Phase 1 · The Cyber Diagnostic
Know where you stand
We measure your maturity against the CyberFundamentals framework, whether NIS2 covers you or not, find your blind spots and hand you the roadmap.
Secure your business
With AI, attacks are automated and no longer pick their target. We measure where you stand, then, if needed, we get your company ready: risk management, incident response, crisis exercises, trained teams.
Why
A bot sweeps the internet and finds one of your machines left unpatched. It did not choose you: you were simply there.
It gets in, settles and moves from one machine to the next, without a sound.
Screens show a ransom note. Production, invoicing, email: everything has stopped.
Your client asks what happened. If you are in scope of NIS2, the CCB expects an early warning within 24 hours. And nobody knows who should answer.
A scenario, not a mission. It happens to companies that thought they were too small to be a target.
The question is no longer if. It is when, and whether you will be ready.
What we check
The Cyber Diagnostic follows the CCB CyberFundamentals framework, aligned with ISO/IEC 27001. Six functions, and for each, two questions: is it written down, and is it applied?
1Govern
Security strategy, roles, policies, management involvement (NIS2, Article 20), supplier management.
How we help We hold the security lead role and the committee, minuted every month.
2Identify
Inventory of assets, data and systems, risk assessment.
How we help We keep the risk register and its treatment plan up to date.
3Protect
Access and identities, strong authentication, backups, updates, team awareness.
How we help We steer the action plan and train your teams.
4Detect
Logs kept, alerts defined, a named person to look at them.
How we help We do not monitor for you: we check that monitoring exists and has an owner.
5Respond
Response plan, crisis roles, NIS2 notification (early warning within 24 hours, notification within 72 hours).
How we help We prepare the procedure, exercise it on the table and support you when the day comes.
6Recover
Recovery plan, tested backups, lessons learned after every incident.
How we help We have recovery tested and draw the lessons with you.
Each function comes out with its level, the gap to target and the order of work.
What we do
Phase 1 · The Cyber Diagnostic
We measure your maturity against the CyberFundamentals framework, whether NIS2 covers you or not, find your blind spots and hand you the roadmap.
Phase 2, if needed · CISO as a service
If you want, we hold the role of your security lead: risk management, incident response and management, tabletop crisis exercises, training for your teams, management briefed every month.
How
See
The Diagnostic: your maturity, your risks, your blind spots.
Decide
The roadmap, prioritised with your management.
Get ready
If needed, CISO as a service: procedures, exercises, training, every month.
Already have a recent audit? We start from it.
Contact
What you risk, and where to start. A cyber, AI or transformation diagnostic, or ongoing support as a service: describe your situation and we come back with the step that fits.
Let's talk →We do use AI, but we stay human-focused: a person reads your message and replies within 48 hours. The first thirty-minute call is free of charge.