• EU Regulatory Compliance (DORA, AI Act, NIS2, PSD2, GDPR)
• CISO Services (vCISO, CISO support, risk assessments, security monitoring and reporting, etc.)
• AI Governance, Risk and Compliance ( AI Audit and Assurance / AI Control Framework, AI Organizational Responsibilities, AI Technology & Risks)
• IS & ICT Risk Management (risk management governance and organization, ICT risk management frameworks - ISO 27005, NIST 800-30&39, threat modelling, risk identification, threat detection, risk evaluation, risk treatment plan – protection and prevention, response and recovery)
• IS & ICT Incident Management (policies, procedures, plans, classification, testing and reporting)
• Digital Operations Resilience Testing ( program definition, performance requirements definition, results review, remediation plans review)
• Third Party Risk Management (framework, strategy, ICT services register, KPIs, KRIs, SLAs, assessments, due diligence, exit strategies and plans, etc.)
• IS & ICT Governance (strategies, frameworks: ISO 27001/2, NIST Cybersecurity framework, COBIT, PCI-DSS, Swift CSP/CSCF)
• Cloud Security (CSA CSM, ISO 27017, ISO 27018)
• ICT Assurance (IT Internal Audit co-sourcing, 3rd Line of Defence support, ITAF, ISAE 3402 - SOC 1, SOC2)