Virtual CISO, AI governance & security, regulatory compliance, internal audit, and training & awareness — five service lines, one accountable practitioner, sized for SMBs across the EU. Each service stands alone or composes into a single ongoing engagement.
Fractional security leadership embedded in your business. We set strategy, manage risk, report to your board, and own ongoing compliance — at a fraction of the cost of a full-time CISO.
EU AI Act compliance, ISO/IEC 42001 readiness, and AI-specific security controls — for SMBs deploying, building, or shipping AI features on foundation models. Four sub-services covering deployer, provider, and GPAI integration routes, scoped to your AI estate.
EU AI Act compliance across deployer, provider, and GPAI integration routes
AI risk methodology aligned to ISO/IEC 23894
Security overlay: OWASP LLM Top 10, MITRE ATLAS, ENISA AI threat landscape
ISO 42001 substrate mapped from Phase 3 — certification is assembly, not rework
NIS2, DORA, GDPR, ISO 27001, PCI DSS, ISO 27701 and the rest of the EU stack. Gap analysis, policy build, audit preparation, and ongoing maintenance — turning complex obligations into a clear, achievable program.
Scoping and applicability assessment per framework
Gap analysis with prioritised, costed action plan
Policy & control implementation oversight
Audit preparation and certification-body coordination
Independent, certified internal audits — ready for external review. Led by PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditors. Scoped to ISO 27001, ISO 42001, NIS2, GDPR, DORA, PCI DSS, ISO 27701, or your own internal policies.
Scoped audit programme and on-the-ground execution
Conformance assessment with evidence references
Executive summary written for the board
Prioritised corrective action plan with owners and timelines
Practical training and phishing simulations that move your team from your weakest link to your first line of defence. Compliance-mapped to NIS2, DORA, GDPR, ISO 27001, and PCI DSS awareness mandates.
Foundation security awareness modules — short, plain-language
Monthly phishing simulations with auto-followed micro-training
Role-based training for finance, executives, HR, IT
Tabletop exercises and executive / board briefings
Senior practitioners on every engagement. CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor, ISO 27001 Lead Implementer, EU GDPR Data Protection Officer — held by the people doing the work.
SMB-first by design
Built from the ground up for lean teams, real budgets, and actual deadlines. No enterprise bloat. No 200-page policy libraries.
Executive scope, honest pricing
Governance, strategy, audit. Technical implementation stays with your IT function — under our supervision. Fixed fees, no hourly tracking.
Compliance frameworks
Twelve frameworks & regulations, covered.
NIS2, DORA, EU GDPR, EU AI Act, Cyber Resilience Act, ISO 27001, ISO 42001, ISO 27701, DPO as a Service, PCI DSS, EU Cybersecurity Act, Data Governance Act. Each has its own deep-dive page with key requirements, penalties, our approach, and a typical timeline.