Cybersecurity and Compliance

We reduce the attack surface and get you to a defensible position against NIS2 and GDPR technical requirements.

Most security incidents we investigate involve nothing sophisticated. The entry point is a reused credential with no second factor, a management interface exposed directly to the internet, a server that has not been patched in a year, or an administrator account still active months after the employee left. Attackers take the cheapest available path, and in most organisations that path is still wide open.

How we approach security

We begin with a technical assessment of the real environment rather than a questionnaire. That means scanning the internet-facing surface, reviewing server and network device configurations, examining access rights and privileged credential handling, and checking patch state against actual exposure. The output is a list of findings with estimated impact, not an abstract maturity score.

Remediation is sequenced by real risk. Multi-factor authentication on every administrative path, removing unnecessarily exposed services, clearing the patch backlog and segmenting the network address the large majority of practical exposure. More advanced controls make sense once that foundation exists. Deploying an expensive detection platform on top of unpatched infrastructure buys alerts about compromises you could have prevented.

For access control we move progressively toward a Zero Trust model: access granted per application and verified on each request against identity and device posture, rather than a flat internal network where anyone who gets in can see everything. Remote access is almost always the first phase, since the benefit is immediate and the disruption is contained.

NIS2 and GDPR readiness

NIS2 has been transposed across EU member states and imposes concrete technical and organisational measures on essential and important entities, along with tight incident reporting deadlines. We establish whether and how you are in scope, run the gap assessment against the required measures, and build a remediation plan with realistic dates rather than aspirational ones.

The areas assessed most closely are risk management, supply chain security, access control, vulnerability handling, business continuity and a demonstrable ability to detect and report incidents. For each one you need both the implemented control and evidence that it works, because assessors ask for both and the second is where most organisations fall short.

On GDPR we handle the technical side of security of processing under Article 32: encryption at rest and in transit, access control and logging around personal data, retention and deletion, and the detection capability required to meet the 72-hour breach notification window. We work alongside your data protection officer or legal counsel, who own the documentary side.

Who this is for

We work with organisations that have just discovered they are in NIS2 scope, with suppliers facing security requirements imposed contractually by a large customer, with companies that have been through an incident and intend not to repeat it, and with businesses preparing for ISO 27001 certification who need the technical controls in place before the audit.

Requests come most often from manufacturing, distribution, private healthcare, transport and digital service providers, which reflects how the directive widened its sectoral scope.

Why an EU provider matters here

Security work involves privileged access to your systems and visibility into your data. Contracting an EU-based provider keeps that relationship under EU law, simplifies the processing agreement and removes the third-country transfer analysis that otherwise accompanies granting administrative access. Our engineers work European hours, which matters during an incident when response time is measured in minutes.

What you end up with

The result is an infrastructure with a materially smaller attack surface, written policies that match how the organisation actually operates, and an incident response plan your team has rehearsed at least once rather than read once. The documentation supports your audit directly, and findings are tracked to closure rather than simply reported and filed.

Frequently asked questions

How do we know whether NIS2 applies to us?

Scope depends on your sector and on size thresholds for headcount and turnover, applied through each member state's national transposition. Many companies are also pulled in indirectly as suppliers to a regulated entity that passes obligations down contractually. Establishing your actual position is the first step of any engagement.

How long does compliance readiness take?

For a mid-sized organisation starting from typical maturity, four to nine months to implement the essential technical measures. The gap assessment itself takes two to three weeks; the rest is real implementation work. Anyone promising compliance in a fortnight is selling documents rather than security.

Does Zero Trust mean replacing everything we have?

No, and attempting that at once usually fails. It is implemented in stages, normally starting with remote access, which is both the most exposed and the easiest to improve. Replacing a flat network VPN with per-application access verified on every request delivers the largest risk reduction for the smallest effort.

Do you carry out penetration testing?

We perform technical vulnerability assessments and configuration reviews, which cover most needs. For formal penetration tests, often required by customers or auditors, we work with independent specialist firms. We think it is right that whoever remediates the findings is not also the party signing the test report.