Governance, Risk & Compliance

We are a technology company. We also know that technology alone never passed an audit, satisfied a regulator, or earned a customer's trust. This is the part that does.

Genuine compliance — not a certificate that lapses the day we leave We run every methodology on ourselves first Advise, build, and operate — under one roof
01 / Summary

What this practice is, in two minutes.

We are a technology company — that part is settled. But technology has never been the whole job. Alongside our technical teams sit our Client Partners, whose role is to understand your business before anyone reaches for a solution: your objectives, your industry, your appetite for risk. And alongside both sits this practice. Governance, Risk & Compliance exists to help your business run in compliance, at lower risk, and under proper governance — whether that runs in parallel with a technology project or stands entirely on its own.

The practice helps you meet the standards and regulations you are measured against — ISO certification, NIS2, GDPR, the EU AI Act, and the rest — and keep meeting them. We run the gap analysis, build the management system with your team, help engineer the controls through our sibling practices, and assemble the evidence that stands up — to an auditor, and to reality. Where you need senior leadership for the long haul, we provide it as a service: a virtual CISO, a Data Protection Officer.

We work differently from the firms that hand over a certificate in a fortnight. That certificate looks identical to a real one — until the day it has to do something. Under a serious audit it falls apart; worse, in a real incident — a breach, an outage, a supply-chain attack — the documents someone sold you do nothing to contain the damage, because nothing underneath them ever changed. We ask you to do the actual work of process reform. We support, advise, engineer, and audit; the operational change is yours to own. It is slower. It is also the only kind of compliance that protects you when it matters.

And we know it works, because we have done it — for ourselves and for our clients. Every methodology we offer is one we already run internally, across every entity in the group. Several we have also delivered for clients we serve: ISO 27001 and ISO 20000 certifications, GDPR compliance programmes, and CISO- and DPO-as-a-Service engagements. What is new is not the work — it is that we are opening it beyond our existing relationships, to new clients who want compliance done properly from the start.

We don't hand you a certificate. We help you earn one — and keep it.
02 / Approach

Compliance that protects you — not just passes you.

There is a whole market that will sell an organisation a certificate in a fortnight, with no change to how the business actually runs. The framed document looks the same as a real one. The difference shows up the day it has to do something. Under a serious audit it falls apart — but the costlier failure is quieter: when a breach, an outage, or a supply-chain attack actually lands, the policies someone sold you do nothing to contain it, because nothing underneath them ever changed. We are not that company.

We build the kind of compliance that still works on the day something goes wrong.

The way we frame our own role is the second line of defence. It sounds technical; the meaning is simple, and it is what separates real governance from compliance theatre.

  • The first line is your business. Your people, running your processes, living with the consequences. They own the work — and they keep owning it after we leave.
  • The second line is us. We do not run your processes; we make sure they are documented, controlled, monitored, and aligned to the standards and regulations that matter, so they are defensible when tested — and effective when they are needed for real.
  • The third line is the auditor or regulator. They arrive periodically with their own assessment. When the second line has done its job, that visit becomes a confirmation of work already done — not a scramble for evidence.

We are also honest about what comes after the assessment. A risk register and a set of documents are the start, not the finish. Once the risks are on the table, you have to decide which to accept and which to treat — and treating them realistically means planning what the real controls will cost. Some are policy and process; others need technology, a security operations centre, threat intelligence, or a managed service to actually work. We cost that picture with you, so the choice of which risks to carry and which to close is made with open eyes — not discovered after the certificate is framed.

And we run internal audit as a conversation, not a fire drill: we present the gap, your process owner explains the reality, and together you decide whether to change the documentation or change the practice. The output is a decision, not a binder.

03 / Services

Four ways we help.

01

Standards & Certification

Get certified, stay certified — with a management system that does not collapse the day the consultants leave. We map the gap, build the system with your team, and prepare you for the certification body, then stay for the surveillance audits.

