Opinion on applicability and scope
Objective confirmation of scope: entities, services, and Critical/Important Functions (CIFs), dependencies, and programme boundaries.
Applicability assessment + gap assessment and a practical roadmap (30-60-90 days + 6–12 months) with evidence ready for supervision and auditing.
Ideal for Compliance, Risk, IT, Security, Operations, and Management teams that need to confirm obligations, quickly reduce risk, and prepare evidence (both internally and for supervision).
Objective confirmation of scope: entities, services, and Critical/Important Functions (CIFs), dependencies, and programme boundaries.
Map of gaps and priorities by risk: governance & ICT risk, incidents & reporting, resilience testing, ICT third parties, and evidence.
Critical actions with owners, deadlines, and minimum evidence to gain control and reduce exposure quickly.
Realistic sequence of implementation, testing, and remediation — without document overload and with a focus on execution.
Templates for policies/procedures, incidents, reporting, ICT third parties, records, and KPIs for supervision/auditing.
Guided delivery of results, internal alignment, and definition of the execution plan (team, decisions, and schedule).
Checklist + essential evidence per pillar (governance/ICT risk, incidents, testing, ICT third parties, and threat intelligence).
Simple, guided, deliverable-oriented process — with evidence and priorities by risk/effort.
Actual perimeter (CIFs + dependencies), risk priorities, incident readiness and reporting, ICT third-party control (contracts, records, monitoring, exit plans) and organised evidence for supervision/auditing.
Quick answers to the most common questions before proceeding.
Typically 5 working days after the initial call and receipt of the minimum evidence required.
No — it is an actionable diagnosis with gaps, priorities, and a roadmap, accompanied by templates and recommended evidence.
Poorly defined perimeters/CIFs, third-party contracts without clauses/exit plans, incidents without quick classification, and scattered evidence.
Yes. We can execute the 30-60-90 plan and the 6–12 month roadmap, including incident playbooks, testing, and third-party ICT pack.
Fill out the form (recommended) and/or schedule a 30-minute call on Calendly. We will respond within 24 business hours.
By submitting the form, you authorise contact in response to your request. See the Privacy Policy.