Service area

Information Security & Governance

Senior information security consultants for ISO 27001 management systems, NIS2, risk management and continuity – from current state to implementation.

ISO 27001NIS2Risk managementContinuitySupplier governance

We are information security consultants for organisations that need governance to work in practice: an ISO 27001 management system that lives on after the project, risk management the board can decide on, and compliance with NIS2, DORA and other requirements without duplicate work. Engagements can be advisory, hands-on delivery or an ongoing role as interim CISO.

A common first step is a gap analysis against ISO 27001, NIS2 or DORA that gives a documented current state and a prioritised plan. We then help you close the gaps, as with a software company building its ISMS and a chemical company meeting NIS2. Read more about how we work.

We are based in Skåne, Sweden, and take advisory assignments nationwide.

In brief

Who
Organisations that need a structured, risk-based security programme, for example ahead of ISO 27001, NIS2 or customer requirements
What
Management system (ISMS), security strategy and roadmap, risk management and continuity, compliance, incident preparedness, training, third-party risk
How
Current state and gap analysis, prioritised plan, implementation together with your organisation and ongoing follow-up

Common situations

This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.

Offers in information security

Six ways to start. Each offer can be bought on its own or combined into a coherent security programme.

Current state

Gap analysis against ISO 27001, NIS2 or DORA

Where do you stand against the requirements today? A documented current state, identified gaps and a prioritised action plan that management can decide on.

You get: a documented current state, gaps per requirement, a prioritised action plan and a review with management.

Scope: defined engagement, a few days to about a week depending on sizeRead more →
Management system

ISO 27001 from gap analysis to certification

An information security management system that works in the business: risk work, policies, controls, internal audit and preparation for certification.

You get: an ISMS with policies, risk method, control structure and Statement of Applicability, ready for audit.

Scope: project over several months, with handover to youRead more →
Governance

Security strategy and roadmap

A clear security direction with target state, prioritised initiatives, budget and ownership, anchored with management.

You get: strategy, target state and a roadmap with priorities, ownership and measurable results.

Scope: defined engagement, a few weeksRead more →
Risk and continuity

Risk analysis and continuity planning

Risk register, risk treatment plans, business impact analysis (BIA), continuity and crisis plans, and exercises.

You get: a current risk register, decided risk criteria, a continuity plan and a completed exercise.

Scope: defined engagement, or part of ongoing supportRead more →
Preparedness

Incident preparedness and exercises

Procedures, roles and playbooks for incident management, aligned with recovery and continuity, tested in tabletop exercises.

You get: an incident process with roles and communication paths, playbooks and a documented exercise.

Scope: defined engagement, exercise as an optionRead more →
Suppliers

Supplier and third-party risk management

Security requirements in contracts, review of suppliers and partners and ongoing follow-up throughout the contract period.

You get: a requirements template, risk-assessed suppliers and a follow-up routine.

Scope: defined engagement, or part of ongoing supportRead more →

See all offers →

Regulations and standards

A closer look at each regulation: who is affected, what is required and how we help.

Frequently asked questions

What is the difference between information security and IT security?

Information security protects all information that matters to the business, whether it sits in systems, on paper or with suppliers, and covers governance, procedures and people. IT security, or cybersecurity, is the technical protection of the IT environment. An information security management system holds both together.

Do we have to certify against ISO 27001?

No, certification is voluntary. Many organisations still work according to the standard because it gives a proven structure for risk work, policies and controls, and because customers and procurements increasingly ask for it. We help you judge whether certification is worth the effort for you.

How long does it take to implement an information security management system?

It depends on the size of the organisation, what already exists and how much time the organisation can invest. A realistic range is from a few months for a smaller organisation in good order to a year or more for a larger organisation starting from scratch. A gap analysis gives a clear answer for your situation.

Can you coordinate ISO 27001, NIS2, DORA and GDPR?

Yes. The requirements overlap to a large extent: risk analysis, policies, incident management, continuity and supplier governance. We build one management system where common requirements are handled once and what is specific to each regulation is added, instead of parallel tracks.

Do you only work with large organisations?

No. We work with companies and organisations of all sizes, from smaller companies to municipalities and regulated businesses. The set-up is adapted to your size and maturity so that the security work stays proportionate.

How we work with information security and governance, in detail

For those who want to know how we set up the work in each part. Jump to a section in the menu, or read from the top. About 7 minutes of reading

Governance & Security Frameworks

We help you establish and maintain robust security governance frameworks tailored to your organization. This includes developing an Information Security Management System (ISMS) aligned with ISO 27001 and other best practices to systematically manage security. We integrate relevant regulatory requirements and industry standards into your business processes, ensuring security is embedded in day-to-day operations. Our experts assist in creating clear security policies, procedures, and controls that reflect your company’s unique risk profile and strategic goals. We also conduct security maturity assessments to evaluate your current security posture and guide improvements, ensuring your governance keeps pace with evolving threats and business needs.

In brief

  • Information security management system (ISMS) aligned with ISO 27001
  • Regulatory requirements and industry standards built into business processes
  • Policies, procedures and controls based on your risk profile
  • Maturity assessments that show the current state and guide improvements

Security Strategy & Roadmap

We help you define a clear security direction that supports your business priorities and risk appetite. This includes establishing a security strategy, target state, and a practical roadmap with prioritized initiatives, budgets, and responsibilities. We translate requirements from standards and regulations into actionable plans and measurable outcomes, ensuring alignment with leadership and key stakeholders. Our approach creates transparency, supports decision-making, and helps you build security maturity step-by-step, without losing momentum in day-to-day operations.

