Skip to main content

Information Security, Risk and Compliance Quarterly Planning

We have three objectives in publishing our quarterly planning:

  1. We want to be transparent about the work we are doing
  2. We want your input on that work and our planning, and we want to document that input and let you know if and when we can add your suggestions to our planning
  3. We want an open dialogue with members and community on developments around Information Security, Risk and Compliance

We launched this initiative in Q2 2022, and we are open to improving what we publish here and how we do that. So let us know if there are ways we can better present our plans. In Q1 2023, we separated the work items of Information Security, Risk and Compliance from the Information Technology and added them to this area.

We will update this page as our activities progress and continue to share updates on RIPE Labs, on the RIPE NCC Membership Discussion and RIPE NCC Services Working Group (WG) mailing lists, and at RIPE Meetings and other events.

Q2 2026 Plans

Last updated: 27 March 2026

Item 1: Ensure Adherence to Regulatory and Security Industry Standards

In Q1 2026 we initiated the annual control testing for the SOC 2 control framework, which will be completed in Q2.

We are continuing with the ongoing initiatives to achieve compliance with the ISO 27001 standard. In Q1 we executed the internal audit to assess readiness against the ISO 27001 standard. In Q2 we will address any potential recommendations from the internal audit and further streamline the implementation of additional improvements.

Status: In progress

Item 2: Elevate Organisational Risk Resilience

In Q2 2026 we will initiate the annual risk assessment activities. We will also continue with the onboarding of our Governance, Risk & Compliance platform.

Status: In progress

Item 3: Secure System Security and Resiliency

In Q1 2026, we rolled out improvements in our vulnerability management reporting, and updated relevant policies and procedures. In Q2 we will continue our focus on rolling out application security capabilities to proactively identify and remediate vulnerabilities across our development lifecycle.

Status: In progress

Item 4: Strengthen Detection and Response

In Q1 2026 we finetuned the coverage of network detection and response capabilities and renewed our threat intelligence capabilities. In Q2 2026, we will continue expanding the coverage of security monitoring tooling and acquisition of managed security services.

Status: In progress

Community Input on Planning

We want the community to contribute to our plans and suggest additional work items. Please share your comments with us or post them on the RIPE NCC Membership Discussion and RIPE NCC Services WG mailing lists. We'll also be monitoring all the other channels where people talk about these services.

When we receive feedback that can significantly impact our planning or that needs a further response, we will add it to the table below.

Archived Quarterly Plans

You can find our plans from the previous quarters on this page. The Q2 2026 plans will be archived once we publish the Q3 2026 planning.