Our offers

First, know where you stand.Then, the role you are missing.

Three domains, one method: a Diagnostic to see where you stand, then, if needed, a lead as a service to move forward. For each offer: what happens and what you keep.

Diagnostic on quote, fixed before we start. Support on time and means: an envelope agreed together, used as you need. Already have a recent audit? We start from there.

Cyber

Cyber and NIS2

See the page Cyber

Phase 1 · The Cyber Diagnostic

Where do you stand against NIS2, what is management exposed to, and where do you start?

Who it is for
Organisations in scope of NIS2, or suppliers to an entity in scope, that want to know where they stand without an in-house security lead.
Frameworks
The CCB CyberFundamentals (CyFun), aligned with ISO/IEC 27001.

How it runs

  1. 1

    Scoping we confirm whether you are in scope, at which level (Basic, Important, Essential) and on which perimeter.

  2. 2

    Current state interviews and review of your documents, control by control.

  3. 3

    Risk reading we rank the gaps by what they expose the organisation and its management to.

  4. 4

    Target and roadmap together we set the target state and the order of work.

  5. 5

    Debrief to management findings, target and the decisions to take.

What you receive

  • A Diagnostic report with an executive summary
  • Your maturity level per CyFun function, as a radar
  • The list of gaps, ranked by risk
  • An initial risk register
  • A prioritised roadmap with its indicators
  • A debrief to management

Not included

  • Penetration tests and technical scans (through a partner, under mandate)
  • Official certification or verification
Request a Cyber Diagnostic →

Phase 2, if needed · CISO as a service

Who steers your security and answers for it to management?

Who it is for
Organisations, in scope of NIS2 or not, that need a security lead without hiring one.
Frameworks
CyberFundamentals (CyFun), ISO/IEC 27001, NIS2.

How it runs

  1. 1

    Set up we put your security management system in place (policies, roles, risk register).

  2. 2

    Every month risk and control review, action plan follow-up, security committee minuted.

  3. 3

    Incidents a NIS2 notification procedure that is ready, tested and has named people; we support you in handling the incident.

  4. 4

    Exercise and train crisis exercises and cyber, risk and NIS2 training at every level.

  5. 5

    Report indicators presented to management every quarter.

What you keep

  • Your documented security management system
  • The risk register and its treatment plan
  • The CyFun matrix or the ISO/IEC 27001 statement of applicability, up to date
  • The security committee minutes
  • The management dashboard
  • The evidence file for verification or certification

Not included

  • Penetration tests (through a partner, under mandate)
  • Third-party platform licences, paid by the client
Talk about CISO as a service →

AI

AI and the AI Act

See the page AI

Phase 1 · The AI Diagnostic

Which AI is really running in your organisation, with which risks and which obligations?

Who it is for
Organisations whose teams already use AI, or are starting to, without a common framework.
Frameworks
ISO/IEC 42001, the EU AI Act, the NIST AI RMF.

How it runs

  1. 1

    Scoping your role under the AI Act (deployer, provider) and the perimeter.

  2. 2

    Inventory the AI uses and tools actually in place, team by team, including undeclared ones.

  3. 3

    Classification each use ranked by risk and by obligation.

  4. 4

    Gaps and target where you stand against ISO/IEC 42001 and the target state.

  5. 5

    Debrief to management first rules, roadmap and the decisions to take.

What you receive

  • The inventory of your AI uses
  • The risk classification of each use
  • The gaps against ISO/IEC 42001
  • Your first rules: use, data, human validation
  • A prioritised roadmap
  • A debrief to management

Not included

  • Development of custom AI solutions
  • ISO/IEC 42001 certification
Request an AI Diagnostic →

Phase 2, if needed · AI Officer

How do you use AI without exposing the organisation, and in line with the AI Act?

Who it is for
Organisations that use or deploy AI and have no in-house AI lead.
Frameworks
ISO/IEC 42001, the EU AI Act, the NIST AI RMF.

How it runs

  1. 1

    Set up AI system register, rules on use, data and human validation, decision path.

  2. 2

    Every month register update, qualification of new tools requested by teams, AI committee minuted.

  3. 3

    Train AI literacy for the teams concerned (AI Act, Article 4) and leadership training.

  4. 4

    Report AI risk review and indicators presented to management every quarter.

What you keep

  • The AI system register, up to date and dated
  • Signed qualification records
  • The AI committee minutes
  • The management dashboard
  • The regulatory watch note applied to your context

Not included

  • Custom AI development
Talk about the AI Officer →
AI trainingTrain your teams first?In-house AI training, built for Article 4 of the AI Act, has its own page: programme, formats and prices.See the training

Transformation

Digital transformation

See the page Transformation

Phase 1 · The Transformation Diagnostic

Where does your data create value, what is holding you back, and in which order should you move?

Who it is for
Leadership teams that want digital and data to drive growth, not just compliance.
Frameworks
The 6 ProHacktiv pillars (strategy, governance, people, process, data, technology), derived from the MIT Chief Digital Officer programme.

How it runs

  1. 1

    Listening interviews with management and teams about where you want to go.

  2. 2

    Mapping your organisation, its flows and its data, as they really work.

  3. 3

    Reading on the 6 pillars we start from the weakest pillar, not the loudest one.

  4. 4

    Target and roadmap the target state and the first measurable milestones.

What you receive

  • The map of your organisation and its flows
  • The problem statement to solve
  • Your maturity read across the 6 pillars
  • Use cases prioritised by value and by risk
  • A roadmap in measurable milestones

Not included

  • Custom development (your teams or selected partners build)
  • Third-party software licences
Request a Transformation Diagnostic →

Phase 2, if needed · CDO as a service

How do you turn a five-year vision into clear, measurable milestones?

Who it is for
Leadership teams that want digital, data and AI to truly serve their business, without hiring a CDO.
Frameworks
The 6 ProHacktiv pillars, derived from the MIT Chief Digital Officer programme; a monthly improvement cycle (PDCA).

How it runs

  1. 1

    Envision the future described first, then the path to get there.

  2. 2

    Design the target organisation and a focused pilot, never a big bang.

  3. 3

    Lead delivery your teams or partners we select build; we answer for the direction taken.

  4. 4

    Every month review of what was planned, done, measured and corrected; decision on the next use cases.

What you keep

  • The vision document and its principles
  • The target architecture and the pilot plan
  • The prioritised roadmap
  • The indicator dashboard and its monthly reviews
  • A team able to carry on without us

Not included

  • Custom development
  • Third-party software licences
Talk about CDO as a service →

Contact

Let's talk.
Know where you stand.

What you risk, and where to start. A cyber, AI or transformation diagnostic, or ongoing support as a service: describe your situation and we come back with the step that fits.

Let's talk →

We do use AI, but we stay human-focused: a person reads your message and replies within 48 hours. The first thirty-minute call is free of charge.