Under NIS2, a significant incident starts a 24-hour clock to your regulator. We prepare the controls, the evidence and the people behind that answer — readiness consulting for NIS2, DORA and ISO 27001, and security for the AI systems you run.
NIS2 Article 23 — reporting after a significant incident
24 hEarly warning
72 hIncident notification
1 monthFinal report
Assessment you can act on, from people who can build the fix.
Regulatory readiness
NIS2 · DORA · ISO/IEC 27001
We prepare your controls and evidence for the auditor and the regulator. The certificate comes from an accredited body — our job is making sure it finds what it needs.
NIS2 scope and gap assessment
Whether you are an essential or important entity, and how your risk management, reporting and supply-chain duties compare with what you run today.
DORA readiness
Resilience testing, third-party risk registers and incident classification for financial entities and their ICT providers.
ISO/IEC 27001 readiness
Scope, statement of applicability and control implementation aimed at an audit you can pass.
GDPR Article 32 controls
Encryption, access control, retention and breach-notification readiness with named owners.
Securing AI systems
OWASP LLM Top 10 · EU AI Act
Models and agents fail in ways most security programmes were never designed to catch. We build AI systems, so we test them the way they actually break.
LLM application security
Prompt and indirect injection, tool-use privilege escalation and unsafe output handling.
Agent permission design
What an agent may read, write and spend, where a human must approve, and how every action is logged.
Sensitive data leakage testing
Adversarial probing for personal data, credentials and proprietary content in responses and retrieval layers.
EU AI Act readiness review
Classifying each system against the Act's risk tiers, then mapping documentation, logging and oversight gaps.
Architecture and response
STRIDE · MITRE ATT&CK · CIS
The findings that matter most live in the design, where no scanner reaches — and the worst day goes better when its decisions are made in advance.
Security architecture review
Threat modelling across trust boundaries, identity, segmentation and data flows.
Cloud security posture
IAM sprawl, exposed storage and drift between infrastructure-as-code and what is actually deployed.
Incident response planning
Runbooks and regulator-notification templates matched to NIS2 and GDPR clocks, rehearsed in tabletop exercises.
Backup and recovery validation
Restores tested rather than trusted, with recovery objectives written down and measured.
Obligations are cheapest to meet when they are designed in.
Retrofitting residency, audit trails and least privilege costs far more than building with them from the first commit. This is the baseline on every engagement.
EU data residency
EU-region deployment and self-hosted inference for workloads that cannot leave the jurisdiction.
Auditable pipelines
Versioned datasets, reproducible builds and staged rollout — evidence produced as a by-product.
Evidence kept current
Decision logs and control records maintained as you go, not assembled the week before an audit.
Hardened by default
Least-privilege access, managed secrets and signed artefacts as the baseline, not an upgrade.
Four steps, and you can stop after any of them.
1
Introductory call
What you run, what you are accountable for, and what is actually urgent.
2
Scoped assessment
A security gap analysis or AI readiness review against the frameworks that apply to you.
3
Prioritised roadmap
The gaps that matter most, sequenced so your systems keep serving while they close.
4
Delivery, if you want it
The people who wrote the assessment can build the fix. Or your team takes the roadmap and runs.
We are not a certification body. We hold no ISO 27001 or NIS2 certification and cannot issue one. We prepare you for the auditor who can.
Before you write to us.
Does NIS2 apply to my organisation?
NIS2 covers far more sectors than the directive it replaced, and scope depends on your sector, size and the criticality of your service. Establishing whether you are an essential or important entity is the first step of our gap assessment, before any remediation is proposed.
Are you certified under ISO 27001 or NIS2?
No, and we say so plainly. We are a consultancy, not a certification or accreditation body: we hold no certification under these frameworks and cannot issue one. We do the preparation — assessing your controls, closing the gaps and assembling the evidence the accredited auditor or regulator will ask for.
Can you keep our data inside the EU?
Yes. For regulated workloads we design around EU-region infrastructure and, where a third-country model provider is not acceptable, self-hosted open-weights models on infrastructure you control. Which applies is decided with you during architecture, not imposed as a default.
We already have AI in production. Is it too late?
No — it is the more common case. We classify what you run, find where it falls short of the AI Act and your own risk appetite, and sequence the fixes so the system keeps serving while the gaps close.
Do you work across the EU?
Yes. We work remotely with clients across the European Union, the EEA, the UK and Türkiye, and travel for workshops and on-site assessments where the engagement calls for it. Engagements are delivered in English.
Start with a conversation.
Fifteen minutes to establish what you run, what you are accountable for, and what is actually urgent. If an assessment makes sense, a scoped proposal follows.