Back to Compliance you can evidence
Know where you stand before you spend
We measure your environment against the requirements that actually apply to you and deliver a prioritised action list with effort estimates, rather than a collection of references to legislation.
30 minutes · no sales pitch · an honest read on whether we fit
A fit when
- You have a NIS2 deadline and no gap analysis yet
- Your customers increasingly ask for security evidence
- You need a defensible basis for a security budget
- An audit is coming and you want to know beforehand what will be found
The situation
- It is unclear whether and to what extent NIS2 applies to you, and the deadline runs anyway.
- Customers send security questionnaires that cost time every week and get answered from scratch each time.
- Controls exist, but there is no evidence that they work.
- Nobody has the incident reporting deadlines in mind, and the process was never practised.
What we do
We start with which requirements actually apply to you, then check your environment against them: identity, endpoints, network, backup, suppliers and reporting paths. The result is a gap list in which every line has an effort, an effect and an owner, plus a short version for the board that enables a decision rather than postponing one.
What is included
- 01Applicability checkWhether NIS2 applies to you, in which category, and what reaches you additionally through the supply chain.
- 02Gap analysis of the environmentA technical comparison rather than a questionnaire: what is configured, what is effective, what is missing.
- 03Prioritised action listEvery action with effort, effect and owner, ordered by risk rather than by convenience.
- 04Version for the boardA short paper with the decision required, a budget frame, and the consequences of doing nothing.
What you end up with
Documented applicabilityPrioritised action list with effortA paper for the boardA practised reporting path
Request a briefingA reply within 1 business day, from a person.