A field approach, evidence-oriented.
Human-scale firm: transparency, communication and useful advice. 2026 cyber expectation: traceability, risk prioritisation, and executable decisions.
What guides every engagement
- Proportionality — controls sized to real scale and risk
- Clarity — deliverables understandable outside IT
- Evidence — every measure leaves usable evidence
- Independence — advice comes before selling equipment
- Continuity — we train your teams to last after we leave
For whom?
Belgian SMEs and mid-market, structured associations, public actors and service operators — including those discovering NIS2 via a client or contracting authority.
We work in French (Dutch on request), on site or remotely.
Four phases, one line of accountability
Understand the context
Short interviews, document review, mapping of services and supply chain. Goal: know what is critical and what actually applies.
Measure the gaps
Structured gap analysis, maturity scoring, effort estimate. You get an executive view and an operational view — without budget surprises.
Implement
Governance, policies, technical controls, exercises, optionally hardware and AI tools / agents. We co-steer with your IT / CISO / leadership.
Demonstrate & improve
Evidence pack, KPIs, tabletop, retests. Compliance becomes a rhythm, not a last-minute sprint.
What you keep
| Deliverable | Use |
|---|---|
| Applicability & gap report | Align leadership, legal and IT on the same findings |
| Budgeted roadmap | Decide 90 / 180 days with clear milestones |
| Policies & registers | A living document base, not a dead binder |
| Evidence pack | Respond quickly to an audit, client or authority |
| Test / exercise reports | Show that controls actually work |
Want to see the method on your case?
A 30-minute call is enough to frame the first milestone.