Concrete engagements with clear deliverables
Every offer describes who it suits, what is included, how the work is done and what you get. All of them are gathered here by service area. If you would rather start from your industry, that section is at the bottom.
Information security and governance
About the service area →Gap analysis and current-state analysis
Your current state against NIS2, CRA, DORA, GDPR or ISO 27001. A decision basis with identified gaps, prioritized risks and a concrete action plan.
Read more → Ongoing supportSenior GRC advisory
A coherent structure for governance, risk management and compliance. Clear responsibilities, working processes, relevant controls and regular follow-up.
Read more → ImplementationISO 27001 from gap analysis to certification
A management system that works in practice. Risk work, governing documents, Statement of Applicability, internal audit and preparation for certification.
Read more → Swedish Cybersecurity ActManagement cybersecurity training
The Swedish Cybersecurity Act makes security a management responsibility, and from 1 October 2026 regulations on security measures and management training apply.
Scope: Defined engagement, half a day plus preparationRead more → Business continuityBusiness continuity management and exercise
What happens if a critical service is down for three days?
Scope: A few days to a week depending on scopeRead more → Classification modelInformation classification
Security work that does not know which information matters ends up either too expensive or too thin.
Scope: A few days to a week depending on scopeRead more →Data protection and privacy
About the service area →External data protection officer (DPO)
We act as, or support, your data protection officer: day-to-day questions, follow-up, data subjects’ rights and reporting to management.
Read more → AnalysisGDPR current-state and gap analysis
Where do you stand against the GDPR today? A documented current state, identified gaps and a prioritized action plan that management can decide on.
Read more → Projects and systemsData protection impact assessments (DPIA)
DPIAs for high-risk processing, and privacy built into projects, systems and procurement from the start.
Read more →Management as a service
About Manager as a Service →Interim CISO and CISO support
Senior security expertise, clear governance and practical progress, adapted to your organization’s risks, regulatory requirements and existing organization.
Read more → Interim or ongoingIT manager as a service
Responsibility for IT operations and IT strategy, integrated into your organization. Steady leadership in everyday work and in the projects that move the business forward.
Read more →IT services and advisory
About the service area →Microsoft 365 Health Check
Security review and hardening of your Microsoft 365 environment: Entra ID, Conditional Access, Intune, Defender, Purview and Secure Score.
Read more → Ongoing operationsIT operations as a service
Network, backup, monitoring and support with clear responsibility. Proactive management and reactive support as a long-term service commitment.
Read more → As part of the engagementHardware, software and licences
We select, procure, implement and manage equipment, software and licences as part of our engagements. The right requirement first, then the right product. Not a shop.
Read more →Cybersecurity and technical security
About the service area →Vulnerability assessment and penetration testing
Find the weaknesses before someone else does.
Scope: Defined engagement, about a weekRead more → Incident planIncident preparedness and tabletop exercise
An incident plan that works when it matters, and an exercise that shows it does.
Scope: Defined engagement, a few daysRead more → Cyber Resilience ActCRA readiness for product companies
If you sell products with digital elements on the EU market, the Cyber Resilience Act applies to you.
Scope: A few days to a week depending on the portfolioRead more →Assurance and internal audit
About the service area →Internal audit against ISO 27001 or NIST
An independent internal audit of your management system and controls against ISO 27001 or NIST CSF.
Scope: Defined engagement, one to two weeksRead more → Supply chainSupplier and third-party review
Your suppliers handle your systems and your information, but your requirements only count if someone follows them up.
Scope: Defined engagement, usually about a weekRead more →Project management
About the service area →By industry
The same expertise, different regulations and priorities. This is what engagements usually look like in the industries we work with most.
Finance and insurance
DORA: gap analysis, register of information and third-party risk. Financial regulations, ISO 27001 and an external data protection officer.
DORA · Gap analysis · DPO
Municipalities and the public sector
Information classification, NIS2 and the Swedish Cybersecurity Act, data protection and independent review of outsourced IT.
Industry and chemicals
Gap analysis and action plan against NIS2 and ISO 27001, risk-based prioritization and ongoing support with the measures.
Medtech and healthcare
Data protection programmes and DPIAs, ISO 27001 and a long-term IT partner for operations and strategy.
Software and SaaS
A management system to ISO 27001 that meets customer and regulatory requirements, the GDPR and secure Microsoft 365.
Critical infrastructure
NIS2 and the CER Directive, operation and monitoring of critical infrastructure, continuity and supplier governance.
NIS2 · CER · IT operations
Cannot find what you are looking for? Tell us what you need and we will suggest an approach.
Contact us