Information Security & Governance
Senior information security consultants for ISO 27001 management systems, NIS2, risk management and continuity – from current state to implementation.
We are information security consultants for organisations that need governance to work in practice: an ISO 27001 management system that lives on after the project, risk management the board can decide on, and compliance with NIS2, DORA and other requirements without duplicate work. Engagements can be advisory, hands-on delivery or an ongoing role as interim CISO.
A common first step is a gap analysis against ISO 27001, NIS2 or DORA that gives a documented current state and a prioritised plan. We then help you close the gaps, as with a software company building its ISMS and a chemical company meeting NIS2. Read more about how we work.
We are based in Skåne, Sweden, and take advisory assignments nationwide.
In brief
- Who
- Organisations that need a structured, risk-based security programme, for example ahead of ISO 27001, NIS2 or customer requirements
- What
- Management system (ISMS), security strategy and roadmap, risk management and continuity, compliance, incident preparedness, training, third-party risk
- How
- Current state and gap analysis, prioritised plan, implementation together with your organisation and ongoing follow-up
Common situations
This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.
A customer or owner requires ISO 27001, or a management system you can show
We build or lift your information security management system and make you ready for certification.
Read about management systems and frameworks →You are affected by NIS2, DORA or other regulations and do not know where the gaps are
Gap analysis against the requirements, a prioritised action plan and support in delivery.
Read about compliance →The risk register is old and the continuity plan has never been tested
Current risk analyses, continuity plans and exercises that show they work.
Read about risk and continuity →Suppliers handle your information, but nobody follows up on their security
Requirements, review and ongoing follow-up of suppliers and partners.
Read about third-party risk →Offers in information security
Six ways to start. Each offer can be bought on its own or combined into a coherent security programme.
Gap analysis against ISO 27001, NIS2 or DORA
Where do you stand against the requirements today? A documented current state, identified gaps and a prioritised action plan that management can decide on.
You get: a documented current state, gaps per requirement, a prioritised action plan and a review with management.
Scope: defined engagement, a few days to about a week depending on sizeRead more → Management systemISO 27001 from gap analysis to certification
An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.
You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.
Scope: project over several months, with handover to youRead more → GovernanceSecurity strategy and roadmap
A clear security direction with target state, prioritised initiatives, budget and ownership, anchored with management.
You get: strategy, target state and a roadmap with priorities, ownership and measurable results.
Scope: defined engagement, a few weeksRead more → Risk and continuityRisk analysis and continuity planning
Risk register, risk treatment plans, business impact analysis (BIA), continuity and crisis plans, and exercises.
You get: a current risk register, decided risk criteria, a continuity plan and a completed exercise.
Scope: defined engagement, or part of ongoing supportRead more → PreparednessIncident preparedness and exercises
Procedures, roles and playbooks for incident management, aligned with recovery and continuity, tested in tabletop exercises.
You get: an incident process with roles and communication paths, playbooks and a documented exercise.
Scope: defined engagement, exercise as an optionRead more → SuppliersSupplier and third-party risk management
Security requirements in contracts, review of suppliers and partners and ongoing follow-up throughout the contract period.
You get: a requirements template, risk-assessed suppliers and a follow-up routine.
Scope: defined engagement, or part of ongoing supportRead more →Regulations and standards
A closer look at each regulation: who is affected, what is required and how we help.
NIS2 & Cybersecurity Act
Which organisations are affected, what security measures are required and how to get started.
Read more →AI Act
The EU framework for artificial intelligence: risk classification, obligations per role and timeline.
Read more →Financial Regulations – DORA
Digital operational resilience for financial entities: ICT risk, incidents, suppliers and testing.
Read more →Financial Regulations – FFFS, EBA, EIOPA & ESMA
IT and information security requirements from the Swedish FSA and the European supervisory authorities.
Read more →Critical Entities Resilience (CER) Directive
Physical and operational resilience for critical entities, complementing NIS2.
