10 questions before choosing a consultancy for NIS2, GRC and CISO support

10 questions to ask before choosing a consultancy for NIS2, GRC and CISO support

The right consultancy for NIS2, GRC and CISO support is about more than paper credentials. 10 questions to help you choose well – and avoid unclear engagements.

Summary: Choosing a consultancy for information security is about more than paper credentials – it is about who does the work, how it is led and whether the advice can be put into practice. Here are ten questions to help you choose the right partner for NIS2, GRC, ISO 27001 and CISO support.

Choosing a consultancy for information security and regulatory compliance is not only about credentials on paper. It is just as much about who actually does the work, how the work is led and whether the advice can be put into practice.

Many organisations need support with NIS2/the Swedish Cybersecurity Act, ISO 27001, GDPR, GRC or CISO matters. But the needs differ. Some need a clear current-state analysis. Others need help getting governance to work in everyday life. Some need an interim CISO or ongoing senior support for management, IT and the business.

Here are ten questions to help you choose the right partner.

1. Who will actually do the work?

It is common for the most senior person to attend the sales meeting, only for the work to then be handed over to other consultants. That is not necessarily wrong, but it should be clear from the start.

Always ask to know who will actually carry out the analysis, run the workshops, write the recommendations and support the implementation.

Our view is simple: senior expertise should stay close to the engagement, not just at the beginning. With us, the aim is that you know which people you are working with and that the same consultants stay with you throughout the engagement.

2. How do you ensure continuity?

Information security and GRC rely heavily on understanding the business. When consultants are replaced too often, context, history and relationships are lost.

A good partner should therefore be able to show how continuity is ensured. That can involve documentation, shared engagement management and having more than one person familiar with the work.

We try to work so that at least two people have insight into the engagement. That gives both redundancy and quality, without you losing the personal relationship with the senior consultant who drives the work forward.

3. Do you have experience from our type of operations?

Information security looks different depending on sector, maturity and regulatory environment. A bank, a healthcare company, an industrial company and a SaaS company may all need to work with risk, incidents and suppliers, but the challenges are not the same.

What matters is not that the consultant has done exactly the same thing before, but that they understand how regulation, risk and the business fit together.

For us it is central not just to read the requirements, but to understand how they affect the organisation’s actual ways of working. That is why we often start with the current state, responsibilities, existing processes and the operational risk picture before we recommend measures.

4. Do you deliver only analysis, or implementation too?

A gap analysis can be valuable. But if it just becomes a report of deficiencies, it rarely changes much.

Good consulting support should be able to help you from analysis to actual governance: priorities, ownership, a timeline, decision support, governance documents, procedures and follow-up.

Our approach is that an analysis should always be usable. Every significant gap should be tied to a recommended action, a priority and a next step. The goal is not to create more documents, but to help the organisation move forward.

5. How do you work with risk prioritisation?

Not all gaps are equally important. Some deficiencies can mean high risk for the business, the customers or compliance. Others are improvement areas that can be handled later.

A good partner should be able to help you distinguish between what is critical, what is important and what can wait. Otherwise there is a risk that everything becomes equally urgent, which often means nothing gets finished.

We prefer to work risk-based. That means we weigh together requirements, threat landscape, business impact, maturity and feasibility. The result should be a prioritised plan, not a long list where everything looks equally important.

6. Are you independent?

Independence matters when you want advice based on your business, not on a particular product, platform or group solution.

A consultancy can be highly competent yet still have commercial ties that influence its recommendations. It is therefore reasonable to ask whether the provider is independent, and whether it profits from recommending certain tools, products or implementations.

Kristensson i Skåne is a smaller, independent consultancy. Our role is to help you understand what is needed, what is reasonable and what should be prioritised. Sometimes that may mean new tools or technical measures, but that should not be the starting point. The starting point should be risk, need and business value.

7. What does the pricing model look like?

Different engagements require different pricing models. Sometimes ongoing advisory fits best. Sometimes a defined project is better. In other cases interim support is needed for a period.

What matters is that the pricing model matches your need and that it is clear what is included. Unclear arrangements often lead to misunderstandings about expectations, deliverables and responsibilities.

We try to be clear about whether the engagement is about analysis, advisory, implementation, ongoing support or a combination. For us it is more important to find an arrangement that works over time than to force every client into the same model.

8. Can you support both management and technology?

Information security often sits between several worlds: the board and management, IT, legal, procurement, the business, data protection and sometimes external suppliers.

The consultant therefore needs to be able to shift levels. Sometimes clear decision support for management is required. Sometimes a detailed dialogue with IT about logging, backup, access, incident handling or technical controls is needed.

Our strength lies in connecting governance and practice. The security work needs to be understandable for management, but concrete enough to be carried out by IT and the business.

9. Do you offer CISO support or interim leadership?

Many organisations know they need CISO support but are unsure of the form. Is an interim CISO who steps in operationally needed? Or is senior advisory to an existing security lead, IT manager or management team enough?

It is important to sort this out before the engagement starts. Otherwise there is a risk that expectations differ.

We can support both as advisory GRC/CISO support and in more operational roles, for example through Manager as a Service. That can be relevant during a temporary leadership gap, ahead of a larger security programme, or when the organisation needs to build up ways of working before a permanent role is in place.

10. Can you show relevant examples?

References, anonymised cases and examples of similar engagements make it easier to understand how the consultancy actually works.

It does not always have to be public client names. In many security engagements it is natural for details to be confidential. But the consultant should still be able to describe the type of engagement, sector, problem, approach and outcome at a level that lets you assess the experience.

We are happy to share relevant examples where possible, often anonymised. What matters is that you get a picture of how we move from current state to prioritisation, governance and practical implementation.

In summary

The right consulting partner should not only know the regulations. They should be able to help you understand what the requirements mean in practice, what is most important to start with and how the work can be anchored in the organisation.

For us, good information security work comes down to three things:

  • a clear current-state picture
  • risk-based priorities
  • practical governance you can follow up

Only then do NIS2, GRC, ISO 27001 and CISO support become more than a report or a project. They become part of how the organisation actually governs, protects and develops its operations.

Would you like to discuss what the right support could look like for your organisation? Read more about our work with information security and governance or contact us and we will gladly have a first conversation.