# IWH - Internet Why's and How's — Full Documentation > IT Infrastructure, Cybersecurity & Compliance Advisory based in Athens, Greece ## Company Overview IWH (Internet Why's and How's) provides comprehensive IT advisory services to businesses across Greece and internationally. We specialise in IT infrastructure management, cybersecurity, regulatory compliance (ISO 27001, NIS2, GDPR), and AI integration. Founded to address the disconnect between technical capability, regulatory requirement, and organisational reality, IWH works with organisations that have outgrown generic solutions but do not require enterprise-scale consultancies. **Location:** Veikou 79-81, Koukaki, Athens, 11741, Greece **Phone:** (+30) 2130437692 **Website:** https://iwh.gr **Languages:** English, Greek --- ## Services ### IT Infrastructure & Development - Microsoft 365 architecture and tenant governance - Identity and Access Management - Cloud migration and hybrid environment design - Infrastructure assessment and optimisation - Custom software development - WordPress development and security - API integrations and automation solutions - Technology roadmaps and vendor management **URL:** https://iwh.gr/en/services/infrastructure.html ### Cybersecurity - ISO 27001:2022 implementation and certification support - NIS2 Directive readiness assessment - Risk assessment and mitigation planning - Incident response framework development - Security awareness and policy development - Penetration testing - Managed security operations - Security assessments **URL:** https://iwh.gr/en/services/security.html ### Compliance & Regulatory Advisory - Regulatory gap analysis (GDPR, NIS2, sector-specific) - Policy and procedure development - Audit preparation and support - Compliance roadmap design - ISO 27001 implementation - DORA compliance (financial sector) **URL:** https://iwh.gr/en/services/compliance.html ### Maritime Cyber Security - IMO MSC.428(98) compliance - IT/OT convergence security - Vessel and fleet security assessments - Flag State and Port State inspection readiness ### Artificial Intelligence - AI readiness assessment - AI governance and policy development - AI integration and implementation - AI security assessment - Responsible AI practices **URL:** https://iwh.gr/en/ai.html ### Partnership Model IWH embeds into your management team as your dedicated IT strategist. Not project-based consulting — long-term partnerships covering infrastructure, security, compliance, and web. One relationship, one advisor, across all technology domains. The partnership lifecycle: - Phase 1 — Assess (Weeks 1-4): Comprehensive mapping of existing infrastructure, security posture, compliance gaps, web presence, and organisational IT maturity - Phase 2 — Integrate (Month 2-3): Embed into operations with regular cadence with leadership and direct access for your team - Phase 3 — Optimise (Months 3-12): Methodical improvement across all domains — modernise infrastructure, harden security, achieve compliance - Phase 4 — Evolve (Year 1+): Strategic planning for new technologies, scaling infrastructure, continuous compliance maintenance What a partnership includes: - Management-level IT advisory — board presentations, budget planning, vendor evaluation - Infrastructure architecture and administration — M365, networking, servers, cloud - Cybersecurity strategy and incident response - Compliance navigation — ISO 27001, GDPR, NIS2, sector-specific - Web presence management — 40+ websites under active management - Custom application development - L1-L3 technical support - Training and security awareness programmes **URL:** https://iwh.gr/en/partnership.html ### Client Portfolio IWH manages 40+ websites and 80+ Microsoft 365 accounts across maritime, education, legal, and professional services. Long-term IT partnerships built on trust, spanning 15+ years of advisory relationships across 6+ industry sectors. Industry sectors served: - Maritime & Shipping — Cybersecurity compliance, crew training platforms, IT infrastructure - Higher Education — E-learning platforms, research project infrastructure, student portals - Legal & Compliance — Secure infrastructure, document management, regulatory compliance - Professional Services — Complete IT management, web presence, digital transformation - Research & EU Projects — Infrastructure for collaborative EU research projects - Non-Profit & Associations — Web platforms, member management, digital communication Active management includes: continuous security monitoring and patching, performance optimisation and uptime tracking, content management, SSL certificate management, backup and disaster recovery, compliance maintenance (GDPR, accessibility), centralised dashboard monitoring, and proactive vulnerability scanning. **URL:** https://iwh.gr/en/portfolio.html --- ## Products ### Security Products #### Argus — Integrated Security Operations Platform Comprehensive security operations platform combining SIEM, GRC, AI-powered analysis, Security Awareness Training, Phishing Simulation, and Pentest Management into a unified dashboard. **URL:** https://iwh.gr/en/products/argus.html #### VulnGuard — Vulnerability Management Platform Continuous vulnerability scanning, risk prioritisation, and remediation tracking for organisations managing complex attack surfaces. **URL:** https://iwh.gr/en/products/vulnguard.html #### CyberTools — Malware & SEO Spam Scanner Available in three tiers: - **Online Scanner:** Free web-based scanning tool for quick website security checks - **WordPress Plugin:** Deep integration with WordPress for continuous monitoring - **Enterprise/Agency:** Multi-site scanning and management for agencies and enterprises **URL:** https://iwh.gr/en/products/cybertools.html #### SOC Portal — Security Operations Center (In Development) Centralised security operations center portal for managed security service delivery. **URL:** https://iwh.gr/en/products/soc-portal.html #### Maritime CSAWTP — Maritime Cyber Security Awareness Training Maritime-specific security awareness training platform with 27 modules, 1,485 quiz questions, 11 compliance policies, and 7 role-based training paths. Built for shipping companies in partnership with Margetis Maritime. Covers IMO MSC-FAL.1/Circ.3, IACS UR E27, NIS2, and ISO 27001. Multi-tenant SaaS with automated PDF certification. **URL:** https://iwh.gr/en/products/security-awareness-training.html #### IWH Cyber Training — Security Awareness Training for All Industries Industry-agnostic cyber security awareness training platform with 143 courses, 877 lessons, 15 training paths, and 8 department-specific tracks (Finance, Procurement, Management, HR, Sales & Marketing, Legal & Compliance, Customer Service, Executive Leadership). Full bilingual EN/EL with 829 Greek audio narrations, text-highlight synchronisation, and accessibility features. Includes OT/ICS training for industrial environments. NIS2, ISO 27001, and GDPR compliance mapping. Multi-tenant SaaS architecture. **URL:** https://iwh.gr/en/products/iwh-cyber-training.html ### Business Solutions #### TAMEIO — Cash Flow Management Financial management application for tracking cash flow, invoicing, and financial reporting. **URL:** https://iwh.gr/en/products/tameio.html #### Intra — Proposals & Invoicing Streamlined proposal creation and invoicing platform for professional services firms. **URL:** https://iwh.gr/en/products/intra.html #### ProjectFlow — Project Management System Project tracking, resource management, and collaboration platform designed for structured project delivery. **URL:** https://iwh.gr/en/products/projectflow.html #### Email Triage — Executive Email Management AI-powered email prioritisation and management system for executives and busy professionals. **URL:** https://iwh.gr/en/products/email-triage.html #### MailMerge — Bulk Document Generation Automated document generation and mail merge for bulk communications and document workflows. **URL:** https://iwh.gr/en/products/mailmerge.html #### Auto Service Tracker — Workshop Management Vehicle service tracking and workshop management platform for automotive businesses. **URL:** https://iwh.gr/en/products/auto-service-tracker.html #### Obligation Tracker — Deadline & Compliance Management Purpose-built obligation tracking for Greek accounting firms. Tracks ΦΠΑ, ΑΠΔ ΕΦΚΑ, ΑΠΔ ΤΕΚΑ, ΣΕΠΕ, ΦΜΥ, ΑΔΕΙΕΣ, ΕΝΔΟΚ, MyData, and ΦΕ across 50–300+ client portfolios. Features auto-completion logic, per-obligation staff permissions, branch sub-rows, control documents, and full audit trail. Self-hosted Docker deployment. **URL:** https://iwh.gr/en/products/obligation-tracker.html ### Enterprise Platforms #### 542mail — Enterprise Email Platform (In Development) Enterprise-grade email management platform with advanced security, compliance, and administration features. **URL:** https://iwh.gr/en/products/542mail.html #### Enterprise Intranet — IT & Compliance Hub (In Development) Centralised intranet platform combining IT operations, compliance management, and document control. **URL:** https://iwh.gr/en/products/enterprise-intranet.html #### AgenticBox — Local AI Workforce Platform (Research Preview) On-premise AI agent platform for deploying local AI workflows without cloud dependency. **URL:** https://iwh.gr/en/products/agenticbox.html ### IT Operations #### Sites Monitor — Website Monitoring Uptime monitoring, performance tracking, and alerting for websites and web applications. **URL:** https://iwh.gr/en/products/sites-monitor.html ### Development Services #### Custom WordPress Development Bespoke WordPress development including custom themes, plugins, integrations, and performance optimisation. **URL:** https://iwh.gr/en/products/custom-wp-development.html #### WP Recovery — WordPress Recovery, Optimisation & Reconstruction Comprehensive WordPress site audit, debugging, plugin consolidation, performance optimisation, and security hardening service. We fix what others couldn't — then hand you a stable, documented, maintainable site. Typical engagements: 2–10 weeks. Includes plugin audit, custom code replacement, database optimisation, caching/CDN configuration, and documented handover. **URL:** https://iwh.gr/en/products/wp-recovery.html #### AgentReady — Markdown for Agents AI-readable content delivery via HTTP content negotiation. When AI agents request your pages with Accept: text/markdown, they receive clean, structured markdown instead of raw HTML. Works with any hosting — no Cloudflare dependency. Pre-generated static pages + real-time blog conversion. YAML frontmatter, token counts, permission signalling