In brief

  • Security strategy, target state and a practical roadmap with priorities, budget and ownership
  • Requirements from standards and regulations translated into concrete plans and measurable results
  • Buy-in from management and key stakeholders

Risk Management & Business Continuity

Proactively identifying and managing threats is central to our approach. We work with you to develop dynamic risk maps and risk registers that pinpoint potential threats to your information assets. Through thorough risk assessments and customized risk treatment plans, we help you prioritize and implement preventive measures to mitigate vulnerabilities before they materialize. Crucially, we also focus on Business Continuity Management (BCM) to ensure your critical operations can withstand and recover from disruptions. Our team assists in creating and testing business continuity plans and disaster recovery strategies, including business impact analyses and crisis response plans. By combining strong risk management with continuity planning, we work to put your organization in a position to keep operating and recover quickly in the face of a cyber incident or another type of crisis.

In brief

  • Risk maps and risk registers that make threats to information assets visible
  • Risk analyses and treatment plans with preventive measures
  • Business continuity management (BCM), disaster recovery, BIA and crisis plans
  • Plans that are developed and tested

Compliance & Regulatory Adherence

Navigating complex laws and standards is made easier with our compliance support. We help your organization achieve and maintain compliance with relevant laws, regulations, and industry standards (such as GDPR, NIS2, or other sector-specific rules). Our consultants establish structured compliance programs that include policy development, internal controls, and ongoing monitoring to ensure no requirement is overlooked. We perform audits and gap assessments to identify compliance risks and highlight any vulnerabilities in your controls. When gaps are found, we guide you through the necessary improvements and remediation steps. Our goal is to foster a strong security culture and demonstrate accountability, so you can confidently meet regulatory obligations and avoid costly penalties. (For dedicated data privacy services, see our Data Protection & Privacy offerings.)

In brief

  • Compliance with laws, regulations and standards such as GDPR and NIS2
  • Structured compliance programmes with policy work, internal controls and follow-up
  • Audits and gap analyses that identify compliance risks
  • Support through improvements and remediation steps

Cybersecurity & Incident Management

We provide hands-on expertise to fortify your IT infrastructure and respond to incidents effectively. Our team helps implement proactive cybersecurity measures – from network and cloud security controls to regular vulnerability assessments – to defend against threats. In addition, we offer incident response planning and disaster recovery planning to minimize damage when incidents occur. Our team works with you to establish clear incident management procedures, define roles and communication channels, and create playbooks for various incident scenarios. We also integrate disaster recovery and business continuity considerations, ensuring that technical recovery solutions (such as data backups, failover systems, and restore processes) are in place to minimize downtime. Through regular drills and tabletop exercises, we test and optimize your response capabilities. By preparing in advance, your organization can contain and manage security incidents with minimal downtime, ensuring business continuity.

In brief

  • Proactive cybersecurity measures, from network and cloud security to vulnerability assessments
  • Incident procedures with roles, communication paths and playbooks
  • Disaster recovery and continuity built in: backups, failover and restoration
  • Exercises and tabletop scenarios that test the capability

Security Awareness & Training

Even the best policies and technologies require knowledgeable people to be truly effective. We deliver customized security awareness training programs to cultivate a security-conscious culture within your organization. Through engaging workshops, e-learning modules, and even simulated exercises, we equip your employees with the tools and knowledge to recognize threats (like phishing or social engineering) and to follow security best practices in their daily work. Our training is tailored to your industry and internal policies, ensuring it’s relevant and practical. By increasing employee awareness and competence, we reduce human risk factors and empower your staff to act as an additional line of defense against security breaches.

In brief

  • Training programmes that build a security-aware culture
  • Workshops, e-learning and simulated exercises, for example against phishing
  • Adapted to your industry and internal policies

Third-Party Risk Management

Your security is only as strong as the weakest link, which is why we extend your governance to your vendors and partners. Our third-party due diligence services evaluate the security practices of your suppliers, service providers, and other external partners. We perform comprehensive assessments and audits of third parties to ensure they meet your organization’s security and compliance standards. This includes reviewing their policies, controls, and past track record, as well as identifying any risks they might pose to your data or operations. We also help you institute ongoing monitoring of third-party security measures, with periodic reviews and updates. By actively managing third-party risk, we help mitigate supply chain and partner-related threats, giving you confidence that your extended enterprise is secure.

In brief

  • Due diligence of suppliers, service providers and partners
  • Assessments and audits against your security and compliance requirements
  • Ongoing follow-up with recurring reviews

Dedicated Expertise & Support

In brief

  • A coherent approach: governance, risk, compliance, technical security and human factors
  • Support whether the goal is ISO 27001 certification, stronger risk management or better everyday security

Our team of highly qualified information security specialists is dedicated to safeguarding your business. We pride ourselves on a holistic approach – covering governance, risk, compliance, technical security, and human factors – to deliver a one-stop solution for your information security needs. Whether you are looking to certify under ISO 27001, strengthen your risk management and business continuity planning, or improve day-to-day security practices, we have the expertise to assist. With our support, you can focus on your core operations, with security and governance work that is documented, followed up, and possible to show in a review.

Want to know what it would look like for you? Contact us and we will tell you more.

Reviewed by Kristensson i Skåne AB. .

Sources: ISO/IEC 27001, information security management systems · EUR-Lex: Directive (EU) 2022/2555 (NIS2) · NIST Cybersecurity Framework

Want to know more about how we can strengthen your information security and governance?

Contact us