Read more →Cyber Resilience Act (CRA)
Cybersecurity requirements for products with digital elements: secure development, vulnerability handling and documentation.
Read more →Frequently asked questions
What is the difference between information security and IT security?
Information security protects all information that matters to the business, whether it sits in systems, on paper or with suppliers, and covers governance, procedures and people. IT security, or cybersecurity, is the technical protection of the IT environment. An information security management system holds both together.
Do we have to certify against ISO 27001?
No, certification is voluntary. Many organisations still work according to the standard because it gives a proven structure for risk work, policies and controls, and because customers and procurements increasingly ask for it. We help you judge whether certification is worth the effort for you.
How long does it take to implement an information security management system?
It depends on the size of the organisation, what already exists and how much time the organisation can invest. A realistic range is from a few months for a smaller organisation in good order to a year or more for a larger organisation starting from scratch. A gap analysis gives a clear answer for your situation.
Can you coordinate ISO 27001, NIS2, DORA and GDPR?
Yes. The requirements overlap to a large extent: risk analysis, policies, incident management, continuity and supplier governance. We build one management system where common requirements are handled once and what is specific to each regulation is added, instead of parallel tracks.
Do you only work with large organisations?
No. We work with companies and organisations of all sizes, from smaller companies to municipalities and regulated businesses. The set-up is adapted to your size and maturity so that the security work stays proportionate.
How we work with information security and governance, in detail
For those who want to know how we set up the work in each part. Jump to a section in the menu, or read from the top. About 7 minutes of reading
Governance & Security Frameworks
We help you establish and maintain robust security governance frameworks tailored to your organization. This includes developing an Information Security Management System (ISMS) aligned with ISO 27001 and other best practices to systematically manage security. We integrate relevant regulatory requirements and industry standards into your business processes, ensuring security is embedded in day-to-day operations. Our experts assist in creating clear security policies, procedures, and controls that reflect your company’s unique risk profile and strategic goals. We also conduct security maturity assessments to evaluate your current security posture and guide improvements, ensuring your governance keeps pace with evolving threats and business needs.
In brief
- Information security management system (ISMS) aligned with ISO 27001
- Regulatory requirements and industry standards built into business processes
- Policies, procedures and controls based on your risk profile
- Maturity assessments that show the current state and guide improvements
Security Strategy & Roadmap
We help you define a clear security direction that supports your business priorities and risk appetite. This includes establishing a security strategy, target state, and a practical roadmap with prioritized initiatives, budgets, and responsibilities. We translate requirements from standards and regulations into actionable plans and measurable outcomes, ensuring alignment with leadership and key stakeholders. Our approach creates transparency, supports decision-making, and helps you build security maturity step-by-step, without losing momentum in day-to-day operations.
In brief
- Security strategy, target state and a practical roadmap with priorities, budget and ownership
- Requirements from standards and regulations translated into concrete plans and measurable results
- Buy-in from management and key stakeholders
Risk Management & Business Continuity
Proactively identifying and managing threats is central to our approach. We work with you to develop dynamic risk maps and risk registers that pinpoint potential threats to your information assets. Through thorough risk assessments and customized risk treatment plans, we help you prioritize and implement preventive measures to mitigate vulnerabilities before they materialize. Crucially, we also focus on Business Continuity Management (BCM) to ensure your critical operations can withstand and recover from disruptions. Our team assists in creating and testing business continuity plans and disaster recovery strategies, including business impact analyses and crisis response plans. By combining strong risk management with continuity planning, we work to put your organization in a position to keep operating and recover quickly in the face of a cyber incident or another type of crisis.