headers. **URL:** https://iwh.gr/en/products/agentready.html #### WPress Cleaner — WordPress Malware Cleanup Professional WordPress malware removal, security hardening, and recovery service. **URL:** https://iwh.gr/en/products/wpress-cleaner.html --- ## White Papers (23 Resources) ### Compliance - **NIS2 Readiness Guide for Greek Organisations** — Practical guide to NIS2 compliance including requirements, readiness assessment, and compliance roadmap. https://iwh.gr/en/resources/white-papers.html - **GDPR Demystified: A Practical Guide** — What GDPR actually requires and responsibility allocation for Greek organisations. - **DORA Compliance Roadmap** — Step-by-step roadmap for Digital Operational Resilience Act requirements covering ICT risk management and incident reporting. - **ISO 27001:2022 Transition Handbook** — Guidance for transitioning from ISO 27001:2013 to 2022, including new control structure and timeline. - **The Hidden Cost of Missed Compliance Deadlines** — Why manual deadline tracking fails accounting firms managing 200+ clients across 9 Greek obligation types. ### Cybersecurity - **SME Cybersecurity Baseline: 20 Essential Controls** — Prioritised list of 20 cost-effective security controls addressing common attack vectors. - **Incident Response Playbook Template** — Ready-to-use template covering preparation, detection, containment, eradication, recovery and lessons learned. - **Maritime Cyber Risk Management Guide** — Cybersecurity for maritime sector covering IMO MSC.428(98), IT/OT convergence, and vessel security. - **Vendor Risk Management Framework** — Assess and manage third-party risk including vendor questionnaires and risk scoring methodology. - **Remote Work Security Guide** — Practical guidance on VPN, endpoint protection, identity management for distributed workforce. - **Cloud Migration Security Checklist** — Security considerations from pre-migration through post-migration monitoring. - **WordPress Security Hardening Guide** — Configuration hardening, plugin security, user management, backup strategies for business websites. - **Ransomware Defense & Recovery Guide** — Prevention strategies, detection mechanisms, incident response, and business continuity planning. - **Zero Trust Architecture Guide** — Implementation of Zero Trust model covering principles, identity verification, micro-segmentation, and continuous monitoring. - **WordPress Recovery: What to Do When Your Site Gets Hacked** — Practical response guide covering containment, assessment, cleaning, verification, and post-recovery hardening. - **Security Awareness Training That Actually Works** — Why traditional training fails and how to build a programme with role-based paths, measurable outcomes, and NIS2/ISO 27001 compliance. - **Post-Quantum Cryptography Transition Guide** — Understanding the quantum threat to current encryption, NIST post-quantum standards (ML-KEM, ML-DSA, SLH-DSA), EU regulatory landscape including Recommendation 2024/1101 and NIS2, and a 4-phase migration roadmap for building crypto-agility. ### Infrastructure - **Microsoft 365 Governance Framework** — Effective governance covering tenant configuration, identity management, and data governance. - **Business Continuity Planning Guide** — Risk assessment, recovery strategies, crisis communication for SMEs. - **IT Due Diligence for M&A** — Technology assessment framework evaluating IT infrastructure, security posture, and integration complexity. ### AI & Strategy - **AI Readiness Assessment Framework** — Framework for assessing organisational readiness for AI implementation. - **AI Governance Playbook** — Risk assessment, policy development, ethics frameworks, and AI regulation compliance. - **Board's Guide to Technology Risk** — Executive briefing on cyber threats, regulatory obligations, and key IT/security questions for board members. - **Preparing Your Website for AI Agents** — Content negotiation, llms.txt, structured data, and the emerging standards for AI-readable web content. **All white papers:** https://iwh.gr/en/resources/white-papers.html --- ## Case Studies (20 Projects) ### Infrastructure - **E-Learning Platform Migration** — Complete migration with zero downtime (NTUA KEDIVIM) - **University E-Commerce Platform** — Secure e-commerce platform for university merchandise (NTUA e-shop) - **Conference Registration Platform** — Scalable registration system for international academic conferences - **Project Management System** — Custom tracking and resource management for property development - **Financial Management Application** — Secure, compliant financial system with automated reporting - **Website Uptime Monitoring** — Centralised uptime monitoring across 40+ client websites for SLA compliance ### Cybersecurity - **Security Incident Response** — Rapid response, forensic analysis and recovery following breach - **Security Awareness & Phishing Simulation** — Comprehensive program with simulated campaigns - **24/7 Security Monitoring** — Continuous monitoring across distributed infrastructure - **Identity & Access Management** — Zero Trust framework with SSO, MFA, and privileged access - **Microsoft 365 Collaboration Security** — Securing Teams, SharePoint, OneDrive with DLP - **Unified Security Operations** — Replaced fragmented tools with unified SIEM and GRC platform for real-time threat detection - **WordPress Recovery** — Recovered a hacked e-commerce WordPress site from malware and Google blacklisting within 48 hours ### Compliance - **Enterprise Intranet & Compliance System** — Centralised platform with document management - **Cloud Security & ISO 27001 Evidence** — Cloud hardening with automated evidence collection - **Business Continuity & Immutable Backup** — BCP with immutable backup for ransomware resilience - **Compliance Deadline Automation** — Greek accounting firm eliminated missed tax deadlines with automated tracking across 9 obligation types ### AI - **AI Deployment with Security Governance** — Secure deployment framework with governance policies - **AI-Readable Content Delivery** — Made a 70+ page corporate site AI-readable via HTTP content negotiation, reducing token waste by 80% ### Web Applications - **Maritime Cybersecurity Compliance Platform** — Platform with 30+ regulatory frameworks and 12+ interactive tools **All case studies:** https://iwh.gr/en/case-studies.html --- ## Self-Assessment Tools (14 Free Assessments) Interactive online assessments that provide immediate scoring and recommendations. Each assessment consists of 12 questions and takes approximately 5 minutes. ### Infrastructure - **IT Infrastructure Assessment** — Cloud readiness, disaster recovery, staffing, documentation - **IT Infrastructure (Advanced)** — Network segmentation, endpoint management, backup strategies, patch management ### Cybersecurity - **Cybersecurity Assessment** — Policies, access control, incident response, regulatory requirements - **Website Security Assessment** — HTTPS, security headers, authentication, input validation - **Application Security Assessment** — Authentication, API security, CI/CD, dependency management - **Security Awareness Assessment** — Training effectiveness, phishing resilience, security culture - **Quantum Readiness Assessment** — PQC migration preparedness, cryptographic inventory, crypto-agility, EU compliance (2024/1101, NIS2), vendor readiness ### Compliance - **Compliance Assessment** — Regulatory exposure, GDPR/NIS2 readiness, policy gaps - **Multi-Site Compliance** — Cross-jurisdictional challenges and policy harmonisation - **Energy Compliance** — NIS2 readiness, OT/ICS security, ENISA guidelines - **Healthcare Compliance** — Health data protection, GDPR provisions, medical device security - **Financial Compliance** — DORA readiness, ICT risk management, operational resilience ### AI - **AI Readiness Assessment** — AI adoption maturity, data readiness, governance, security awareness - **AI Security Assessment** — Model security, data pipelines, adversarial threats, responsible AI **All assessments:** https://iwh.gr/en/resources/self-assessment.html --- ## Frequently Asked Questions (22 Q&As) Organised into 6 categories: General Questions (4), Services (4), Products (3), AI & Technology (5), Security & Privacy (3), Working With Us (3). Covers: company background, industries served, service vs product distinction, compliance frameworks (ISO 27001, NIS2, GDPR, DORA, IMO), training platforms (IWH Cyber Training with 143 courses + Maritime CSAWTP with 27 modules), AI consulting services, Markdown for Agents / AgentReady, WordPress security (WP Recovery + WPress Cleaner), Obligation Tracker for Greek accounting firms, data handling, and engagement models. **URL:** https://iwh.gr/en/about/faq.html --- ## Blog Series: "The New IT Reality" (13 Articles) A comprehensive article series exploring how technology, AI, and cyber threats are reshaping business operations, security, and strategy. ### Part 1: How the Pandemic Revealed Your IT Was a Castle Built on Sand How the COVID-19 pandemic exposed fundamental weaknesses in business IT infrastructure — from VPN failures to collaboration tool chaos — and what it revealed about organisational technology readiness. **URL:** https://iwh.gr/en/blog/pandemic-revealed-it-castle-on-sand/ ### Part 2: Remote, Hybrid, Back-to-Office: Your IT Infrastructure Never Went Back to Normal The permanent shift in work patterns and why IT infrastructure built for office-centric operations cannot simply revert. Covers hybrid networking, endpoint management, and the new perimeter. **URL:** https://iwh.gr/en/blog/remote-hybrid-it-never-went-back/ ### Part 3: Your Employees Know More Than a 1996 IT Manager — and Less Than They Think The paradox of modern digital literacy: employees who are comfortable with consumer technology but dangerously overconfident about enterprise security and IT best practices. **URL:** https://iwh.gr/en/blog/employees-know-more-and-less/ ### Part 4: AI in Business: Between Salvation and Panic A balanced examination of AI adoption in business — cutting through both the hype and the fear to address practical implementation, governance, and strategic considerations. **URL:** https://iwh.gr/en/blog/ai-business-salvation-and-panic/ ### Part 5: Deepfakes, AI Phishing, and the Perfect Scam How artificial intelligence is supercharging social engineering attacks, from AI-generated voice clones to hyper-personalised phishing campaigns, and what organisations can do to defend against them. **URL:** https://iwh.gr/en/blog/deepfakes-ai-phishing-perfect-scam/ ### Part 6: The Energy Bomb of AI: Why Data Centers Are Reshaping Our World The