Skip to content

Everyone Deserves to Be Secure

Security within reach of every organisation

NIS2 and KSC audits (KSC is the Polish act implementing NIS2), maturity assessment and training for healthcare and regulated sectors. Advisory only, independent of vendors.

Critical, yet small

Small and medium organisations are the backbone of the European economy, and many of them perform critical roles despite limited resources, from healthcare, through transport, to the safety of medicines.

  • A critical role

    Organisations whose smooth and secure operation matters to others.

  • Limited resources

    Without the large security departments found in major corporations.

  • A proportionate approach

    Safeguards matched to real risk and scale, not overdone.

That is why we do not propose solutions tailored for large corporations, but select safeguards in proportion to real risk. Internally, our own security management system is based on ShieldNet, a framework we created, and we recommend it to smaller organisations for its scalability and its fit with the realities of the SME sector. ShieldNet is not a regulatory requirement. We work with public and private organisations, in Poland and across Europe.

How we help

We help organisations prepare for the requirements of NIS2 and KSC and manage risk consciously, from assessing the current state to training the team. We work in an advisory capacity, neutral towards vendors.

We focus on preparation, standards and knowledge. We do not provide operational security services such as SOC, SIEM or 24/7 monitoring, which is how we remain an independent, objective adviser to your organisation.

We understand healthcare

We specialise in the cybersecurity of healthcare, understood broadly: from care providers, through laboratories and diagnostics, to the availability of medicines and medical technologies.

Healthcare is a complex, interdependent organism in which the weakness of one link becomes a risk for the others.

  • Patient data

    Protection of medical data in line with the GDPR and the requirements of the EHDS, without making the work of staff harder.

  • Continuity of care

    Preparation for incidents so that an attack or a failure does not interrupt the treatment of patients.

  • Medical devices and equipment

    Cybersecurity of medical hardware and technologies in line with the requirements of the MDR.

We treat security as support for doctors, nurses and management, not as another burden.

Why you can trust us

We will not show our clients' logos here, because in the same way we would not show yours. We build our credibility differently: through knowledge, experience and genuine commitment to the security of the sectors we serve.

  • Knowledge confirmed by publication

    Our founder is the author of a book on implementing NIS2 in Poland, published by INFOR. We do not explain the rules at second hand, we help shape the way the market understands them.

  • Genuine commitment, not only commerce

    We coordinate ASCLEPIUS, a European project strengthening the cybersecurity of healthcare entities, committing our own resources to it. We treat the security of the health sector as a mission, not only as a service.

  • Competence confirmed by certifications

    Our team consists of auditors with recognised certifications, including CISA as well as ISO 27001, ISO 42001 and ISO 22301 Lead Auditor. We know the standards inside out, which is why we know which requirements your organisation genuinely needs and which would be excessive.

  • Present where the rules are made

    We take part in regulatory consultations and working groups at European level, from NIS2 and KSC to the EHDS and the MDR. Thanks to this our advisory work anticipates change instead of catching up with it.

"We recommend IS Consulting as a competent advisory partner in assessing and building compliance with the KSC, cybersecurity audits, training and preparation for supervisory requirements."
Director of a specialist hospitalTestimonial translated from Polish.

Work for the community

Beyond our advisory work we engage in the security of the whole market, independently of our commercial activity. We share knowledge and help shape regulation.

  • Influence on regulation

    We comment on legislative initiatives and take part in working groups at national and European level, from NIS2 and the CRA to the EHDS and the MDR. We prepare recommendations for regulated sectors and for small and medium companies.

  • Knowledge and publications

    Our founder is the author of a book on implementing NIS2 in Poland, which helps shape the way the market understands the new rules. We also publish sector reports on the state of cybersecurity, among others in healthcare and on the railways.

Let us talk about the security of your organisation

You do not need to be ready for a large project. A conversation about where you are and what the law requires of you is enough. We will help you plan realistic, workable steps.

Email
contact@isconsulting.pl
Address
ul. Żelazna 51/53, 00-841 Warszawa, Poland