Services

I help organisations build a management system that answers ISO 27001, NIS2 and GDPR at once, and keep it alive after the certificate is on the wall. The work comes in shapes you can budget for: fixed-scope assessments, implementation projects, a fractional role, and training. Every engagement ends with something you can act on and, where it makes sense, a populated Abacordo register.

ISO 27001

  1. Gap analysis. Two to three weeks, fixed fee. Where you stand against ISO 27001:2022 and Annex A, what a certification auditor will flag first, and a sequenced plan with effort estimates. You leave knowing whether certification is six months away or eighteen.
  2. Implementation. Scope and context, risk assessment and treatment on ISO 27005, the policy set, the Statement of Applicability, control implementation with your teams, and the management review. I write the documents with you, not for you, so they describe how you actually work.
  3. Internal audit and audit preparation. An independent internal audit the standard requires, a pre-certification dry run, and support during the stage 1 and stage 2 audits. I have been the auditor; I know which questions come next.

NIS2 and CyberFundamentals

For entities under the Belgian NIS2 law of 26 April 2024, and for their important suppliers who are starting to receive questionnaires.

  • Scope memo. Whether NIS2 applies to you, as an essential or important entity, in which sector, and what that means for registration, supervision and the conformity route. Written so the board can decide.

  • CCB registration and CyFun self-assessment. Registration with the Centre for Cybersecurity Belgium, the CyberFundamentals level that fits you (Basic, Important or Essential), a scored self-assessment on the CCB maturity scale, and the deviation list that becomes your plan.

  • Measure coverage and governance. Coverage of the eleven risk-management measures, the management body's approval and training evidence under article 31, supplier security, and an incident process with the 24-hour, 72-hour and one-month clocks built in.

  • Supply chain and CRA exposure. Which of your products and suppliers fall under the Cyber Resilience Act, and what to ask of them before they ask it of you.

GDPR

Records of processing, impact assessments, article 32 security measures, breach notification procedure, and processor contracts, linked to the same assets and controls as your security programme so the DPO and the CISO keep one truth. Outsourced DPO support on a retainer for organisations that need a named DPO without a full-time hire.

Fractional CISO or GRC lead

Most mid-sized organisations cannot justify a full-time CISO, and should not have to. I take the role on a retainer of one or two days a week: run the management system, own the risk register, report to the board, manage suppliers and auditors, and build the internal capability so the role can move inside when the time is right. Typical term six to eighteen months, reviewed quarterly.

Quantum-safe transition

The EU expects organisations to start their transition to post-quantum cryptography by the end of 2026, with critical infrastructure migrated by 2030. For a GRC officer this is a risk-management measure with a date on it, and a cryptographic inventory is the first step. I offer a fixed-fee Quick Scan, a costed migration roadmap, and programme support, grounded in the NIST standards and in what NIS2 supervision will ask. Read more on quantum-safe →

Training and briefings

  • Board briefing, 90 minutes

    What NIS2 and ISO 27001 actually ask of the management body, what personal liability looks like, and the three questions to ask your CISO next week. A first orientation briefing is free of charge and without obligation.

  • GRC workshop, half day

    For the compliance owner and their team: how to run one management system for three frameworks, how to evidence controls without drowning in paperwork, and how to prepare for an audit in an afternoon rather than a fortnight.

  • Quantum-safe masterclass, one day

    The NIST standards in practice, inventory methods, hybrid deployments and crypto-agility. Hands-on, honest, vendor-free.

A note on funding

Depending on your region and size, advisory and training work may qualify for Belgian or European innovation support (VLAIO, Innoviris, EDIH programmes). It is worth checking before we start, and I will point you to the right instrument.

Independent and vendor-neutral: I sell advice and the tool I built to support it, nothing else. Book a conversation →