Cybersecurity & Resilience

Security Strategy, Risk & Compliance

Know exactly where your security stands, which regulations apply to you and what to fix first, with a roadmap your board can follow and auditors can verify.

Is this for you?

You might need this if…

You think NIS2 or DORA applies to you, but nobody can say for certain which requirements you already meet.

Customers and auditors send security questionnaires, and answering them takes weeks of chasing people for evidence.

You have no dedicated CISO, so security decisions end up with whoever in IT has time that week.

Critical suppliers have access to your systems and data, but you have little insight into how they protect it.

What we deliver

What it covers

Maturity assessment and roadmap

We assess your security against a recognised framework such as ISO 27001 or the NIST Cybersecurity Framework and show where you stand. You get a prioritised roadmap that puts the biggest risk reductions first.

Virtual CISO

An experienced security leader joins your management team part-time to own the security programme, report to the board and guide decisions. You get senior leadership without the cost and hiring time of a full-time CISO.

Regulatory readiness

We establish which of NIS2, DORA, GDPR, ISO 27001 and the Cyber Resilience Act apply to you, map the gaps and plan the work to close them. Overlapping requirements are handled once, not separately for each regulation.

Risk and supplier risk management

We set up a practical risk process, from identifying and rating risks to tracking how they are treated, and extend it to your suppliers. Critical third parties are classified, assessed and followed up according to their access and importance.

Policies, governance and audit support

We write policies people can actually follow, define security roles and responsibilities, and prepare the evidence for audits and certification. During the audit itself, we support you through interviews and the follow-up of findings.

Awareness training and phishing simulation

Short, role-based training and realistic phishing campaigns build lasting habits rather than ticking a box. Results show where people need more support and how behaviour improves over time.

Our approach

How we work

01

Assess

Interviews, document review and technical sampling establish your current maturity and which regulations and contractual demands apply.

02

Prioritise

Gaps are rated by risk, effort and regulatory weight, and turned into a roadmap that management can approve and fund.

03

Implement

We help put policies, processes and controls in place, with clear owners, so improvements land in daily work rather than in a binder.

04

Assure

Regular follow-up, internal audits and board reporting show progress and keep you ready for external audits and supervision.

Best practices

What we bring to every engagement

Map once, comply many times

One control framework mapped to NIS2, DORA, ISO 27001 and GDPR avoids duplicated work and conflicting evidence.

Make management accountable

NIS2 places responsibility for cyber risk on management bodies, so leaders need regular reporting they can understand and act on.

Risk-based, not checklist-based

Controls are chosen for the risks you actually face, so effort goes where it reduces exposure most.

Know your crown jewels

Protection starts with knowing which processes, systems and data the business cannot do without.

Tier your suppliers

Suppliers are assessed in proportion to their access and criticality, rather than sending the same long questionnaire to everyone.

Collect evidence as you go

Evidence gathered continuously as part of normal work makes audits routine instead of a last-minute scramble.

Outcomes

What you get

  • A security maturity baseline against a recognised framework
  • A gap analysis for NIS2, DORA, ISO 27001 or other applicable rules
  • A prioritised security roadmap with owners and effort estimates
  • A risk register and a supplier risk process
  • An approved policy set and governance model
  • Board-level reporting on cyber risk

AI-powered

Unleash the power of AI

We offer the possibility of using AI throughout this work: ready-to-use AI tools, or a customised version built for your organisation that can run inside your own infrastructure. In security governance and compliance, AI maps your existing policies and controls against regulatory requirements, drafts policy text and answers to customer security questionnaires, and summarises supplier assessments, so specialists spend their time on judgement rather than paperwork.

Starter offer

NIS2 Readiness Check

A fixed-scope, four-week assessment that confirms whether and how NIS2 applies to you, shows your gaps and gives you a prioritised plan to close them.

Week 1

Scope

Kick-off, clarification of whether you are an essential or important entity, and collection of policies and documentation.

Week 2

Assess

Interviews and review of risk management, incident handling, supplier security and governance against NIS2 requirements.

Week 3

Prioritise

Gaps rated by risk and effort, with quick wins and longer-term measures worked through with your team.

Week 4

Report

Findings, roadmap and a management briefing, including what NIS2 expects of management itself.

You receive

  • Clarity on how NIS2 applies to your organisation
  • A gap analysis against the NIS2 risk-management measures
  • A prioritised remediation plan with quick wins
  • A management briefing on responsibilities and next steps

FAQ

Frequently asked questions

Does NIS2 apply to us?

It depends on your sector, size and role, and in some cases on designation by national authorities. Many organisations are also affected indirectly, because customers covered by NIS2 must manage the security of their suppliers. The NIS2 Readiness Check gives you a clear answer as its first step.

How long does it take to become compliant?

A first assessment usually takes three to six weeks. Closing the gaps typically takes from a few months to a year or more, depending on your starting point and how many regulations apply, which is why we start with the measures that reduce most risk.

Can you help us get ISO 27001 certified?

Yes. We help you build and run the information security management system and prepare for the certification audit. The certificate itself is issued by an independent, accredited certification body, which we can help you choose.

How do you work with our existing IT and security suppliers?

We work alongside them. As your single point of contact, we coordinate specialists from our partner network with your current suppliers, so requirements and responsibilities are clear and nothing falls between the cracks.

Related services

Technology Strategy & Advisory AI Strategy & Governance Identity & Access Management Offensive Security & Testing Incident Response & Cyber Recovery Multi-vendor Service Integration (SIAM)

Let’s strengthen your security governance

Book a free 60-minute idea session. We explore your challenges and opportunities with you, and suggest where to start — with no obligation.