Skip to content

Practice · Cybersecurity & compliance

Cybersecurity & compliance

Security regulation has caught up with security technology: NIS2, ISO 27001, client questionnaires and tender gates now demand evidence, not assurances. Most organisations have more security than they can prove — and less than they assume.

Strategys builds the programme that closes both gaps: ISO 27001-aligned ISMS build-up, NIS2 readiness, risk-based governance and incident preparedness — run by senior specialists who apply the same discipline to our own estate.

Talk to us

Who it's for

When security must be provable

We are most useful when security stops being a purely technical concern and becomes an obligation — regulatory, contractual or reputational. The common need is the same: controls that genuinely run, and the evidence to show it.

  • NIS2 lands on your desk

    Organisations newly in scope of the EU NIS2 directive that must turn Article 21 obligations — risk management, incident handling, supply-chain security — into a working, evidenced programme.

  • Security needs governance

    Companies whose technical security has outgrown its paperwork: policies, risk registers, asset inventories and audit trails that must catch up with — and keep up with — the estate they describe.

  • Clients and tenders ask hard questions

    Suppliers facing security questionnaires, vendor assessments and tender gates who need honest, defensible answers backed by real controls rather than aspirational statements.

How we work

Evidence first, paperwork second

We work control by control against recognised baselines — ISO/IEC 27001:2022 and NIS2 Article 21(2) — and treat evidence as the deliverable: registers, runbooks, test results and change logs that stand up to scrutiny. Where security work meets a wider programme, we pair this with our digitalisation and PMO & delivery practices.

  1. Assess against a real baseline

    A structured gap analysis against ISO/IEC 27001:2022 and, where in scope, NIS2 Article 21(2) — control by control, evidence first, no checkbox theatre.

  2. Prioritise by risk, not by list order

    A risk register on a likelihood/impact basis that tells you which gaps actually matter for your threat model and budget, and which can wait.

  3. Build the ISMS that fits your size

    Policies, roles, asset and access registers, and operating procedures scaled to your organisation — an ISMS people follow, not a binder no one opens.

  4. Prove it works

    Restore tests for backups, incident-response runbooks that have been exercised, change logs with rollback plans, and independent penetration testing on a recurring cycle.

  5. Keep it living

    Review cadence, threat-intelligence and patch workflows, and supplier-risk reviews — so the programme still matches reality a year later, and every answer stays evidence-backed.

Experience

We run what we recommend

Our own operation runs on the discipline we sell: an ISO 27001-aligned, control-by-control self-assessed ISMS, a NIS2 Article 21(2) self-assessment, sequential change management with rollback plans, quarterly backup-restore testing, and independent penetration testing on a recurring cycle. Our consultants bring security-governance and engineering experience from financial services, life sciences, the public sector and manufacturing.

FAQ

Cybersecurity & compliance — questions we get

What is NIS2 and does it apply to my organisation?

NIS2 is the EU directive on network and information security that widens the scope of its predecessor to many more sectors — energy, transport, health, digital infrastructure, manufacturing and their suppliers. If it applies, Article 21 obliges you to run documented cyber-risk management: incident handling, business continuity, supply-chain security, encryption, access control and more. We help you determine scope and build the evidenced programme behind it.

Do you certify us against ISO 27001?

No — certification is issued only by accredited certification bodies. What we do is the substance underneath: gap analysis against ISO/IEC 27001:2022, building the ISMS, and preparing the evidence, so that a certification audit — if and when you choose to pursue one — assesses a programme that genuinely runs. We practise what we advise: our own ISMS is ISO 27001-aligned and self-assessed control by control.

What does a security gap analysis involve?

We review your controls against the ISO/IEC 27002:2022 control set and any regulation in scope — control by control, with evidence, ownership and status per item — and deliver a prioritised, risk-weighted remediation plan rather than a wall of red.

Can you help answer client security questionnaires and tender requirements?

Yes. We prepare honest, defensible answers to vendor assessments and tender security gates, backed by documentation — and where a control is missing, we say so and put a dated commitment behind it. Overstating security in a questionnaire is a contract risk we will not take on your behalf.

Do you run penetration tests yourselves?

Penetration testing should be independent of the people who build and operate the controls. We scope and commission testing with independent specialists, translate the findings into a remediation plan, and verify closure — the same recurring model we apply to our own estate.

How is this priced — do we need a big engagement?

No. Most of this work runs as a focused engagement: a gap analysis with a remediation roadmap, an interim security-governance lead, or a defined ISMS build-up. Senior specialists, embedded or as a small team, across Denmark and the Nordics in Danish, English, Arabic, Urdu and other European languages.

Need security you can prove?

Tell us what regulation, client or incident has put security on the agenda. We will talk you through what a gap analysis would show and what a right-sized programme looks like.

Contact us