NIS2 readiness & implementation
We assess where your security program stands against the NIS2 measures, help you close the gaps, and implement the controls, so that readiness can be demonstrated through operations, not assurances.
ISO 27001 as your foundation
The smartest way to handle overlapping EU rules is to build one strong ISMS and map the rest onto it. We help you build and operate an ISO 27001-based information security management system including documented controls, risk treatment, monitoring; and then map NIS2, DORA and GDPR onto the same foundation, so you invest once instead of running parallel programs.
GDPR Article 32: security of processing
Data protection isn’t only privacy: Article 32 requires technical and organizational measures appropriate to the risk. We help you plan and implement the security side of GDPR: encryption, access control, resilience, and the ability to restore data after an incident, so your personal-data security is built and evidenced.
Financial-sector resilience
If you’re a financial entity or a critical ICT provider serving one, DORA and other framworks prescribes not just what to do but which documents to keep. We help you build the ICT risk management framework, the incident reporting flow, and the third-party controls; and if you’re a vendor, we get you ready for the DORA questionnaires your financial clients will send.
Product security
If you make products with digital elements, the frameworks like the CRA will govern their security across the lifecycle: secure development, vulnerability handling, and SBOMs. We help you build security into the product and prepare the technical documentation, so your product meets the baseline the target market demands.
Technical & organisational measures (TOMs)
Underneath every framework sits the same question: which measures do you actually run, and can you prove it? We design and implement the concrete controls including access management, encryption, logging, segmentation, backup and recovery, and produce the evidence trail.
Incident response & resilience testing
The frameworks converge on one demand: detect early, respond in a structured way, report accurately and on time. We build your incident response capability and test it, so the 24-hour, 72-hour and financial-sector clocks are met by a trained team.
Forensic-readiness & logging review
We assess whether your logging can prove the scope of a breach to a regulator and satisfy accountability, and whether the logs themselves carry excess personal data that creates a new liability. We help you set forensic-readiness requirements up front: which events to log, in what format, with what integrity, retention and masking.
Access control & least-privilege review
We review who can reach which systems and data, and assess it for excess against least-privilege: standing privilege, orphaned accounts, vendor access that outlived its contract, over-broad access to regulated data and production. We give you a prioritised map of over-permissioned access and a path to least privilege, covering privileged and non-human (service account, AI agent) identities.
Supply-chain security & vendor assessment
We build your third-party risk management: classify vendors by criticality, assess them before signing, embed security clauses and breach-notification duties into contracts, and maintain the register of ICT contracts. We help prepare SBOMs and CRA-readiness so your product and supply chain meet the baseline the target market demands.