Service

Implementation

We implement requirements in modules, in the order that follows from the readiness review. You pay for what your organisation really needs.

Modules

  • Security policy and roles

    Who is responsible for what, from the board to IT suppliers.

  • Risk analysis

    Risks to your services and systems, with decisions on how to treat them.

  • Business continuity with a tabletop exercise

    Continuity and recovery plans, tested in an exercise with your team.

  • Incidents and reporting

    An incident handling procedure, reporting within 24 and 72 hours, and the final report.

  • Supplier security

    Requirements for suppliers and how to verify them.

  • Board training

    Management obligations and accountability, in practice.

How we work

  • Documents describe the actual state, not a template for the drawer.
  • We match safeguards to scale and risk.
  • We advise independently of vendors. We do not sell licences or hardware.
  • If you prefer to do part of the work yourself, we offer a package of consulting hours.
  • We do not later carry out a statutory audit of an organisation where we implemented the requirements. This protects the independence of the audit.