Cybersecurity that supports the business — not just the documentation
I connect risk management, ISO 27001, GRC, supplier security, incidents and regulatory requirements into one operational system that can actually be maintained.
What can be improved
Scope is matched to organisational maturity and risk — from a short assessment to a full cybersecurity or compliance programme.
ISO 27001 / ISMS
Scope, context, risk, policies, SoA, roles, internal audits and continual improvement.
GRC and risk
Risk register, metrics, action tracking, management reporting and requirement mapping.
Incidents and resilience
Incident response, escalation, exercises, backups, recovery and business continuity.
Suppliers and supply chain
ICT supplier risk, contractual requirements, onboarding, periodic reviews and monitoring of critical vendors.
Employees are part of the security system — prepare them for phishing, incidents and compliance requirements.
I deliver practical cybersecurity training for employees online and on-site. The standard programme lasts 3 hours and covers cyber hygiene, phishing, social engineering, MFA, secure remote work, incident response, risk and business continuity basics.
When does this training make particular sense?
- after an incident or a series of phishing attempts,
- when implementing NIS2 / uKSC, ISO 27001 or internal security policies,
- before an audit when awareness activity must be evidenced,
- for new employees or entire teams,
- when the organisation wants to raise the baseline level of cyber hygiene quickly.
Cybersecurity and strategic management from first customers to scale.
A startup does not need a corporate compliance system or heavy management process on day one. It needs security controls and decision-making practices matched to its real risk, business model and stage.
I help founders and technical teams decide what must be done now, what can wait, how to prepare for enterprise customers and how to translate strategic goals into specific actions, owners and metrics.
Possible scope
- Security baseline: access, MFA, devices, backup, logging, vulnerabilities and basic cloud standards.
- Enterprise customers: security questionnaires, contractual requirements and security/procurement discussions.
- ISO 27001 / regulation: roadmap, NIS2/uKSC, CRA and supply-chain security where relevant.
- Strategy: objectives, priorities, roadmap, operating model and scaling decisions.
- Business development: B2B offer, partnerships, pipeline, go-to-market and enterprise customer preparation.
- Governance: lightweight management cadence, KPIs, ownership and delivery of key initiatives.
30/60/90 assessment
If the organisation does not need a full programme immediately, start with a focused review and priorities.
- 30 days: identify critical services, assets and major risks,
- 60 days: organise key policies, incidents, suppliers and ownership,
- 90 days: implement priority controls, metrics and a reporting cycle.
Technology + process + ownership
Cybersecurity becomes effective only when technical decisions are connected with business risk and clear accountability. I work across technical teams, management and operational processes.
Understand the service
What is critical for customers, revenue, production or compliance?
Measure risk
Which scenarios have the highest impact and likelihood?
Select controls
Which organisational, technical or operational measure reduces the risk?
Prove operation
Which report, log, test or record shows that the control works?
Cybersecurity consulting — common questions
Does cybersecurity start with tools?
No. Start with critical services, assets and risks. Then select processes and technical safeguards proportional to risk.
How do ISO 27001 and NIS2 / uKSC fit together?
ISO 27001 can provide the ISMS backbone. uKSC requirements are then mapped onto it, including sector duties, reporting and evidence requirements.
Can we start with a short assessment?
Yes. A focused review can identify major risks, process gaps and 30/60/90-day priorities without launching a large programme.
Do you advise startups before enterprise sales?
Yes. This can include security baseline, policies and evidence, customer questionnaires, an ISO 27001 roadmap, strategic priorities, operating model, governance and the B2B sales process.
Need a cybersecurity plan, not another PDF?
Describe the current situation and business goal. We can define a focused assessment or implementation roadmap.