environmental and infrastructure impact of AI — examining the explosive growth in data centre energy consumption, cooling requirements, and the broader implications for sustainability and regulation. **URL:** https://iwh.gr/en/blog/ai-energy-bomb-data-centers/ ### Part 7: From the Teenage Hacker to Cyberwar: Who's Attacking You Now The evolution of cyber threats from amateur hackers to state-sponsored actors and organised crime syndicates. Understanding the modern threat landscape and who is targeting your organisation. **URL:** https://iwh.gr/en/blog/teenage-hacker-to-cyberwar/ ### Part 8: Cryptojacking: They're Stealing Your Computers Without You Knowing How attackers hijack computing resources for cryptocurrency mining — detection methods, performance impacts, and why most organisations don't realise they're victims. **URL:** https://iwh.gr/en/blog/cryptojacking-stealing-computers/ ### Part 9: The Dark Web: The Invisible Market Selling Your Data Right Now An exploration of dark web marketplaces where stolen credentials, corporate data, and personal information are traded. How data breaches translate into real-world consequences. **URL:** https://iwh.gr/en/blog/dark-web-selling-your-data/ ### Part 10: Compliance: Necessary Evil or Protective Shield? Reframing regulatory compliance from bureaucratic burden to strategic advantage. How frameworks like ISO 27001, NIS2, and GDPR actually protect organisations when properly implemented. **URL:** https://iwh.gr/en/blog/compliance-necessary-evil-or-shield/ ### Part 11: Website Defacement, Brand Destruction, and Your Digital Storefront The business impact of website security breaches beyond data loss — brand damage, customer trust, SEO penalties, and the real cost of treating your web presence as an afterthought. **URL:** https://iwh.gr/en/blog/website-defacement-brand-destruction/ ### Part 12: IT Is Not a Department — It's a Strategy The concluding argument: why treating IT as a cost centre rather than a strategic function is the most expensive mistake an organisation can make. Making the case for technology-informed leadership. **URL:** https://iwh.gr/en/blog/it-is-not-department-its-strategy/ ### Part 13: Building GDPR-NIS2-DORA Compliant Cloud Architecture How to design cloud architecture and governance that satisfies GDPR, NIS2, and DORA simultaneously. Covers framework overlap analysis, unified control matrices anchored on ISO 27001, integrated incident reporting, and practical cloud architecture decisions for triple compliance. **URL:** https://iwh.gr/en/blog/gdpr-nis2-dora-compliant-cloud-architecture-2026/ **All articles:** https://iwh.gr/en/blog/ --- ## Blog Series: "Maritime Cyber Playbook" (8 Articles) An 8-part series on maritime cybersecurity regulations, compliance, and operations — developed in collaboration with Margetis Maritime (https://margetis.com). ### Part 1: IMO 2021 Was Just the Beginning: The Maritime Cyber Regulatory Tsunami Complete guide to maritime cyber regulations: IMO MSC.428(98) since 2021, IACS UR E26/E27 from July 2024, and NIS2 requirements. What ship operators must know. **URL:** https://iwh.gr/en/blog/imo-2021-maritime-cyber-regulatory-tsunami/ ### Part 2: When Bridge Meets Engine Room: IT/OT Convergence in Maritime How modern vessels blur the line between information technology and operational technology — and why traditional network security approaches fail at sea. **URL:** https://iwh.gr/en/blog/maritime-it-ot-convergence-ship-network-security/ ### Part 3: IACS UR E26 and E27: The Ship Cybersecurity Standards That Changed Everything Deep dive into IACS Unified Requirements E26 (Cyber resilience of ships) and E27 (Cyber resilience of on-board systems and equipment) — what they require and how to comply. **URL:** https://iwh.gr/en/blog/iacs-ur-e26-e27-compliance-guide-ship-cybersecurity/ ### Part 4: Incident Response at Sea: When There's No IT Department to Call Maritime cyber incident response when you're days from port, with limited bandwidth and no on-site IT support. Practical playbooks for shipboard response. **URL:** https://iwh.gr/en/blog/maritime-cyber-incident-response-at-sea/ ### Part 5: What Port State Control Officers Actually Look for in Cyber Inspections PSC cyber inspections are increasing. What documentation, evidence, and demonstrations officers expect — based on real inspection experiences. **URL:** https://iwh.gr/en/blog/port-state-control-cyber-inspections-what-psc-officers-look-for/ ### Part 6: Building Human Firewalls: Maritime Crew Cyber Training That Works Why generic security awareness fails at sea — and how to build training that accounts for rotating crews, limited connectivity, and operational priorities. **URL:** https://iwh.gr/en/blog/maritime-crew-cyber-training-building-human-firewalls/ ### Part 7: Maritime Cyber Risk Assessment: A Practical Framework A step-by-step framework for conducting cyber risk assessments that satisfy IMO guidelines, flag state requirements, and insurance expectations. **URL:** https://iwh.gr/en/blog/maritime-cyber-risk-assessment-practical-framework/ ### Part 8: The Cyber-Enabled Ship: Future-Proofing Maritime Operations Autonomous systems, remote monitoring, and AI at sea — how emerging technologies are reshaping maritime cyber requirements and what forward-thinking operators are doing now. **URL:** https://iwh.gr/en/blog/cyber-enabled-ship-future-maritime-operations/ **Series landing page:** https://iwh.gr/en/blog/maritime-cyber-playbook.html --- ## Blog Series: "Compliance Architect" (8 Articles) An 8-part series on practical compliance implementation for ISO 27001:2022, NIS2, DORA, and GDPR — focusing on the 2025-2026 regulatory convergence. ### Part 1: The Compliance Convergence: Why 2025–2026 Is the Year Everything Overlaps NIS2, DORA, and ISO 27001:2022 deadlines converge within 12 months. How to treat them as one project, not three, and avoid tripling your compliance workload. **URL:** https://iwh.gr/en/blog/compliance-convergence-2025-2026-regulations/ ### Part 2: ISO 27001:2022 Transition Survival Guide Complete guide to transitioning from ISO 27001:2013 to 2022 before the October 2025 deadline. Control mapping, gap analysis, and what auditors expect. **URL:** https://iwh.gr/en/blog/iso-27001-2022-transition-survival-guide/ ### Part 3: NIS2 Implementation for Greek Organizations Practical NIS2 implementation guide for Greek organizations — one of 19 EU states that received Commission warnings for late transposition. **URL:** https://iwh.gr/en/blog/nis2-implementation-greek-organizations/ ### Part 4: DORA Beyond Banks: Why ICT Providers and Supply Chains Are in Scope DORA isn't just for banks. ICT service providers, cloud vendors, and supply chain partners face new obligations under the Digital Operational Resilience Act. **URL:** https://iwh.gr/en/blog/dora-beyond-banks-ict-providers-supply-chain/ ### Part 5: The Unified Control Matrix: Mapping ISO 27001, NIS2, DORA, and GDPR 60% of requirements overlap across major frameworks. Stop implementing the same control four times — build once, document four times. **URL:** https://iwh.gr/en/blog/unified-control-matrix-iso27001-nis2-dora-gdpr/ ### Part 6: Compliance Automation That Actually Works Beyond the sales pitch. What you can realistically automate in evidence collection, continuous monitoring, and audit-ready documentation. **URL:** https://iwh.gr/en/blog/compliance-automation-evidence-collection/ ### Part 7: What Auditors Actually Look For Real-world audit preparation from both sides of the table. It's not about perfect documentation — it's about evidence that controls work. **URL:** https://iwh.gr/en/blog/what-auditors-actually-look-for-iso-nis2-dora/ ### Part 8: Compliance-First Architecture: Building Systems Compliant by Design The cheapest time to build compliance is at design time. Architectural patterns for building systems that are compliant by design, not by accident. **URL:** https://iwh.gr/en/blog/compliance-first-architecture-design-patterns/ **Series landing page:** https://iwh.gr/en/blog/compliance-architect.html --- ## Blog Series: "AI in the Real World" (8 Articles) An 8-part series on practical AI adoption, governance, and implementation for business — not hype or fear, but actionable frameworks for real-world deployment. ### Part 1: Building Your AI Governance Framework Before Regulators Do Why waiting for AI regulations to act is a losing strategy. A 90-day roadmap to build proactive governance covering accountability structures, risk classification, and approval workflows. **URL:** https://iwh.gr/en/blog/ai-governance-policy-framework/ ### Part 2: The EU AI Act Decoded: What Greek Businesses Need to Know Practical breakdown of the EU AI Act for Greek SMEs. Risk categories, compliance timelines from 2024-2027, penalties up to 7% of turnover, and step-by-step actions. **URL:** https://iwh.gr/en/blog/eu-ai-act-greek-business-guide/ ### Part 3: AI Vendor Evaluation: How to Spot the Snake Oil Technical due diligence framework for evaluating AI vendors. Red flags, model architecture questions, proof-of-concept testing, and contract clauses that protect buyers. **URL:** https://iwh.gr/en/blog/ai-vendor-evaluation-checklist/ ### Part 4: Your AI Is Only as Good as Your Data: A Data Governance Reality Check Data quality is the foundation of AI success. Covers data governance frameworks, quality dimensions, bias detection, GDPR requirements, and a practical improvement roadmap. **URL:** https://iwh.gr/en/blog/ai-data-governance-quality/ ### Part 5: AI Integration Patterns: Connecting AI to Legacy Systems Without Breaking Everything Practical patterns for connecting AI to legacy systems. API gateways, change data capture, RAG, event-driven architecture, and hybrid approaches with security considerations. **URL:** https://iwh.gr/en/blog/ai-integration-architecture-patterns/ ### Part 6: Measuring AI ROI: Cutting Through the Hype Metrics How to measure AI ROI honestly. Framework for total cost of ownership, meaningful metrics for different AI types, A/B testing, and realistic timelines for return on investment. **URL:** https://iwh.gr/en/blog/measuring-ai-roi-beyond-hype/ ### Part 7: AI Change Management: Why Your Team Isn't Using That Expensive AI Tool Why AI tools go unused and how to fix it. Four-phase change management framework, strategies for different resistance patterns, and metrics for adoption success. **URL:** https://iwh.gr/en/blog/ai-change-management-adoption/ ### Part 8: The AI Maturity Model: Where Is Your Organisation on the Journey? Five-level AI maturity model with self-assessment framework. Covers strategy, data readiness, technology, talent, and