How we work
01Strategy and policy
Setting direction, drafting the cyber security policy and having it adopted by the board.
02Risk management
Maintaining the risk register, defining risk appetite and investment priorities.
03Reporting to the board
Regular status, trend and open issues, in language the board understands.
04Running the compliance programme
Tracking deadlines, owners and evidence for each measure, through to verification.
05Incident response
Leadership during an incident and the decision on significance and notification to the competent CSIRT.
What you get
Named responsible person
Policy and strategy
Risk register
Board reporting
Compliance roadmap
Measures of Annex II this service covers
01 Commitment and accountability of those responsible for implementing cyber risk management measures
03 Risk management
11 Incident handling
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.