Security strategy and governance
Information security management systems, regulatory readiness and board reporting for NIS2, DORA, FINMA and ISO/IEC 27001.
Many organisations now fall under more than one regime at once. A German manufacturer may be an important entity under the NIS2 implementation act and also certify to ISO/IEC 27001:2022. A Swiss bank with an EU subsidiary answers to FINMA Circular 2023/1 at home and to DORA in the EU. We map those obligations against each other, find where one control can serve several requirements, and build a management system that people actually run.
Governance work also covers the people who sign off on risk. NIS2 makes management bodies responsible for approving and overseeing cybersecurity measures. We prepare risk reports, decision papers and training that give boards and executive committees a clear basis for those decisions.
Typical deliverables
- Applicability assessment for NIS2, DORA, FINMA Circular 2023/1 and the Swiss FADP
- Gap analysis and remediation roadmap against ISO/IEC 27001:2022
- Information security policy framework, roles and risk methodology
- Management reporting format and board briefing on cyber risk