Straight answers on how our services work, and where the boundaries sit.
Do you implement security measures yourselves?
No. We advise, lead and govern; we do not build or operate. Where we act as your CISO we direct the work, but implementation and day-to-day operations stay with your own teams or your chosen providers, which keeps our judgement independent of who does the work.
What is the difference between CISO as a Service and CSO as a Service?
A CISO as a Service holds the security lead role inside your organisation: owning the management system, setting policy, directing the work and reporting upward. A CSO as a Service sits above that, at board level, overseeing the security agenda and representing it in executive decisions. If you have nobody leading security, you want the first. If you have a function but no senior voice where decisions are made, you want the second. We will not do both for the same organisation at the same time.
How is CSO as a Service different from hiring a consultant?
A consultant delivers a piece of work and leaves. In a CSO as a Service arrangement we take an ongoing seat in your governance: we attend board meetings, own the security agenda at that level, and stay accountable for keeping it moving.
We already have a CISO. What would you add?
Usually one of three things: an experienced peer to test decisions against, extra weight when a case needs to be made to the board, or coaching to help a capable security lead become a more effective leader.
Do you certify organisations against ISO 27001 or NEN 7510?
No. Certification is carried out by an accredited certification body, and it would not be appropriate for the same firm to advise and to certify. We help you get ready, and we help your board understand what the certificate does and does not cover.
Are we in scope for the Cyberbeveiligingswet?
That depends on your sector, your size, and in some cases on designation by the government. Some organisations fall under the law automatically; others do not, but are pulled towards the same requirements by their customers' contracts. Now that the law is in force, this is worth settling quickly rather than leaving open. It is usually a short exercise.
Do you work in English?
Yes. We work in Dutch and English, and a substantial part of our work is with international organisations or with Dutch companies whose board language is English.
How long does an engagement last?
A briefing or assessment may take weeks. Coaching and roadmap work typically run six to twelve months. CISO as a Service and CSO as a Service are ongoing arrangements, reviewed annually.
Do you work with organisations that have had an incident?
Yes, usually in the period afterwards, when the immediate response is over and the question becomes what to change structurally so it does not happen again.
Let's talk.
Thirty minutes is usually enough to work out whether we can help.