Governance, Risk & Compliance
GRC
We translate business risk into defensible controls, documentation, and evidence — across eight engagement types.
- ISMSISO/IEC 27001 & 27002 implementation.
- NIS2 / DORAEU readiness assessments & remediation.
- GDPR & DPIAEU/EEA assessments and support.
- NSM GrunnprinsipperAlignment for Norwegian entities.
- Policy authoringStandards and procedures, board-grade.
- Supply-chain riskThird-party assessments & controls.
- Internal auditGap analysis and remediation roadmaps.
- Risk managementRisk assessments, registers, and treatment plans aligned to ISO 27005.
Engagements scale from focused gap assessments to long-term advisory retainers. Contact us to scope.
Information sharing
Traffic Light Protocol (TLP)
We operate according to the Traffic Light Protocol for classifying and sharing sensitive information with clients and partners. TLP designations apply to all communications.
- TLP:REDNot for disclosure, restricted to participants only.
- TLP:AMBER+STRICTLimited disclosure, restricted to participants' organization.
- TLP:AMBERLimited disclosure, restricted to participants' organization and clients.
- TLP:GREENLimited disclosure, restricted to the community.
- TLP:CLEARDisclosure is not limited (subject to standard copyright rules).
For emails, include the TLP designation in capital letters in the subject line and body. For documents, place designations in headers and footers.