NIS2 Readiness and Implementation
Your board has been briefed on NIS2, and nobody has yet established your scope, the size of the gap, or where to begin.
Applicability, gap assessment, management body governance, the ten risk control domains, incident processes against the notification timelines, supply chain security, and the evidence model, taken through from assessment to delivery.
NIS2 Programme Design
You have your readiness findings, and now the gaps have to become a costed, sequenced programme your board will fund and your teams can deliver.
Translation of diagnostic and gap findings into a delivery programme: workstreams, ownership, milestones, dependencies, investment profile, and the governance and evidence model that carries it through to business as usual.
DORA ICT Risk Support
As a financial entity, you must show supervisors an ICT risk framework that functions in practice.
Governance, critical and important function mapping, third party ICT risk, resilience testing governance including threat-led penetration testing readiness, cloud risk, and remediation oversight.
Cyber Security and Resilience Bill Readiness
The Cyber Security and Resilience Bill will reshape UK obligations, and if you are in scope you need to know what will change and what to prepare.
Assessment of scope, critical suppliers, governance, reporting, resilience, and the organisational changes the Cyber Security and Resilience Bill will demand, aligned with any parallel EU obligations.
Cyber Resilience Act Advisory
Your products with digital elements must meet CRA obligations on a fixed timeline, and your product, engineering, and legal teams each own a piece of the answer.
Product risk governance, secure development responsibilities, vulnerability handling, supplier duties, and the technical documentation and evidence the conformity route requires.
Supply Chain and Third Party Cyber Risk
NIS2 and DORA both place supplier security obligations on you, and your contracts do not yet reflect them.
Supplier criticality assessment, contractual security provisions, concentration risk, due diligence, and the ongoing monitoring process that survives handover to business as usual.
Cross Regulatory Control Frameworks
Several regulations apply to you at once, and running a separate programme for each would multiply your cost and fragment your evidence.
Mapping of common obligations across the regulations and standards that apply to you, into one control framework and one body of evidence.