What We Do
One partner across the cybersecurity lifecycle.
From first gap assessment to a fully operating product security organization — GRC, consulting, testing, and leadership under one roof.
Service lines
01
GRC Programs & Operating Model
Governance · Risk · Compliance — AI-Accelerated
- Gap assessment against IEC 62443, EU CRA, NIS2 and ISO 27001 in one pass
- MDS² and IEC 81001-5-1 questionnaire answers, written once and reused
- Audit evidence packs assembled from records your team already keeps
- A written operating model: owners, decision points, review cadence
- Supplier reviews scoped to what each one actually touches
02
Consulting & Auditing
Gap Analysis · Compliance · Architecture
- Architecture and risk review of the system as built, not as documented
- Product security gap analysis ranked by what blocks a sale
- Audit readiness: findings closed before the assessor arrives
- Policy, procedure and record templates you can adopt as they are
03
Penetration Testing
OT · Embedded · Connected Products
- OT, embedded and connected-product testing against the real deployment
- Threat modeling across the attack surface the product actually has
- Findings written with the fix, the component, and the order to do them
- One test, two reports: technical detail and board-level posture
04
Regulatory Readiness
EU CRA · NIS2 · IEC 62443
- EU CRA and NIS2 obligations mapped to your product, deadlines marked
- Market-by-market assessment of what applies — and what does not
- Gap analysis of shipping product against IEC 62443 and the EU CRA
- Technical file and conformity documentation, built as the work happens
Insights
What we are writing about
Notes on the standards and regulations our clients are working through, written for the people who have to implement them.
EU CRA
The CRA's first deadline is 11 September 2026
Vulnerability and incident reporting starts fifteen months before the rest of the regulation, on a 24-hour clock — and it covers products you have already shipped.
IEC 62443
Which part of 62443 actually applies to you
The series is organised by role, not by topic. A map of the parts, and the SL-T / SL-C / SL-A distinction that decides what a supplier claim is worth.
Architecture
Zones and conduits, and the question they ask
Not how many firewalls, but what may talk to what. The five separation rules that produce an honest zone map from an existing plant drawing.