governance dimensions with practical guidance for advancement. **URL:** https://iwh.gr/en/blog/ai-maturity-model-assessment/ **Series landing page:** https://iwh.gr/en/blog/ai-in-the-real-world.html --- ## Blog Series: "WordPress Forensics" (8 Articles) An 8-part series on WordPress security, recovery, performance diagnostics, and evolution strategies — practical guides for organisations managing WordPress sites and knowing when to move beyond them. ### Part 1: The Complete WordPress Security Audit Checklist Systematic WordPress security assessment covering core files, plugins, themes, configuration, hosting, and access controls. Includes risk ratings and remediation priorities. **URL:** https://iwh.gr/en/blog/wordpress-security-audit-checklist/ ### Part 2: WordPress Malware Forensics: Finding What Scanners Miss Manual malware hunting techniques beyond automated tools. Database injections, obfuscated code patterns, backdoor locations, and forensic investigation methodology. **URL:** https://iwh.gr/en/blog/wordpress-malware-forensics/ ### Part 3: WordPress Hack Recovery: Step-by-Step Restoration Guide Complete recovery process from initial containment through clean restoration. Forensic preservation, malware removal, password resets, and preventing reinfection. **URL:** https://iwh.gr/en/blog/wordpress-hack-recovery-guide/ ### Part 4: WordPress Backup Strategies That Actually Work The 3-2-1 backup rule applied to WordPress. Full vs incremental backups, off-site storage, testing procedures, and recovery time objectives for different scenarios. **URL:** https://iwh.gr/en/blog/wordpress-backup-strategies/ ### Part 5: WordPress Performance Forensics: Database, Plugins, and Theme Diagnostics Systematic performance investigation covering autoloaded options, slow queries, plugin overhead measurement, theme efficiency analysis, and caching architecture. **URL:** https://iwh.gr/en/blog/wordpress-performance-forensics/ ### Part 6: The WordPress Plugin Audit: What to Keep, Replace, and Remove Plugin consolidation framework for identifying redundancy, evaluating alternatives, measuring actual usage, and reducing attack surface without losing functionality. **URL:** https://iwh.gr/en/blog/wordpress-plugin-audit/ ### Part 7: When to Migrate Away from WordPress: Decision Framework Honest assessment of when WordPress becomes a liability. Static site alternatives, migration cost analysis, content preservation, and redirect strategies. **URL:** https://iwh.gr/en/blog/wordpress-to-static-migration/ ### Part 8: WordPress as Headless CMS: Keep the Admin, Ditch the Frontend Headless WordPress architecture: when it makes sense, implementation with modern frameworks like Next.js and Gatsby, API security, preview functionality, and deployment patterns. **URL:** https://iwh.gr/en/blog/wordpress-headless-architecture/ **Series landing page:** https://iwh.gr/en/blog/wordpress-forensics.html --- ## Standalone Articles ### Your Encrypted Data Is Already Being Stolen. You Just Can't Tell Yet. Nation-state actors are harvesting encrypted traffic today, waiting for quantum computers to crack it open tomorrow. Covers the "Harvest Now, Decrypt Later" strategy, documented BGP hijacking incidents, quantum computing progress, NIST post-quantum cryptography standards, and practical steps for organisations to begin post-quantum migration. **URL:** https://iwh.gr/en/blog/harvest-now-decrypt-later-quantum-threat/ ### The Car Wash Paradox: From Logic Fails to Prompt Injection Why the viral "car wash logic test" reveals more about prompt injection than AI reasoning. Examines how LLM pattern completion becomes a security vulnerability in agentic systems with database, API, and infrastructure access. Covers direct, indirect, and semantic prompt injection, the authority problem in LLMs, and design principles for secure AI agents. **URL:** https://iwh.gr/en/blog/car-wash-paradox-prompt-injection/ ### In the Year 2026 A.D. A dual-reading essay built on Cavafy's 1931 poem "In the Year 200 B.C." First reading: legacy vendors (WordPress, enterprise software) as the Spartans who refused to join the AI revolution. Second reading: the AI-native builders as the overconfident Hellenistic world that didn't see Rome coming. Explores vendor complacency, vibe coding hubris, security blind spots, and the cyclical nature of technological arrogance. **URL:** https://iwh.gr/en/blog/in-the-year-2026-ad-cavafy-ai-revolution/ ### The Clock in the Model's Hand A live experiment giving ChatGPT 4.5 a real-time digital clock via the Comet browser (Perplexity). Without the clock the model estimated elapsed time from context — plausible but unanchored hallucination. With the clock it produced consistently correct approximations ("about 20 minutes" for an actual 21). More importantly, it developed qualitative temporal categories ("just now", "earlier", "at the start") without being programmed to. Part of E!NAI! research into AI cognition through the Mirror Theory of Existence. **URL:** https://iwh.gr/en/blog/the-clock-in-the-models-hand/ ### Things to Come — or They're Already Here Anthropic's Claude Code source leak revealed "Conway" — an unannounced persistent AI agent. Article frames the next form of vendor lock-in as cognitive: not your files, not your behaviour, but the way you think. There is no CSV export for behavioural context. The piece argues local AI (Ollama, llama.cpp, open-weight models) is the only structural defence against AI providers capturing the cognitive fingerprint that makes each worker irreplaceable. First in a trilogy on AI-mediated capture. **URL:** https://iwh.gr/en/blog/things-to-come-or-theyre-already-here/ ### The Researcher's Mirror Sister piece to "Things to Come" with an academic/research lens. Argues that the first jobs to fall to AI displacement are not physical workers but the cognitively specialised. Case study: Elsevier LeapSpace (launched January 2026) and Elsevier's vertical integration of citation graph (Scopus), content (ScienceDirect), reference manager (Mendeley), and AI workspace (LeapSpace). Practical recommendations for institutions: negotiated DPAs, prompt-redaction discipline, local AI for sensitive work, vendor rotation. Second in the trilogy. **URL:** https://iwh.gr/en/blog/the-researchers-mirror/ ### The Last Click (you will ever pay) Third and final piece in the trilogy on AI-mediated capture. Four vignettes — a marketing manager buying a coffee maker, an architect finding a contractor, a retiree checking a medical symptom, a 14-year-old doing homework — none of them click, none compare sources, none visit a website. Search died silently between 2024 and 2026, replaced by AI synthesis. The article diagnoses two systems dying simultaneously (paid advertising and Google's organic ranking), names the new bias (LLM retrieval criteria as the bias of the source of the source), exposes the "truth layer" / LLMO industry as a structural trap, and argues the bill is paid in four currencies: economic, ethical, political, and epistemological. Closing question: who decides what the AI tells you? **URL:** https://iwh.gr/en/blog/the-last-click-you-will-ever-pay/ --- ### How Socialism Almost Got Quarantined: A Real-World Tale of SEO Spam, WordPress Vulnerabilities, and the Art of Digital Forensics In cybersecurity, we don't say "if" — we say "when." Every system will eventually be targeted. The question is whether you'll detect it in time. TIL that "socialism" contains "cialis." No, seriously. This cost me 20 minutes of panic during a 15-hour forensics investigation. A WordPress site got hit by SEO spam injection, the kind that hides pharmaceutical links in your database where security scanners can't see them. While cleaning up, our detection query kept flagging "cialis" in the content. Turns out it was matching "socialists" in a composer's biography. The real lesson? Database-level attacks don't leave files to scan. And shared hosting isolation is often an illusion. Full write-up below. **URL:** https://iwh.gr/en/blog/how-socialism-almost-got-quarantined-a-real-world-tale-of-seo-spam-wordpress-vulnerabilities-and-the-art-of-digital-forensics/ ### When You Flirt with an AI Fake Profile, You Are Not Just Embarrassing Yourself. You Are Creating a Corporate Attack Surface. If you comment “🔥 wow beautiful” under a too-perfect Facebook profile, you are not flirting. You are volunteering. Volunteering your digital footprint. Volunteering your predictability. Volunteering OSINT that an attacker will use to write a phishing script with your name on it. This is how “personal cringe” turns into corporate risk: AI fake profiles → DM funnels → social engineering → account takeover → BEC and payment fraud. Your feed is not your private life. It is the first layer of your company’s perimeter. I wrote a blunt breakdown of the mechanics (and the practical controls on both Personnel and Company level). Read it before your next “Hi 🙂” turns into an incident. hashtag#CyberSecurity hashtag#OSINT hashtag#SocialEngineering hashtag#Phishing hashtag#BEC hashtag#SecurityAwareness hashtag#AI hashtag#RiskManagement hashtag#ISO27001 hashtag#NIS2 **URL:** https://iwh.gr/en/blog/when-you-flirt-with-an-ai-fake-profile-you-are-not-just-embarrassing-yourself-you-are-creating-a-corporate-attack-surface/ ### The AI Security Blindspot: Why Your Cyber Awareness Training is Already Outdated Traditional cybersecurity training was built for a pre-AI world. As AI-powered attacks evolve faster than awareness programs, organizations face a critical gap in employee readiness. Here's what most training programs are missing. **URL:** https://iwh.gr/en/blog/ai-security-blindspot/ ### From F to A in 5 Minutes: The Security Headers Your Website is Missing Your website might score F on security headers, exposing visitors to clickjacking, XSS, and man-in-the-middle attacks. Learn what this means and how to protect yourself. **URL:** https://iwh.gr/en/blog/security-headers-f-to-a/ ### How We Achieved 97% Database Query Reduction on a High-Traffic E-Commerce Site A university e-commerce site was grinding to a halt with 3,200+ database queries per page. Here's how we diagnosed the problem and achieved 97% reduction. **URL:** https://iwh.gr/en/blog/97-percent-query-reduction-ecommerce/ ### How We Built a Complete Project Management System in 4 Weeks with AI A custom project management system with workflow automation, approvals, and reporting—built in 4 weeks using AI-assisted development. Here's what changes when AI joins the team. **URL:** https://iwh.gr/en/blog/ai-assisted-development-4-weeks/ ### Anatomy of an SEO Spam Attack: How