Ready before the clock starts.

Under NIS2, a significant incident starts a 24-hour clock to your regulator. We prepare the controls, the evidence and the people behind that answer — readiness consulting for NIS2, DORA and ISO 27001, and security for the AI systems you run.

NIS2 Article 23 — reporting after a significant incident
  1. 24 hEarly warning
  2. 72 hIncident notification
  3. 1 monthFinal report

Assessment you can act on, from people who can build the fix.

Regulatory readiness

NIS2 · DORA · ISO/IEC 27001

We prepare your controls and evidence for the auditor and the regulator. The certificate comes from an accredited body — our job is making sure it finds what it needs.

NIS2 scope and gap assessment
Whether you are an essential or important entity, and how your risk management, reporting and supply-chain duties compare with what you run today.
DORA readiness
Resilience testing, third-party risk registers and incident classification for financial entities and their ICT providers.
ISO/IEC 27001 readiness
Scope, statement of applicability and control implementation aimed at an audit you can pass.
GDPR Article 32 controls
Encryption, access control, retention and breach-notification readiness with named owners.

Securing AI systems

OWASP LLM Top 10 · EU AI Act

Models and agents fail in ways most security programmes were never designed to catch. We build AI systems, so we test them the way they actually break.

LLM application security
Prompt and indirect injection, tool-use privilege escalation and unsafe output handling.
Agent permission design
What an agent may read, write and spend, where a human must approve, and how every action is logged.
Sensitive data leakage testing
Adversarial probing for personal data, credentials and proprietary content in responses and retrieval layers.
EU AI Act readiness review
Classifying each system against the Act's risk tiers, then mapping documentation, logging and oversight gaps.

Architecture and response

STRIDE · MITRE ATT&CK · CIS

The findings that matter most live in the design, where no scanner reaches — and the worst day goes better when its decisions are made in advance.

Security architecture review
Threat modelling across trust boundaries, identity, segmentation and data flows.
Cloud security posture
IAM sprawl, exposed storage and drift between infrastructure-as-code and what is actually deployed.
Incident response planning
Runbooks and regulator-notification templates matched to NIS2 and GDPR clocks, rehearsed in tabletop exercises.
Backup and recovery validation
Restores tested rather than trusted, with recovery objectives written down and measured.

Obligations are cheapest to meet when they are designed in.

Retrofitting residency, audit trails and least privilege costs far more than building with them from the first commit. This is the baseline on every engagement.

  • EU data residency

    EU-region deployment and self-hosted inference for workloads that cannot leave the jurisdiction.

  • Auditable pipelines

    Versioned datasets, reproducible builds and staged rollout — evidence produced as a by-product.

  • Evidence kept current

    Decision logs and control records maintained as you go, not assembled the week before an audit.

  • Hardened by default

    Least-privilege access, managed secrets and signed artefacts as the baseline, not an upgrade.

Four steps, and you can stop after any of them.

  1. Introductory call

    What you run, what you are accountable for, and what is actually urgent.

  2. Scoped assessment

    A security gap analysis or AI readiness review against the frameworks that apply to you.

  3. Prioritised roadmap

    The gaps that matter most, sequenced so your systems keep serving while they close.

  4. Delivery, if you want it

    The people who wrote the assessment can build the fix. Or your team takes the roadmap and runs.

We are not a certification body. We hold no ISO 27001 or NIS2 certification and cannot issue one. We prepare you for the auditor who can.

Before you write to us.

Does NIS2 apply to my organisation?

NIS2 covers far more sectors than the directive it replaced, and scope depends on your sector, size and the criticality of your service. Establishing whether you are an essential or important entity is the first step of our gap assessment, before any remediation is proposed.

Are you certified under ISO 27001 or NIS2?

No, and we say so plainly. We are a consultancy, not a certification or accreditation body: we hold no certification under these frameworks and cannot issue one. We do the preparation — assessing your controls, closing the gaps and assembling the evidence the accredited auditor or regulator will ask for.

Can you keep our data inside the EU?

Yes. For regulated workloads we design around EU-region infrastructure and, where a third-country model provider is not acceptable, self-hosted open-weights models on infrastructure you control. Which applies is decided with you during architecture, not imposed as a default.

We already have AI in production. Is it too late?

No — it is the more common case. We classify what you run, find where it falls short of the AI Act and your own risk appetite, and sequence the fixes so the system keeps serving while the gaps close.

Do you work across the EU?

Yes. We work remotely with clients across the European Union, the EEA, the UK and Türkiye, and travel for workshops and on-site assessments where the engagement calls for it. Engagements are delivered in English.

Start with a conversation.

Fifteen minutes to establish what you run, what you are accountable for, and what is actually urgent. If an assessment makes sense, a scoped proposal follows.

Prefer to write? [email protected]

Remote across the EU, EEA, UK and Türkiye. On site for workshops and assessments.

Pick a time for a 15-minute call.

Times are shown by Cal.com, our scheduling provider. It loads only when you ask.

Open the scheduler in a new tab