Business line · Resilient · Sovereign · Productive

    Cloud & Cybersecurity

    Architecture, standards and jurisdiction, stated concretely enough to verify. We audit against the standard, build the ISMS, move the workload into a jurisdiction you can name, and then run it.

    Who this is for

    • CISO

      Needs evidence, not assurance language, for the board and the auditor.

    • CIO and IT director

      Has to keep services running while the control set gets tighter.

    • CTO

      Wants architecture decisions documented before the next platform commitment.

    • Risk and compliance

      Owns NIS2, DORA and supplier assurance and needs the paper trail.

    The attacker's economics changed before the defender's did

    Phishing that once needed a fluent writer and a week now needs a prompt and four minutes. Voice cloning moved from conference demo to routine step in payment fraud inside two years. Reconnaissance that took a skilled operator days runs unattended. The number of credible, well-targeted attacks a single adversary can produce per hour has risen by an order of magnitude, and it is not coming back down.

    Almost nothing about your control framework is wrong. It is outnumbered. A security operation that depends on a human reading alerts in sequence cannot hold against an adversary generating them in parallel — the arithmetic does not work at any headcount you would be willing to fund. The only defence that scales against an AI-driven attacker is AI-driven detection: machine triage on everything, human judgment on the fraction that earns it.

    That is what we run. Monitoring runs continuously. Out of hours, containment is automated and a named on-call engineer is reachable for severity-one events. You get the full team during business hours and an answer at night for the things that cannot wait, rather than a rota you are paying for and will never use.

    The second pressure is where the workload sits. For most of our European clients that is Microsoft Azure in EU regions, with data residency in Europe as a design constraint rather than a preference. Where a contract, a regulator or a client's own policy requires it, we place workloads in colocation through local partners, on HPE and Lenovo hardware, and operate them to the same standard. The point is that the placement decision is made deliberately and documented, not inherited from whoever signed the first cloud contract.

    The third pressure is regulatory, and it is now personal. NIS2 widened the population of in-scope entities far beyond critical infrastructure and put accountability on management bodies rather than on IT. DORA does the same for financial entities and, importantly, for their ICT providers. ISO 27001 remains the instrument that turns all of it into something a client's procurement team will accept without a six-week questionnaire.

    We do the assessment, the roadmap, the implementation and the running of it. Most firms stop at one of those four, which is why so many risk registers describe controls nobody operates.

    What is different when this is done properly

    1. 01Alerts are triaged the moment they appear, not the next morning, because triage does not depend on someone being awake.
    2. 02Your risk register maps to ISO 27001 Annex A controls and to the ISO 27005 process that produced it, so a certification auditor can follow your reasoning rather than take your word for it.
    3. 03Where your data sits, and who can be compelled to produce it, is a documented decision with a named owner.
    4. 04NIS2 and DORA obligations are answered from one control set, mapped twice, instead of two programmes producing two registers.
    5. 05Your people stop being the softest target: phishing simulation and awareness sit inside the assessment cycle, measured, rather than beside it as an annual e-learning ritual.
    6. 06When a client asks for your security posture, you send a document instead of scheduling a call.

    How the security operation actually runs

    Four layers. The first two are machine-speed and continuous; the second two are where humans earn their place.

    Detect

    Endpoint, identity, cloud and external surface, monitored continuously. SentinelOne on the endpoint, native cloud telemetry, and external threat and brand exposure monitoring for what is happening about you outside your perimeter — leaked credentials, spoofed domains, executive impersonation.

    Triage

    The AI layer correlates, deduplicates and scores. The overwhelming majority of signal is closed here, with the reasoning recorded. What reaches a human has already been enriched with the context an analyst would otherwise spend twenty minutes assembling.

    Respond

    Containment actions on agreed playbooks — isolate the host, revoke the session, disable the account — executed under the authority you have delegated in advance, so response time is not a function of who answers the phone.

    Improve

    Every incident returns to the risk assessment and to the control set. This is the loop most operations skip, and it is why their control effectiveness scores drift while their alert volumes rise.

    Where the exposure concentrates

    Two patterns dominate our pipeline: organisations where IT and OT are converging faster than the security model, and small professional practices holding highly confidential material with almost no defensive readiness.

    Manufacturing and industrial

    Production networks were built for availability and long asset lifetimes, then connected for remote support and analytics. The result is a flat network segment where a twelve-year-old controller is one hop from an internet-facing jump host. Segmentation and OT-aware monitoring are the first two things we look at, and neither requires taking a line down.

    Retail and consumer

    Payment estate, e-commerce front end, and a supplier network with a wide range of security maturity. Third-party and brand exposure is the underrated risk: fraudulent domains and cloned storefronts damage revenue before any system of yours is breached.

    Healthcare

    Clinical availability makes disruption uniquely costly, and medical devices resist patching for regulatory reasons rather than negligent ones. The workable path is compensating controls and monitoring around devices that cannot be changed, and a tested recovery position for the ones that can.

    Legal, accounting and notarial practices

    Small teams holding material that is worth more to an attacker than the firm's annual IT budget. Readiness is typically low and the practical first move is unglamorous: multi-factor authentication everywhere, tested backups, managed endpoint detection, and staff who can recognise a well-written invoice fraud.