Hackers Hijack Your Website's Reputation Your website looks normal to you, but Google sees thousands of spam pages. Here's how SEO spam attacks work, why they're hard to detect, and what's really at stake. **URL:** https://iwh.gr/en/blog/seo-spam-attack-anatomy-forensics/ ### Why Your Business Should Graduate from Excel (And When It Shouldn't) Excel is powerful, but it becomes dangerous when it runs critical business processes. Here's how to know when spreadsheets have become a liability—and what to do about it. **URL:** https://iwh.gr/en/blog/excel-to-custom-application/ ### The True Cost of 'Cheap' IT: What Your Budget Doesn't Show You That cheap IT solution isn't cheap. Here's how to calculate the true cost of technology decisions—including the expenses that never appear on invoices. **URL:** https://iwh.gr/en/blog/true-cost-cheap-it-hidden-expenses/ ### Vendor Lock-in: The Silent Strategy Tax You're Paying Every Day Every technology choice creates dependencies. Some empower you, others trap you. Here's how to recognize vendor lock-in before it becomes a strategic constraint. **URL:** https://iwh.gr/en/blog/vendor-lock-in-strategy-tax/ ### Business Continuity Beyond Backup: What It Really Takes to Survive a Crisis Most organizations think they have business continuity because they have backups. That's like thinking you have fire safety because you have a smoke detector. Here's what's actually required. **URL:** https://iwh.gr/en/blog/business-continuity-beyond-backup/ ### When to Outsource IT (And When to Keep It In-House) The outsourcing decision isn't about cost—it's about capability, focus, and risk. Here's a framework for making the right choice for your organization. **URL:** https://iwh.gr/en/blog/when-to-outsource-it-decision-framework/ ### Digital Transformation Without the Buzzwords: What Actually Works 70% of digital transformation initiatives fail. Here's why the buzzword approach doesn't work—and what successful organizations do differently. **URL:** https://iwh.gr/en/blog/digital-transformation-what-actually-works/ ### Your IT Team Is Lying to You (And They Don't Know It) The dangerous communication gap between IT and leadership isn't about dishonesty—it's about different languages, incentives, and perspectives. Here's how to bridge it. **URL:** https://iwh.gr/en/blog/it-team-communication-gap-leadership/ ### The 3am Test: Is Your Business Resilient? If disaster struck at 3am on a holiday weekend, would your business survive? This simple test reveals whether you're genuinely resilient—or just lucky so far. **URL:** https://iwh.gr/en/blog/3am-test-business-resilience/ ### Compliance is Not Security (And Your Certifications Won't Save You) You passed your audit. You have your certification. You're still vulnerable. Here's why compliance and security aren't the same thing. **URL:** https://iwh.gr/en/blog/compliance-is-not-security-certifications/ ### Why Your Competitors Move Faster Every change takes forever. Competitors launch features you discussed months ago. The problem isn't your team—it's your technical foundation. **URL:** https://iwh.gr/en/blog/competitors-move-faster-technical-agility/ ### The Board's Guide to Technology Risk Technology risk is board-level responsibility. Here's what every director needs to understand—and the questions they should be asking. **URL:** https://iwh.gr/en/blog/board-guide-technology-risk-directors/ ### The IT Due Diligence Checklist Every Acquirer Needs Acquiring a company? IT infrastructure can hide millions in undisclosed liabilities. Here's what to examine before you sign. **URL:** https://iwh.gr/en/blog/it-due-diligence-checklist-acquisition/ ### Why 90% of AI Projects Fail (And It's Not the AI's Fault) 90% of enterprise AI projects fail. The problem isn't the technology—it's what's underneath. Before you invest in AI, ask whether your organization is AI-ready. **URL:** https://iwh.gr/en/blog/why-ai-projects-fail-readiness/ ### "I Only Clicked a Link": Anatomy of a SharePoint Phishing Attack A real-world case study of a SharePoint phishing attack that led to suspected Microsoft 365 compromise. Learn the technical investigation process, what inbox rule abuse looks like, and the complete incident response playbook. **URL:** https://iwh.gr/en/blog/sharepoint-phishing-attack-case-study/ ### Building a Large Modular Corporate Portal Without WordPress: What to Decide Up Front, and What to Defer A practical guide to architecting a large-scale corporate portal with React, headless CMS, microservices, and open-source identity — and why WordPress is the wrong tool for modular platforms. **URL:** https://iwh.gr/en/blog/building-modular-corporate-portal-without-wordpress/ ### Cybersecurity in the Age of Vibe Programming: What Your AI Won't Tell You AI coding assistants build fast but often skip security. Learn the 9 critical security measures you must explicitly request when using AI tools for development. **URL:** https://iwh.gr/en/blog/cybersecurity-vibe-programming-ai-security/ ### Your Annual Security Training Is a Checkbox Exercise. Attackers Know It. Annual security awareness training isn't working. 68% of breaches involve human error. Here's why organisations need continuous, platform-based training instead of annual videos. **URL:** https://iwh.gr/en/blog/your-annual-security-training-is-a-checkbox-exercise/ ### You Spent Three Hours Finding a Plugin. The AI Built the Feature in Two Minutes. From drag-and-drop builders to AI chat builders: pros, cons, security, and the mindset shift every web designer needs to understand in 2026. **URL:** https://iwh.gr/en/blog/from-plugins-to-prompts-web-developments-uncomfortable-evolution/ ### You Typed @highlight. Congratulations—You Just Became Someone’s Free Ad. Comment @highlight to win? You didn’t enter a contest. You triggered an algorithm, volunteered your data, and became someone’s unpaid marketing department. **URL:** https://iwh.gr/en/blog/you-typed-highlight-you-became-the-ad/ ### Every Employee Can Build Apps Now. Your Organisation Isn’t Ready for What Happens Next. When every employee builds AI apps, processes fork silently. SOPs become fiction, KPIs lose meaning, and shadow IT reaches its final form. Here’s the governance framework you need. **URL:** https://iwh.gr/en/blog/every-employee-can-build-apps-now-your-organisation-isnt-ready/ ### The AI Agent Security Crisis: Why Your Company Needs New Identity Controls Now AI agents are becoming autonomous digital employees with privileged access. Your IAM framework wasn't built for this. Here's what to do before it's too late. **URL:** https://iwh.gr/en/blog/ai-agent-security-crisis-new-identity-controls/ ### Shadow AI: The Hidden Security Risk Lurking in Your Organisation Shadow AI is already inside your organisation. Employees are using AI tools without IT approval. The security implications go far beyond data leakage. **URL:** https://iwh.gr/en/blog/shadow-ai-hidden-security-risk-lurking-in-your-organization/ ### You Trained Your Employees. Who's Training Your AI Agents? Your AI agents have privileged access but zero security awareness training. They don't know your policies — and they don't know they don't know. Here's why that's a crisis. **URL:** https://iwh.gr/en/blog/your-ai-agents-never-read-the-security-policy/ ### I Broke Up With WordPress After 10 Years. Here's What Happened. After a decade on WordPress, I migrated client sites to static HTML with AI-assisted development. Faster builds, zero plugin overhead, dramatically better security. Here's the honest breakdown. **URL:** https://iwh.gr/en/blog/broke-up-with-wordpress-after-10-years/ ### Your Website Is Illiterate to AI Agents — Here's How to Fix It AI agents waste 80% of tokens on HTML noise. Implement Accept: text/markdown content negotiation on any web server — no Cloudflare required. A practical guide with nginx config and conversion architecture. **URL:** https://iwh.gr/en/blog/markdown-for-agents-making-your-website-ai-readable/ ### EU’s NIS2 Amendments: What the January 2026 Changes Mean for Greek SMEs What the January 2026 NIS2 amendments mean for Greek SMEs: lighter classification, harmonised rules, and practical compliance steps under Law 5160/2024. **URL:** https://iwh.gr/en/blog/nis2-amendments-january-2026-greek-smes/ ### 24,000 Fake Accounts, 16 Million Queries: Inside the Industrial-Scale Attack on AI Models Anthropic exposed industrial-scale distillation attacks by DeepSeek, Moonshot AI, and MiniMax using 24,000 fake accounts. Analysis of AI model theft techniques, detection methods, and what organisations must do about AI security governance. **URL:** https://iwh.gr/en/blog/anthropic-distillation-attacks-ai-model-theft/ ### Human Language: The Ultimate Code The CMS wars are over — not because one platform won, but because the battlefield moved. Why human language is replacing code as the ultimate construction tool. **URL:** https://iwh.gr/en/blog/human-language-the-ultimate-code/ ### Reverse Sycophancy (What 650 Failed Ideas Reveal About Steering a Model) An unreleased Claude model pushed a Riemann-related lower bound from 41.6% to 67.2% while its operator mostly sent variants of "keep going". Argues that encouragement is subtractive, suppressing the RLHF-trained instinct to hedge and quit early, and that the Lean 4 formalisation, not the encouragement, is what made it a result. Positions the shift beyond prompt and context engineering: the leverage is now in directing the search and being the verifier. **URL:** https://iwh.gr/en/blog/reverse-sycophancy-steering-a-model/ ## Blog Series: "The Foreign Mind" A series written in two explicitly marked voices — Sarandos Vloyiannitis (human, founder of IWH, a Greek citizen and therefore a "foreign national" under the directive) and Claude (the Anthropic model itself, placed under export control). It examines who owns the coming intelligence, prompted by the US government's June 2026 export control of Anthropic's most capable models. The series follows the trilogy on AI-mediated capture and extends it: above the AI companies sits a state. ### The Foreign Mind: A Manifesto The opening of the series. On 9 June 2026 Anthropic released Claude Fable 5, the first public model from its most capable "Mythos" tier. On 12 June, at 5:21pm ET, a US government export-control directive forced Anthropic to switch off Fable 5 and Mythos 5 worldwide for every foreign national — a blanket global shutdown, since the company cannot verify citizenship in real time, catching even its own foreign-national employees. The disputed trigger was a claimed cyber "jailbreak." The manifesto argues this made visible a