Services

Compliance and technical depth, under one roof.

Each service below can run as a standalone engagement or as part of a broader programme. All of them are staffed by the same senior consultants — so a finding from an audit, an architecture review or a compliance gap assessment doesn't get lost between teams.

Directive (EU) 2022/2555 · Regulation (EU) 2022/2554

NIS2 & DORA Compliance

We help essential and important entities under NIS2, and financial entities and their critical ICT third parties under DORA, move from legal text to operating reality.

We work alongside your legal counsel rather than replacing it. Our focus is translating each obligation into technical controls, evidence and processes your team can actually run day to day — not a compliance binder that sits on a shelf.

  • ✓Scope and entity-classification assessment
  • ✓Risk management framework aligned to the applicable regime
  • ✓Incident detection, classification and reporting procedures
  • ✓ICT third-party risk management, including register of information
  • ✓Board and management-body reporting packages
  • ✓Resilience testing support (DORA)

ISO/IEC 27001:2022

ISO 27001 Certification Support

Whether you're pursuing certification for the first time or maintaining an existing ISMS, we support the full lifecycle from scoping through to the certification audit.

We work with the certification body of your choice and prepare your team to answer auditor questions with real, working evidence — not paperwork assembled the week before the audit.

  • ✓ISMS scoping and context assessment
  • ✓Risk assessment methodology and treatment plan
  • ✓Statement of Applicability and Annex A control documentation
  • ✓Policy and procedure drafting
  • ✓Internal audit programme
  • ✓Certification and surveillance-audit readiness

Independent technical & process audit

IT Audit

We conduct independent audits of IT general controls, access management, change management, backup and recovery, and vendor oversight — sized to what your organisation actually needs.

That might be a pre-certification readiness check, a due-diligence audit ahead of an investment or acquisition, or a recurring internal audit function you don't have the headcount to run yourselves.

  • ✓IT general controls (ITGC) review
  • ✓Access and identity management audit
  • ✓Change management and SDLC controls
  • ✓Backup, recovery and business-continuity testing
  • ✓Vendor and outsourcing oversight
  • ✓Prioritised, evidence-backed remediation plan

CIS Critical Security Controls v8

Security Architecture Review

We assess your network, identity, endpoint and cloud architecture against the CIS Critical Security Controls, mapped to the Implementation Group that fits your organisation's size and risk exposure.

The output is a concrete architecture roadmap — what to change, in what order, and why — connecting technical decisions back to the control objectives your compliance obligations require.

  • ✓Architecture and control-coverage assessment against CIS v8
  • ✓Implementation Group (IG1 / IG2 / IG3) scoping
  • ✓Identity, network segmentation and endpoint review
  • ✓Cloud configuration and data-protection review
  • ✓Prioritised, sequenced remediation roadmap
  • ✓Mapping from control gaps to NIS2 / DORA / ISO 27001 obligations

Not sure which service fits?

Tell us what's prompting the engagement and we'll recommend a starting point — no obligation.

Talk to us