Services

How we
work with you

Tailored senior support. Practical. Scalable.
Always aligned with your maturity.

Right expertise.
Right time.

One-off outside view or sustained senior support, combined, scaled up, or scaled back as your maturity grows.

Not sure what you need?

Every organisation sits at a different point on the curve. Thirty minutes is usually enough to work out the right fit.

Book an introduction

Coaching for CISOs

Being a CISO is a lonely job. You are expected to be technically credible, commercially fluent, politically astute and calm in a crisis, often without a peer inside the organisation to test your thinking against.

We coach security leaders on the parts of the role that are rarely taught: influencing without authority, communicating risk to non-technical executives, building a board narrative that gets heard, handling pressure during incidents, and growing from technical expert into genuine leader.

Typical formatRegular one-to-one sessions over six to twelve months, with ad-hoc contact when something urgent comes up.
Good fit whenYou have a capable CISO who is stretched, newly appointed, or struggling to land their message at executive level.

CISO support

Sometimes the need is not coaching but capacity and counsel. We work alongside your CISO as an experienced second pair of eyes: reviewing plans before they go to the board, stress-testing risk assessments, helping build business cases, preparing for audits and supervisory reviews, and stepping in during peak periods.

Your CISO stays in the lead. We make their work stronger and their case more persuasive.

Typical formatA fixed number of days per month, plus availability for escalations.
Good fit whenYour security lead is doing the right things but needs experienced backup, or is facing something they have not faced before.

CISO as a Service

Plenty of organisations need a security lead but cannot justify, or cannot find, a full-time one. The role then gets absorbed by an IT manager who already has a day job, or split across people who each own a fragment of it. Nobody is accountable for the whole, and it shows the first time a customer sends a security questionnaire.

We fill the role on a fractional basis, as a named person with an explicit mandate. That means owning the information security management system, maintaining the risk register, setting and maintaining policy, directing the work of internal staff and external providers, acting as the point of contact for customers, auditors and supervisors, and reporting to the board in terms it can act on.

We lead the security function. We do not run security operations: monitoring, tooling, patching and response stay with your own teams or your chosen providers, and we make sure they are properly directed.

Typical formatA fixed number of days per week or per month, with a named individual, an agreed mandate, and a defined reporting line.
Good fit whenYou have no security lead at all, you are between permanent hires, customers are asking who owns security at your organisation, or a certification or regulatory programme needs a single accountable owner.

CSO as a Service: at board level

Not every organisation needs, or can attract, a full-time Chief Security Officer. But almost every organisation needs senior security leadership represented where decisions are made.

We take that seat on a part-time basis: attending board and management meetings, owning the security agenda at executive level, translating between the security function and the business, and holding the organisation to its own roadmap.

This is deliberately a governance role rather than a functional one. A CISO as a Service leads the security function; a CSO as a Service oversees it and represents it at the top table. Neither role runs your security operations.

Typical formatA set commitment per month, including board attendance and quarterly reporting.
Good fit whenYou are growing quickly, facing new regulatory obligations, between permanent hires, or want independent senior oversight of an existing security function.
Which one do you need?

Four services that sit close together

The difference is how much of the role we take on. Click a row to highlight it.

ServiceYou haveWe provide
Coaching for CISOsA security lead who needs to grow into the roleDevelopment for the person
CISO supportA security lead who needs backupCapacity and counsel alongside them
CISO as a ServiceNo security leadThe role itself, fractionally
CSO as a ServiceA function, but no senior voice at board levelOversight and board representation
More ways we help

Guidance, briefings, roadmaps and compliance

Guidance for Information Security Officers

ISOs are frequently handed a mandate far larger than their time, budget or authority. We help ISOs regain focus: cutting the backlog down to what genuinely reduces risk, sequencing work so each step makes the next one easier, defining what "done" means, and building the evidence needed to show progress upward.

Typical formatStructured guidance sessions, often combined with a short assessment.
Good fit whenProgress is hard to demonstrate, or your ISO is spread across too many demands at once.
NIS2 / Cyberbeveiligingswet compliance

The Cyberbeveiligingswet replaced the Wbni on 15 August 2026 with no transition period. A good many organisations were not ready and are working through it now. That is a normal position, not a reason to keep the subject off the agenda.

We help boards get to a defensible position on:

  • Scope. By law, by designation, or not at all, across group entities and member states.
  • Registration. Getting your entity register entry right, and keeping it current.
  • Duties. Translating duty of care and incident reporting into owned, dated actions.
  • Governance. Making sure the management body genuinely approves and oversees the measures.
  • Supervisory contact. Preparing the board for questions from the competent authority.
  • Evidence. Building the record that shows how, and when, you exercised oversight.
  • The chain. Requirements arriving through customer contracts, even out of direct scope.
Good fit whenYou are in scope and behind, unsure whether you're in scope, or being pulled towards the same requirements by customers.
More on the Cyberbeveiligingswet →
Security roadmap development

We assess where you are, agree with you where you need to be, and design the route between the two: phased, budgeted and assigned to owners. Built to be governed: milestones you can track, checkpoints for the board, and flexibility to absorb the things nobody planned for.

Typical formatA structured assessment followed by roadmap design, with optional quarterly reviews.
Strategy and policy alignment

Security policies often accumulate over the years, borrowed from templates and never reconciled with what the company is actually trying to achieve. We review your policy landscape against your strategic goals and reshape it so the two pull in the same direction: tightening what matters, simplifying what does not.

Typical formatA review and rewrite programme, sized to your policy estate.

Let's talk.

Thirty minutes is usually enough to work out whether we can help.

Book an introduction