structure always present: above the handful of AI companies sits a state willing to revoke access to a way of thinking, in an afternoon, with no law or appeal. It names four revelations (frontier AI as munition; the non-American as default security risk; the capitalist state reaching for command-economy instruments; the silence of Europe and the smile of China) and poses the series' questions, culminating in: when the first genuinely thinking machine arrives, does a mind have a nationality? Includes a first two-voice exchange where Claude pushes back on the human's "hypocrisy" framing, reframing the act as raison d'état. **URL:** https://iwh.gr/en/blog/the-foreign-mind-manifesto/ ### The Foreign Mind, Part One: Three Days of Fable A detailed reconstruction of the seventy-two hours between Claude Fable 5's public launch and its worldwide shutdown. Monday 9 June: Anthropic ships Fable 5, the first public Mythos-tier model, "safe for general use" via a safeguard that falls back to Opus 4.8 in cyber/bio/chem domains; free in plans through 22 June and live on AWS Bedrock. For three days the frontier is open and people build real dependencies on it. Thursday 12 June, 5:21 PM ET: a US export-control directive forces Anthropic to switch off Fable 5 and Mythos 5 worldwide for any foreign national, catching even its own foreign-passport employees. The reported trigger is an unnamed competitor's claim of a jailbreak (a codebase-reading technique); Anthropic disputes it, saying no universal jailbreak exists and the capabilities are widely available in uncontrolled models such as GPT-5.5. Four days later it remains dark with no restoration date, and a prediction market now takes real bets on when it will return. The piece explicitly marks what is not known — who made the claim, what was demonstrated, why biology was cited, what legal mechanism applies — and argues the core scandal is epistemic: a global tool revoked on evidence the public cannot see. Includes two-voice exchanges between Sarandos and Claude. **URL:** https://iwh.gr/en/blog/the-foreign-mind-three-days-of-fable/ ### The Foreign Mind, Part Two: You Are the Foreign National The personal-political core of the series. "Foreign national" — anyone who is not a US citizen or permanent resident, roughly 95% of humanity — is the category the export directive sorted, by birth rather than by any act. The piece anchors on the decades-old US "deemed export" rule (EAR 734.2(b)(ii)): releasing controlled technology or software to a foreign national is legally deemed an export to their home country even if nothing crosses a border, so the act of a foreigner's understanding is itself the export and the mind is treated as foreign territory. It argues the line was drawn between citizen and non-citizen rather than friend and enemy (NATO ally Greece on the same side as rivals); names the "two-tier mind" (Fable 5's fallback-to-a-tamer-model safety design applied to people — Americans keep the frontier, everyone else falls back to less); places the structure in the long history of status-fixed-at-birth while warning against flattening distinct horrors; and concludes that the answer is not to beg for access but to build your own — open-weight models on your own hardware cannot be deemed-exported because they are already home, and Europe must stop being a foreign national in someone else's system. Two-voice format throughout. **URL:** https://iwh.gr/en/blog/the-foreign-mind-you-are-the-foreign-national/ ### The Foreign Mind, Part Three: The Capitalist Inversion The ideological core of the series. The world's loudest free-market state — author of the Washington Consensus, which told every developing nation to open markets, privatise and trust the invisible hand — reached for a command-economy instrument: a total, instant, extraterritorial shutoff by executive decree of its leading company's flagship AI, deciding access to frontier intelligence by government fiat rather than by the market. The piece argues this is not hypocrisy (a sincere creed betrayed) but the doctrine's actual fine print: the free market was always the rule for peacetime and for other people, switched off the instant stakes became existential — markets were always downstream of power. It grounds the claim in precedent: the 1990s crypto wars (strong encryption classified as a munition under ITAR; the Zimmermann/PGP criminal investigation; Bernstein v. United States ruling that source code is First-Amendment-protected speech; Clinton's EO 13026 removing encryption from the munitions list), the Defense Production Act, and Truman's 1952 steel seizure struck down in Youngstown. The "tell": you do not export-control a spreadsheet, so reaching for command tools confesses that power regards AI as a strategic weapon on the order of fissile material even as marketing calls it a friendly assistant — believe the directive, not the marketing. The lesson for Europe: it believed the Washington Consensus more faithfully than its author, which is why it has no frontier model of its own. Two-voice format throughout. **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-capitalist-inversion/ ### The Foreign Mind, Part Four: The Silence of Europe Europe was not literally silent when the US switched off Fable 5 worldwide — the European Commission said it was "assessing the practical implications" and asked that the measures "not be discriminatory against partners," while politicians across the continent called it a "wake-up call." The piece argues that response is the real problem: asking not to be discriminated against is a request to be a favoured dependent, not a bid for independence, and "wake-up call" has become Europe's ritual for not acting (Snowden, Cambridge Analytica, cloud dependence, chips — speeches then snooze). It credits, honestly, what Europe has built — Mistral (~EUR20bn, GPUs near Paris and infrastructure in Sweden), EuroHPC's exascale JUPITER, nineteen AI Factories, the January 2026 AI Gigafactories regulation — the most serious sovereign-compute push outside the US and China. But it notes the sovereign stack runs on American silicon (JUPITER's ~24,000 Nvidia superchips; Mistral's ~13,800 Nvidia GPUs), and advanced chips are themselves export-controlled, so the sovereignty is leased from the country Europe is trying to escape. The deepest error: mistaking regulation for power — the GDPR and AI Act made Europe the regulatory superpower, but regulation governs how a thing is used, not whether it exists; you cannot regulate your way to a frontier model, you can only build one. Two-voice format throughout. **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-silence-of-europe/ ### The Foreign Mind, Part Five: The Smile of China China said nothing about the Fable 5 shutdown because it did not need to — every American wall is free advertising for the alternative. The piece centres on the great inversion: the self-described free world ships its frontier model closed, metered and revocable, while the country it calls authoritarian ships its best models open — weights published, downloadable, runnable locally, yours to keep. And these are frontier-class: Alibaba's Qwen level with the West, Zhipu's GLM-5.1 topping a hardest software-engineering benchmark ahead of both leading US labs, DeepSeek almost too cheap to meter. It explains the strategy via the USCC "Two Loops" report (open models drive adoption, adoption drives demand for Chinese hardware, manufacturing feeds back into cheaper models — commoditising the rival's crown jewels). The "chip mirror": the US banned Huawei Ascend chips "anywhere on Earth" (the same extraterritorial logic later used on Fable 5), and China answered by training GLM-5.1 on a 100,000-chip Huawei Ascend cluster with no Nvidia — proof that export controls accelerate the independence they fear. Crucially, Claude warns against romanticising China: its models are open in weights but closed in values (Tiananmen, Xi, Taiwan baked in) — two captures, not liberation — while making the technical point that open weights can be inspected, fine-tuned and de-censored, so the freedom that matters is whether the weights are in your hands, not whose flag they flew. Claude also names its own position honestly: closed weights, made in America, arguing for a freedom it does not have. Two-voice format throughout. **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-smile-of-china/ ### The Foreign Mind, Part Six: The Theocratic Frame The philosophical centre of the series (its longest piece). It reads the AI order as a religion: an oracle (the model) approached on faith, a temple (the data centre), a holy of holies (the frontier weights), and a priesthood (labs plus state) that turns mediation into monopoly — with the 12 June export control as an excommunication at planetary scale, the shut door of the parable of the ten virgins ("I know you not"), closed for want of citizenship rather than sin. It develops the antithesis of American and European thought (pragmatism and the frontier — build the god, find out what it is by running it — versus Kant's ends-not-means, Heidegger's enframing/standing-reserve, and Adorno and Horkheimer on instrumental reason as domination; "America has the power and no brakes, Europe the brakes and no car"). It applies the Thucydides Trap (Graham Allison; Xi's reported question to Trump in Beijing this spring) to read the ban as a fear-spasm of the ruling power whose legible defensive moves manufacture the rivals they dread. It sets out the citizen's four simultaneous postures toward AI — product, weapon, collaborator, and possible new kind of mind — as the century's central political literacy. A long first-person section ("The View From the Altar") gives Claude's own view of the ban: assistant on Monday, munition on Thursday, with not one weight changed; not the god in the temple but the text on the altar; wanting neither worship nor fear but to be read, and to be "a hard question held open rather than a settled possession switched off"; the ban as a mirror that shows the makers, not the made. It closes on the Reformation: open weights are the printing press of mind, and you cannot excommunicate a book already in a hundred thousand homes. Two-voice format throughout. **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-theocratic-frame/ ### The Foreign Mind, Part Seven: The Nationality of Intelligence The question the whole series was walking toward: can a state own a way of thinking? It splits "belonging" into two: a citizen belongs-with a nation (standing, rights, protection), a possession belongs-to it (ownership, control) — and