    Why us

    • Credentials held in the team: ISO/IEC 42001 Senior Lead Implementer, ISO/IEC 27001 Lead Implementer and Lead Auditor, ISO/IEC 27005 Risk Manager, EBIOS Risk Manager, ISO/IEC 20000 Lead Implementer, and Microsoft data and BI certifications.
    • Frameworks we work in: COBIT, TOGAF, ITIL, Zachman and NIST AI RMF.
    • PECB Certified Partner. We teach these standards as well as implement them.
    • Not a Big 4, not a freelancer. The practitioner who audits is the practitioner who has built one.
    • Offices in Amsterdam and Casablanca, with remote delivery from Porto.
    • Detection and protection partners: SentinelOne, Sophos, Fortinet and Palo Alto Networks. Threat intelligence and exposure: Infoblox. Infrastructure: HPE and Lenovo. Cloud platform: Microsoft Azure, European regions.
    • 15+ years across regulated industries in Europe and Africa.

    What it costs

    Published ranges for engagements delivered from our European entity. Work delivered from our African and Middle Eastern entity is quoted on request.

    EngagementIndicative priceNotes
    Security assessment or audit€8,500–19,000 per engagementISO 27001 gap analysis, cloud configuration review, or a full posture assessment.
    Risk assessment to ISO 27005€8,500–19,000 per engagementA risk register your auditor can follow, with the method documented.
    Remediation and implementation€25,000–65,000 per engagementScoped from the assessment findings rather than estimated in advance.
    vCISOfrom €2,500 per monthSecurity leadership on retainer, minimum six months.
    Managed detection and responseOn requestPriced on estate size and log volume. Continuous monitoring and out-of-hours on-call escalation are part of the service.

    All prices exclude VAT. The assessment fee is credited against implementation if you proceed with us within ninety days.

    Certified practitioners, not readers of the regulation

    • ISO/IEC 42001 Senior Lead Implementer
    • ISO/IEC 27001 Lead Implementer and Lead Auditor
    • ISO/IEC 27005 Risk Manager
    • EBIOS Risk Manager
    • ISO/IEC 20000 Lead Implementer
    • Microsoft data and BI certifications
    • PECB Certified Partner and accredited trainer

    Frameworks we work in

    • COBIT
    • TOGAF
    • ITIL
    • Zachman
    • NIST AI RMF

    Questions

    Frequently asked questions

    What is the difference between an ISO 27001 audit and a gap analysis?

    The audit issues a conformity opinion against ISO/IEC 27001 and Annex A. The gap analysis issues a roadmap: what is missing, what it costs and in what order to close it. Different deliverables, different engagements.

    Which risk methodology do you use?

    ISO 27005 and EBIOS Risk Manager, depending on the audience. EBIOS RM works well where an ANSSI-aligned, scenario-driven analysis is expected; ISO 27005 fits an ISMS certification track.

    Can you operate the environment after you build it?

    Yes. Sovereign Secured Operations covers detection and response, service desk under ITIL and ISO 20000 aligned processes, cloud support and infrastructure, with quarterly reviews.

    What is an AI SOC, and how is it different from a traditional SOC?

    A traditional security operations centre routes alerts to human analysts who investigate them in sequence, which makes analyst hours the hard limit on how much signal can be examined. An AI SOC puts a machine layer in front of that queue: it correlates events across endpoint, identity, cloud and external sources, discards the noise with its reasoning recorded, enriches what remains, and escalates only what needs human judgment. The practical difference is that everything gets looked at, immediately, rather than the queue being triaged by whatever arrived first.

    What does NIS2 require of us, and does it apply?

    NIS2 applies to essential and important entities across eighteen sectors, and it captured a large population of mid-sized companies that were out of scope under the original directive — including manufacturing, food production, digital providers, waste, postal services and parts of healthcare. It requires risk management measures, incident reporting on a defined clock, supply chain security, and — the change most boards underestimate — accountability at management level, including possible personal liability for senior management. Whether it applies to you turns on your sector, your size and the transposition in the member state where you operate; that determination is the first hour of the assessment, not a project in itself.

    Where does our data sit, and can we choose?

    By default, in Microsoft Azure regions inside the European Union, with EU data residency treated as a design constraint. Where a contract, a regulator or your own policy requires physical separation, we place workloads in colocation through local partners on HPE and Lenovo hardware and operate them to the same standard. The placement is documented as a decision with a named owner, so when someone asks the question two years later there is an answer that does not depend on institutional memory.

    Can awareness training and phishing simulation be part of the audit?

    Yes, and it should be. Testing whether people can recognise a well-crafted lure produces a measurement, and a measurement belongs in the assessment cycle alongside your technical control testing. Treated as a separate annual e-learning exercise it produces a completion rate, which measures compliance with the training rather than resilience to the attack.

    How fast do you respond to an incident?

    Monitoring runs continuously. Out of hours, containment is automated and a named on-call engineer is reachable for severity-one events. Containment actions on agreed playbooks execute automatically under authority you delegate in advance, so isolating a compromised host does not wait for a phone call. Severity one is defined with you and written into the service description rather than implied.

    Related insights

    What is Cyberthreat Monitoring?

    Cyberthreat monitoring refers to all practices, tools and methods aimed at detecting computer threats likely to target an information system in real time.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.