Security Risk & Compliance Consulting

Integrated solutions for information security and regulatory compliance.

From the design and implementation of Information Security Management Systems (ISO 27001) to data protection under the GDPR, and alignment with the European NIS2 and CER Directives.

A convergent approach that combines governance, risk management, and operational continuity, ensuring resilience and protection for infrastructures, processes, and people.

01

Management System Implementation (ISO 27001)

  • Design and support for the adoption of ISMS (Information Security Management System)
  • Preparation for ISO 27001 certification with internal audits, risk analysis, and training

02

Privacy and Data Protection Compliance (GDPR)

  • Data Protection Impact Assessment (DPIA), processing mapping, drafting of policies and records
  • Support for the role of DPO (Data Protection Officer)

03

Compliance with the NIS2 Directive – Network and Information Security

  • Analysis of compliance requirements for essential and important entities
  • Implementation of governance, risk management, incident response, and supply chain security measures

04

Compliance with the CER Directive – Critical Entities Resilience

  • Identification of critical infrastructure and assessment of its vulnerability.
  • Design of business continuity and crisis management plans in line with the CER Directive.