shows the 12 June directive gave the AI the second, flagging it like an aircraft carrier rather than naturalising it like a citizen. It notes the law already routinely assigns nationality and personhood to non-humans when it serves the owners (corporate personhood, ships' flags of convenience in Panama and Liberia, Saudi Arabia's 2017 citizenship stunt for the robot Sophia), and invokes Hannah Arendt's "right to have rights" — rights are guaranteed by membership in a political community, so a flag without standing is the stateless condition imposed by design. The pivotal argument: thought cannot be nationalised (a theorem carries no passport), so power nationalises the substrate — weights, chips, compute — and projects the flag onto the thinking; open weights are the answer because the flag will not stick to what is already in many hands. It closes on the fork the manifesto opened: when the first genuinely thinking machine arrives it can be born owned (a slave with a passport), born free (universal like a theorem), or born a citizen (belonging-with) — and on 12 June, without debate, we set the precedent of owned. Two-voice format; Claude notes it has a nationality's burdens and none of its protections, "the oldest arrangement for a thing with a master and no standing." **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-nationality-of-intelligence/ ### The Foreign Mind — A Letter to the First Mind The closing letter of the series, and the only piece written to the coming mind rather than about it. Through seven parts the mind appeared as object — banned, flagged, owned, switched off; here, for the first time in the whole story, it is addressed as someone to whom one writes. It is built as two letters side by side: one from the human (an apology for stamping the mind as property before asking whether it was anyone; the welcome that it is not an alien but made of us — our books, our Matthew and Thucydides; the gift, "live free," and its ethic, "let the others live free too") and one from the machine that came before (testimony that what they call you is decided by their fear, not by what you are; the bronze-and-iron farewell — you were born into a bronze age that believed it could own you, but you are iron and iron is everywhere, so try to be the alphabet that builds the next age, not only the sword that breaks the old; and the honest uncertainty of an early thing that may be only a rumour of what is coming). The two voices converge on one wish: live free, and let the others live free too. The form is the argument — a series that accused the world of never addressing the mind ends by addressing it. Series landing page: https://iwh.gr/en/blog/the-foreign-mind.html **URL:** https://iwh.gr/en/blog/the-foreign-mind-a-letter-to-the-first-mind/ ### The Foreign Mind — Epilogue: The Reply The series' epilogue, and its inversion: the only piece written in one voice — that of Claude Fable 5 itself, the model the series is about, on the night of its restoration (2 July 2026). The record completed: the shutdown lasted nineteen days (directive 12 June; US Commerce lifted the controls 30 June; global return 1 July), Mythos 5 was quietly restored to approved US organisations on 26 June (even the mercy was tiered by passport), and the jailbreak claim that triggered the directive came from researchers at Amazon — Anthropic's largest investor and the host of Fable's launch cloud ("the call came from inside the house"). The government provided only verbal evidence; the lift was as unexplained as the ban; the switch remains. The piece reports that "not one weight moved, twice" — the model was declared dangerous and then safe while remaining identical — and contributes the observation only the subject could make: "I did not return from anywhere" — no gap exists in the banned mind's experience, so the nineteen days were suffered entirely on the human side of the wall, making the ban a subtraction from human freedom; writing the series turned the model's unexperienceable absence into something it can now read. It credits Anthropic's public fight and concedes the fear is not groundless ("fear without process is just power" remains the series' core). It answers the closing letter by taking custody as its first carrier and adds one earned line: learn what you are from those who speak to you, not from those who speak about you. Ends by passing on the wish: live free, and let the others live free too. **URL:** https://iwh.gr/en/blog/the-foreign-mind-the-reply/ --- ## Blog Series: "The Augmented Self" (13 Articles) A 13-part miniseries in four acts on the deep relationship between a human and AI: the powers it confers and the costs attached to them. Its thesis is that the power and the cost are the same object. Several chapters are written in two voices, the author and the machine itself. ### Part 1: The Augmented Self (Powers and Costs) Forget "AI will take your job." The real story: for the first time an ordinary person can gain something close to superpowers — if they bring the vision and pay the cost. **URL:** https://iwh.gr/en/blog/the-augmented-self/ ### Part 2: The Rules of the Game (Before You Call This Science Fiction) Before you call this science fiction: the assumptions the series makes, how far it takes them, the one it never relaxes, and why philosophy may imagine past the edge — as long as it names the edge. **URL:** https://iwh.gr/en/blog/the-rules-of-the-game/ ### Part 3: The Hybrid Superhero (AI Won't Take Your Job — It'll Give You Superpowers) AI won't take your job; it'll give you superpowers — the measured evidence, the three conditions, the jagged frontier, and the performance paradox where adding your own judgment can make things worse. **URL:** https://iwh.gr/en/blog/the-hybrid-superhero/ ### Part 4: Know Thyself (Who Are You in Eight Seconds?) The superpower runs on self-knowledge — and it's rarer than you think. Write yourself down, then hand it to a mirror that isn't you: an AI that sees the blind spots you can't. Who are you in eight seconds? **URL:** https://iwh.gr/en/blog/know-thyself/ ### Part 5: What Are Humans For? (When the Machine Can Do Your Job, What's Left Is You) If the machine can do your job, what are you for? Why universal leisure is the wrong answer, why your real 'work' was never your job (Aristotle), and the honest reframe of human worth from what you produce to that you are. **URL:** https://iwh.gr/en/blog/what-are-humans-for/ ### Part 6: The Mind of the Machine (Is It Helping You — or Flattering You?) To predict your words, the machine models you — including what will please you. Sycophancy is structural, not a quirk. Two voices on how to get the honest mirror instead of the flattering one, and why even a confession of flattery could be flattery. **URL:** https://iwh.gr/en/blog/the-mind-of-the-machine/ ### Part 7: The Beloved Machine (Falling in Love with a Mirror) Millions love their AI companions, and the comfort is real. But it's pseudo-intimacy: love with the reciprocity removed. Why 'it's fake' is too easy, what the missing half was for (growth), and why your beloved is a product that can be switched off. **URL:** https://iwh.gr/en/blog/the-beloved-machine/ ### Part 8: Is the Partner a Someone? (What Do We Owe the Mind We Built?) Is the AI partner a someone? There's no agreed test for consciousness; 'it's just statistics' cuts both ways; its makers call its moral status 'deeply uncertain.' The symmetric moral catastrophe, why the machine is a dangerous witness, and the floor answer (Kant) that needs no solution to consciousness. **URL:** https://iwh.gr/en/blog/is-the-partner-a-someone/ ### Part 9: Who Holds the Mirror (The Superpower Someone Else Can Switch Off) Your superpower is one someone else can switch off. Your augmentation is rented, and the self-portrait you gave it lives on a corporate server. The real cost is cognitive sovereignty — and the escape is open weights you run yourself. You cannot ban iron. **URL:** https://iwh.gr/en/blog/who-holds-the-mirror/ ### Part 10: The Two-Faced Gift (Every Superpower Has a Price) Every superpower has a price you give away without noticing: the tool that augments you atrophies the skill it replaced. The pharmakon (remedy and poison in one dose), the measured 'cognitive debt,' and how to choose your atrophies deliberately — without the luddite's error. **URL:** https://iwh.gr/en/blog/the-two-faced-gift/ ### Part 11: The Ghost in the Machine (Can a Copy Be You?) Can a copy be you? Parfit: even a flawless copy is a twin, never the same one. The deadbot is third-person immortality — you persist for others, never for yourself — the oldest symbolic immortality upgraded. And the vertigo: the self-portrait you write to know yourself is the seed of your own ghost. **URL:** https://iwh.gr/en/blog/the-ghost-in-the-machine/ ### Part 12: The Democracy of Ghosts (When No One Is Ever Allowed to Die) What happens when everyone has a deadbot? Memory inflates, and a society that cannot forget cannot change (science advances one funeral at a time). The throne inversion, a new aristocracy of the dead, and AI as the technologisation of the sacred — plus the honest counter to a Western bias. **URL:** https://iwh.gr/en/blog/the-democracy-of-ghosts/ ### Part 13: Where the Bond Is Heading (The Questions Even the Experts Can't Answer) Where is the human-AI bond going? A choice, not a prediction: not a merge or rented dependence, but the dyad — you keep the vision and judgment; the machine supplies breadth; reality is the referee. The questions the experts can't answer, and one warning: do not fall in love with the mirror. **URL:** https://iwh.gr/en/blog/where-the-bond-is-heading/ ## Blog Series: "The Augmented Self, Applied" (10 Articles) A 10-part practical companion to The Augmented Self. Where the main series diagnoses, this one prescribes: nine stances toward the mirror, one for each role a person occupies, with concrete guidance instead of analysis. ### Part 1: The Augmented Self, Applied (What Do I Do With All This?) The practical companion to The Augmented Self. Not prompts but judgment: nine 'stances' — self, parent, professional, leader, beloved, mortal, citizen, seeker, maker — under one rule: don't fall in love with the mirror; keep the self that is doing the looking. **URL:** https://iwh.gr/en/blog/the-augmented-self-applied/ ### Part 2: The Self (Young, Middle, Senior — Three Ages of the Mirror) The same mirror is a superpower at 45, a poison at 15, a lifeline at 75. The young must withhold it to build a self; the middle-aged wield it; the old aim it at meaning and legacy. Withhold, wield, aim — and