In brief
- Risk maps and risk registers that make threats to information assets visible
- Risk analyses and treatment plans with preventive measures
- Business continuity management (BCM), disaster recovery, BIA and crisis plans
- Plans that are developed and tested
Compliance & Regulatory Adherence
Navigating complex laws and standards is made easier with our compliance support. We help your organization achieve and maintain compliance with relevant laws, regulations, and industry standards (such as GDPR, NIS2, or other sector-specific rules). Our consultants establish structured compliance programs that include policy development, internal controls, and ongoing monitoring to ensure no requirement is overlooked. We perform audits and gap assessments to identify compliance risks and highlight any vulnerabilities in your controls. When gaps are found, we guide you through the necessary improvements and remediation steps. Our goal is to foster a strong security culture and demonstrate accountability, so you can confidently meet regulatory obligations and avoid costly penalties. (For dedicated data privacy services, see our Data Protection & Privacy offerings.)
In brief
- Compliance with laws, regulations and standards such as GDPR and NIS2
- Structured compliance programmes with policy work, internal controls and follow-up
- Audits and gap analyses that identify compliance risks
- Support through improvements and remediation steps
Cybersecurity & Incident Management
We provide hands-on expertise to fortify your IT infrastructure and respond to incidents effectively. Our team helps implement proactive cybersecurity measures – from network and cloud security controls to regular vulnerability assessments – to defend against threats. In addition, we offer incident response planning and disaster recovery planning to minimize damage when incidents occur. Our team works with you to establish clear incident management procedures, define roles and communication channels, and create playbooks for various incident scenarios. We also integrate disaster recovery and business continuity considerations, ensuring that technical recovery solutions (such as data backups, failover systems, and restore processes) are in place to minimize downtime. Through regular drills and tabletop exercises, we test and optimize your response capabilities. By preparing in advance, your organization can contain and manage security incidents with minimal downtime, ensuring business continuity.
In brief
- Proactive cybersecurity measures, from network and cloud security to vulnerability assessments
- Incident procedures with roles, communication paths and playbooks
- Disaster recovery and continuity built in: backups, failover and restoration
- Exercises and tabletop scenarios that test the capability
Security Awareness & Training
Even the best policies and technologies require knowledgeable people to be truly effective. We deliver customized security awareness training programs to cultivate a security-conscious culture within your organization. Through engaging workshops, e-learning modules, and even simulated exercises, we equip your employees with the tools and knowledge to recognize threats (like phishing or social engineering) and to follow security best practices in their daily work. Our training is tailored to your industry and internal policies, ensuring it’s relevant and practical. By increasing employee awareness and competence, we reduce human risk factors and empower your staff to act as an additional line of defense against security breaches.
In brief
- Training programmes that build a security-aware culture
- Workshops, e-learning and simulated exercises, for example against phishing
- Adapted to your industry and internal policies
Third-Party Risk Management
Your security is only as strong as the weakest link, which is why we extend your governance to your vendors and partners. Our third-party due diligence services evaluate the security practices of your suppliers, service providers, and other external partners. We perform comprehensive assessments and audits of third parties to ensure they meet your organization’s security and compliance standards. This includes reviewing their policies, controls, and past track record, as well as identifying any risks they might pose to your data or operations. We also help you institute ongoing monitoring of third-party security measures, with periodic reviews and updates. By actively managing third-party risk, we help mitigate supply chain and partner-related threats, giving you confidence that your extended enterprise is secure.
In brief
- Due diligence of suppliers, service providers and partners
- Assessments and audits against your security and compliance requirements
- Ongoing follow-up with recurring reviews
Dedicated Expertise & Support
In brief
- A coherent approach: governance, risk, compliance, technical security and human factors
- Support whether the goal is ISO 27001 certification, stronger risk management or better everyday security
Our team of highly qualified information security specialists is dedicated to safeguarding your business. We pride ourselves on a holistic approach – covering governance, risk, compliance, technical security, and human factors – to deliver a one-stop solution for your information security needs. Whether you are looking to certify under ISO 27001, strengthen your risk management and business continuity planning, or improve day-to-day security practices, we have the expertise to assist. With our support, you can focus on your core operations, with security and governance work that is documented, followed up, and possible to show in a review.
Want to know what it would look like for you? Contact us and we will tell you more.
Want to know more about how we can strengthen your information security and governance?
Contact us