Generally Available», αλλά όποιος διαβάσει προσεκτικά θα δει ότι μόνο ένα κομμάτι είναι πραγματικά GA. Για έναν οργανισμό με δεκάδες tenants, shadow IT και config drift, αυτή η διάκριση δεν είναι ακαδημαϊκή, καθορίζει τι μπορείς να βασίσεις σε production και τι όχι ακόμα.</description></item><item><title>Allowed Agent Types στο Microsoft 365: Γιατί το «Only Certified External Publishers» είναι η μόνη λογική επιλογή</title><link>https://thecybersec.gr/posts/allowed-agent-types-only-certified-external-publishers/</link><pubDate>Fri, 07 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/allowed-agent-types-only-certified-external-publishers/</guid><description>Ένα radio button μέσα στο Copilot Control System είναι η διαφορά ανάμεσα σε ελεγμένο agent ecosystem και σε Shadow AI χωρίς φρένο. Δες γιατί το «Only certified external publishers» είναι η ρύθμιση που θα διάλεγα ξανά, με screenshots από το δικό μου tenant.</description></item><item><title>Αύξηση Τιμών Microsoft 365 2026: Οδηγός Στρατηγικής για Security Leaders ενόψει της 1ης Ιουλίου</title><link>https://thecybersec.gr/posts/microsoft-365-price-increase-2026-security-leader-playbook/</link><pubDate>Thu, 30 Jul 2026 20:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/microsoft-365-price-increase-2026-security-leader-playbook/</guid><description>Η Microsoft λέει ότι είναι &amp;lsquo;αναβάθμιση αξίας&amp;rsquo;. Στην πράξη είναι αύξηση τιμών από 5% έως 43%, με άνιση κατανομή ανά πλάνο και ένα κρυφό στοίχημα σε όσους έχουν Enterprise Agreement. Εδώ είναι τι πραγματικά αλλάζει, τι κερδίζεις δωρεάν στο E3, τι κοστίζει το Security Copilot στην πράξη, και ένα πρακτικό πλάνο για να μην πληρώσεις παραπάνω απ&amp;rsquo; όσο χρειάζεται.</description></item><item><title>Microsoft Secure Score: Πρακτικός Οδηγός για τον ΥΑΣΠΕ NIS2</title><link>https://thecybersec.gr/posts/secure-score-defender-praktikos-odigos/</link><pubDate>Mon, 27 Apr 2026 10:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/secure-score-defender-praktikos-odigos/</guid><description>Πρακτικός οδηγός Microsoft Secure Score για τον Έλληνα junior μηχανικό και Υ.Α.Σ.Π.Ε., από το score στην πραγματική μείωση κινδύνου, στο πλαίσιο NIS2 και του Νόμου 5160/2024.</description></item><item><title>Microsoft Secure Score as a GRC Tool for ISO 27001 &amp; NIS2</title><link>https://thecybersec.gr/posts/secure-score-grc-part-0-intro/</link><pubDate>Wed, 22 Apr 2026 10:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/secure-score-grc-part-0-intro/</guid><description>Series introduction: the mid-market GRC problem, how Microsoft Secure Score covers 60–70% of ISO 27001:2022 Annex A and NIS2 Article 21 controls automatically, the four building blocks of the Gold-Award programme, and the recommended reading path for the full series.</description></item><item><title>Microsoft Secure Score Part 1: How to Read a Recommendation</title><link>https://thecybersec.gr/posts/secure-score-grc-part-1-anatomy/</link><pubDate>Mon, 27 Apr 2026 07:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/secure-score-grc-part-1-anatomy/</guid><description>Part 1 of the Secure Score series. A beginner-friendly walk through a single Microsoft Secure Score recommendation. Every field on the screen, what each one means, and the small observations that help new professionals start extracting value in under an hour.</description></item><item><title>Microsoft Secure Score Part 2: Inside the Defender Ecosystem</title><link>https://thecybersec.gr/posts/secure-score-grc-part-2-ecosystem/</link><pubDate>Mon, 04 May 2026 07:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/secure-score-grc-part-2-ecosystem/</guid><description>Part 2 of the Secure Score series. Where Microsoft Secure Score physically lives, how it feeds off the Microsoft Defender family, what each source product contributes, and a practical exercise to trace one score point back to the product that generated it.</description></item><item><title>Microsoft Secure Score Part 3: Daily Operations &amp; ISO 27001</title><link>https://thecybersec.gr/posts/secure-score-grc-part-3-operations/</link><pubDate>Fri, 22 May 2026 07:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/secure-score-grc-part-3-operations/</guid><description>Part 3 of the Secure Score series. How to actually run Microsoft Secure Score day-to-day: prioritizing 260+ recommendations, building a change management process that doesn&amp;rsquo;t break production, mapping controls to ISO 27001 and NIS2, collecting audit evidence, and reporting to the board.</description></item><item><title>Microsoft Defender Part 4: The Licensing Decoder</title><link>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-4-licensing-decoder/</link><pubDate>Sat, 25 Jul 2026 20:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-4-licensing-decoder/</guid><description>Part 4 of the Microsoft Defender Demystified series. A licensing decoder across the 2026 Microsoft 365 lineup, including the new Defender Suite add-ons, the July 2026 pricing update, and three real-world scenarios (small business, mid-market, enterprise) for sizing the right purchase.</description></item></channel></rss>