EXPERTISE / GRC
Risk & governance
Link security investment to business consequences and genuinely applicable requirements, then organise decisions.

WHAT TO ADDRESS
Choose the right engagement.
The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.
8 results
GRC-01 / Risk & governance
EBIOS Risk Manager risk assessment
A structured method linking business objectives to cyber-risk scenarios and a treatment plan decided by the organisation.
GRC-02 / Risk & governance
EBIOS 2010 review and transition to EBIOS RM
Updating a legacy EBIOS 2010 assessment or supporting its transition to EBIOS Risk Manager without treating the versions as interchangeable.
GRC-03 / Risk & governance
ISO/IEC 27001 and ISMS implementation support
Establishing an information security management system: responsibilities, risks, controls, evidence and continual improvement, with optional certification preparation.
GRC-04 / Risk & governance
NIS 2 readiness and security improvement plan
Support to assess potential NIS 2 applicability and develop relevant technical, organisational and evidence-based security measures.
GRC-05 / Risk & governance
DORA and ICT risk-management support
Support for digital operational resilience at in-scope financial organisations and for evidence requested from their ICT providers.
GRC-06 / Risk & governance
Fractional CISO and cybersecurity governance
Recurring executive support to manage security risks, priorities, projects and decisions without immediately hiring a full-time CISO.
GRC-07 / Risk & governance
Security policies, procedures and project governance
Defining understandable, enforceable rules for access, usage, operations and security decisions within projects.
GRC-08 / Risk & governance
Third-party and supply-chain risk management
Assessing risks introduced by external providers, software and services according to their access and business importance.
No matching results. Try a broader term or another family.
SET THE BOUNDARIES
What we agree
before we start.
- Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.
- Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.
Technology names in service descriptions are implementation examples, not claims of partnership or licence entitlement.
START A CONVERSATION
Let’s put the next step in focus.
Tell us what you need to protect, change or understand. We will start with the scope, not a product list.