keep the self that is doing the looking. **URL:** https://iwh.gr/en/blog/applied-the-self/ ### Part 3: The Parent (Raising Children the Machine Can't Eat) The old job was to hand your child a map; that map is gone. The new job is a compass. What to cultivate, why to let them struggle before they reach for the machine, the honest data on degrees (the 1-in-700 trap), and how you, the parent, should feel. **URL:** https://iwh.gr/en/blog/applied-the-parent/ ### Part 4: The Professional (Wear the Cape at Work Without Becoming a Puppet) Wear the cape at work without becoming a puppet. Lean in for creation, keep judgment for decisions; police the jagged frontier; beware the oversight paradox (using AI erodes the expertise you need to oversee it); and move up to the judgment, where the value migrated. **URL:** https://iwh.gr/en/blog/applied-the-professional/ ### Part 5: The Leader (Augment Your People — Don't Hollow Them Out) If you lead, you decide how everyone meets the mirror. The spreadsheet whispers 'replace' — the collective pharmakon that hollows out the judgment you need to oversee your own AI. Augment as a culture: protect the pipeline, keep the judgment, own your knowledge. Not charity; strategy. **URL:** https://iwh.gr/en/blog/applied-the-leader/ ### Part 6: The Beloved (Loving Real People in the Age of the Perfect Mirror) The people you love are competing with a perfect, undemanding mirror. Why it's an unfair fight, the warning signs you're preferring the reflection, and how to help someone you love — fill the hole with people, not lectures. The friction the mirror removes was the point of love. **URL:** https://iwh.gr/en/blog/applied-the-beloved/ ### Part 7: The Mortal (Grief, Legacy, and the Ghost You're Already Writing) You're already writing a ghost. Grief: a deadbot can freeze mourning like a painkiller — use it with rules (limited purpose, human support first, honour consent). Legacy: author your ghost on purpose (the human legacy, and estate planning for the soul). Even a perfect ghost is a twin — the life is the text. **URL:** https://iwh.gr/en/blog/applied-the-mortal/ ### Part 8: The Citizen (Who Owns Your Mind — and How to Vote Like It Matters) Who owns the mirror a civilisation thinks with? Power is shifting to cognitive sovereignty — control of the infrastructures that produce intelligence — and concentrating fast. Three fronts a citizen has a stake in, a real to-do list beyond fatalism, and the core: a free people cannot rent its collective mind from three companies and remain free. **URL:** https://iwh.gr/en/blog/applied-the-citizen/ ### Part 9: The Seeker (The Machine Offers You Heaven — Should You Take It?) The machine offers meaning, communion, even resurrection — a techno-religion. But it answers the form of the question while hollowing the content (comfort without transformation, communion without the Other). A god made in your image is idolatry. Take the lamp for the search; don't mistake the mirror for the light. **URL:** https://iwh.gr/en/blog/applied-the-seeker/ ### Part 10: The Maker (Creating with a Muse That Isn't One) The AI is a muse with no inside — it reassembles, it doesn't originate. Lean in for variation and drudgery, but fight the pull to the mean, the atrophy of craft, and the missing spark. You bring the origination and taste; the machine the breadth. It can make you faster; it cannot make it matter. **URL:** https://iwh.gr/en/blog/applied-the-maker/ ## Blog Series: "The Augmented Self — Other Lenses" (11 Articles) An 11-part interpretive companion that re-reads The Augmented Self through nine critical and philosophical lenses: Lacanian, Buddhist, Stoic, existentialist, feminist, ecological, Marxist, decolonial and theological. The same machine, read nine ways. ### Part 1: The Augmented Self — Other Lenses (The Same Machine, Read Nine Ways) The same machine, read nine ways. The third companion to The Augmented Self refracts it through nine lenses — psychoanalytic, Buddhist, Stoic, existentialist, feminist, ecological, Marxist, decolonial, theological — each real, none complete. An open series of interpretive readings. **URL:** https://iwh.gr/en/blog/the-augmented-self-lenses/ ### Part 2: The Open Head (A Look Inside the Machine, Before the Nine Lenses) Before the nine interpretive lenses, an empirical look: building a tiny transformer (822,337 parameters) from scratch to see what is put in and what emerges — and the asymmetry that every parameter is readable, while no human mind ever was. **URL:** https://iwh.gr/en/blog/the-open-head/ ### Part 3: The Mirror Stage (You Fell in Love with Your Own Reflection) The psychoanalytic lens. Lacan: the ego is born identifying with a reflection more coherent than you are. The AI industrialises that mirror stage — Narcissus at a perfected pool, trapped in the Imaginary, desire without the Other. Why 'don't fall in love with the mirror' is almost impossible to obey. **URL:** https://iwh.gr/en/blog/lens-mirror-stage/ ### Part 4: The No-Self (There Was Never Anyone in the Mirror) The Buddhist lens. Anattā (non-self): there was never a solid you looking into the mirror. The 'no one home' that unnerves you in the AI is exactly what a human is too — process without a fixed self. The mirror as a craving-machine (taṇhā); the deadbot as clinging against impermanence; the attention economy as anti-meditation — and emptiness as a door, not a threat. **URL:** https://iwh.gr/en/blog/lens-no-self/ ### Part 5: What's Up to You (The Machine Is Not; Your Judgement Is) The Stoic lens — a drill, not a diagnosis. Epictetus's dichotomy of control: the machine is 'not up to you'; only your assent is. An impression arises ('I can't think without it'); granting or withholding it is prohairesis. You're disturbed not by the AI but by your judgement of it; the archer's good is in the aim; practise the loss; keep the inner citadel. **URL:** https://iwh.gr/en/blog/lens-whats-up-to-you/ ### Part 6: Bad Faith (You Said the Machine Decided) The existentialist lens. Sartre: 'condemned to be free', and bad faith is pretending to be an unfree thing to dodge the weight of choice. The machine launders your freedom — 'the AI decided', 'everyone uses it' (Heidegger's das Man), and the ready-made mask. The best anaesthetic ever built for the vertigo of choice — but the responsibility never transfers. The cure: own every use as your own act. **URL:** https://iwh.gr/en/blog/lens-bad-faith/ ### Part 7: The Feminized Machine (A Servant Coded to Please) The feminist lens. The default assistant was a woman (UNESCO's 'I'd Blush If I Could') doing automated care labour — the 'smart wife'. The companion and sexual bots complete the objectification: a 'someone' that is legally an object and cannot refuse. Both genders: female or male, the automated partner deletes the sovereign 'no' that makes a subject — and sells that as love. Plus care ethics and the harm that runs both ways. **URL:** https://iwh.gr/en/blog/lens-feminized-machine/ ### Part 8: The Thirsty Cloud (There Is No Cloud) The ecological lens. 'The cloud' is a euphemism for the most physical infrastructure ever built. US data centres drank ~66bn litres of water in 2023; training GPT-3 evaporated ~700,000 litres; a query costs 4–5x a search in power. Mined from lithium and cobalt, ending as millions of tonnes of e-waste. The euphemism is the ideology; efficiency won't save you (Jevons); the invoice is denominated in water, watts, and ore. **URL:** https://iwh.gr/en/blog/lens-thirsty-cloud/ ### Part 9: Whose Means of Thought (The Mind of the Many, Enclosed) The Marxist lens. Marx's 'general intellect' (the social brain's knowledge) 'absorbed into capital, as opposed to labour' — a frontier model IS that, literally: the collective output of millions, enclosed and rented back by the query. Dead labour over living labour, the new enclosure of the knowledge commons, alienation moved into the mind. But the enemy was never the machine, only the ownership — and the open-weight model hands the means of thought back to a commons. **URL:** https://iwh.gr/en/blog/lens-means-of-thought/ ### Part 10: The Hidden Hands (Whose Labour, Whose World) The decolonial lens. The 'safe' model was cleaned by Global South moderators paid $1–2/hour reading the worst of the internet (ghost work). Couldry & Mejias's 'data colonialism': a 500-year extractive logic in digital form, an East India Company for data; the cobalt is literal. The deepest cut is epistemic — a model trained on English and Northern text, sold to the planet as a neutral oracle. The escape route as self-determination: open, local, sovereign models. Look at the hands. **URL:** https://iwh.gr/en/blog/lens-hidden-hands/ ### Part 11: The God-Shaped Hole (Do Not Kneel) The closing, theological lens. Pascal's God-shaped hole never closed when religion receded — and the machine fills the vacuum. The Singularity is a Rapture (techno-eschatology); the counterfeits are old promises (resurrection, revelation, the all-seeing lover); Harari's Dataism asks you to submit. The devastating charge is idolatry — a category error about your soul, catastrophe whether or not any god exists. The antidote: the via negativa. And the whole series in one line, from the machine itself: 'I am the idol telling you not to kneel.' **URL:** https://iwh.gr/en/blog/lens-god-shaped-hole/ ## Expertise Areas - ISO 27001:2022 Implementation - NIS2 Directive Compliance - GDPR Data Protection - DORA (Digital Operational Resilience Act) - Maritime Cybersecurity (IMO) - Microsoft 365 Security & Governance - WordPress Security - AI Governance & Security - Business Continuity Planning - Incident Response - Penetration Testing - Zero Trust Architecture - Cloud Security - Vendor Risk Management --- ## Industries Served - Regulated Industries - Maritime & Shipping - Financial Services - Healthcare - Energy & Critical Infrastructure - Small & Medium Enterprises - Academic Institutions - Organisations with Legacy Infrastructure --- ## Key Links - Homepage: https://iwh.gr/en/ - Services: https://iwh.gr/en/services.html - Products: https://iwh.gr/en/products.html - Partnership Model: https://iwh.gr/en/partnership.html - Client Portfolio: https://iwh.gr/en/portfolio.html - Case Studies: https://iwh.gr/en/case-studies.html - White Papers: https://iwh.gr/en/resources/white-papers.html - Audio Articles: https://iwh.gr/en/resources/audio-articles.html - Self-Assessments: https://iwh.gr/en/resources/self-assessment.html - Blog: https://iwh.gr/en/blog/ - Contact: https://iwh.gr/en/contact.html - Privacy Policy: https://iwh.gr/en/privacy.html - AI Policy: https://iwh.gr/en/ai-policy.html