  • ISO/IEC 27001 — information security management
  • ISO/IEC 20000 — IT service management
  • ISO 22301 — business continuity
  • ISO 37001 — anti-bribery management
  • TISAX — information security for automotive supply chains
  • SOC 2 and CREST — attestation and accreditation the group already holds
02

Regulatory Readiness

The EU regulatory wave is arriving in layers. Local enforcement is uneven; your Western-European customers' demands are not. We translate each regulation into work you can actually do, and into the evidence your partners ask for.

  • NIS2 — governance wrapper, risk assessments, incident-reporting procedures aligned to the 24-hour and 72-hour duties, supply-chain compliance evidence
  • GDPR — privacy programme, records of processing, data-subject request handling, processing agreements
  • EU AI Act — risk classification, AI governance policy, transparency and human-oversight posture
  • CSRD & ESG — sustainability reporting readiness, EcoVadis improvement
  • Cyber Resilience Act — on the horizon, tracked country by country
03

Risk & Assurance

Know your risk, control it, and prove the controls work. The same four-level risk framework and audit discipline we run internally, turned outward — built to give management the truth, not a comfortable story.

  • Enterprise risk framework — project, standard-specific, value-chain, and enterprise levels
  • Internal audit — run as a focused review and a decision, not a checklist before the auditor arrives
  • Control monitoring — evidence pipelines that run continuously, not once a year
  • Management reporting — honest findings, including the uncomfortable ones
04

CISO & DPO as a Service

Senior security and privacy leadership without the full-time hire — drawn from the same Group CISO and Data Protection Officer functions that govern our own group across every entity, and from CISO- and DPO-as-a-Service engagements we have already delivered for clients.

  • Virtual CISO — security strategy, governance, and board-ready reporting
  • Data Protection Officer — the GDPR role, fulfilled and accountable
  • Security governance — the policy, documentation and risk layer that sits on top of your technical controls
  • Incident coordination — response procedures and the notification duties that come with NIS2 and GDPR
04 / Frameworks

The standards we are fluent in.

The frameworks below are not a reading list. Each is one we hold, run, or prepare clients for in practice — and most we maintain on our own group first.

Information security
ISO/IEC 27001

The backbone standard for an information security management system — and the foundation most other compliance builds on.

Service management
ISO/IEC 20000

IT service management done to standard, where our Operations function and the audit evidence centre.

Business continuity
ISO 22301

The discipline of continuing to operate — and proving you can — when something goes wrong.

Anti-bribery
ISO 37001

Anti-bribery management, increasingly asked for by Western-European and public-sector counterparties.

EU directive
NIS2

In force across our region. We own the governance half; the Group CISO owns the technical controls.

Data protection
GDPR

Maintained across every entity in the group, with the Data Protection Officer function run in-house.

AI governance
EU AI Act

Risk classification and AI governance, with the people who actually build the AI systems at the table.

Automotive infosec
TISAX

The information-security assessment automotive supply chains require of their partners.

Service-org controls
SOC 2

The trust-services report North-American and enterprise buyers expect — an attestation the group holds.

Security testing
CREST

Accreditation for penetration-testing and security-assessment quality, held by the group.

Industrial / OT
IEC 62443

OT and industrial security, delivered with our Advanced OT Solutions practice and its plant-floor engineers.

Sustainability
CSRD & ESG

Sustainability reporting and ESG posture — increasingly written into Western-European and public-sector tenders.

05 / Across practices

Most compliance firms can only advise. We can also build.

A pure-play GRC consultancy writes you a recommendation and leaves. When the recommendation implies a firewall, a segmented OT network, an evidence pipeline, or an AI guardrail, someone else has to build it — and the gap between advice and implementation is where compliance quietly dies. Inside this group, the people who build it sit down the corridor.

Group CISO & Infrastructure
Security, governed and engineered

We own the governance — policies, documentation, risk assessments, the proof package. The Group CISO and the Infrastructure & Cybersecurity practice own the controls, the SOC, detection and response. NIS2 done properly needs both halves. We have both.

Advanced OT Solutions
OT certification, with plant-floor depth

IEC 62443 organisational certification and ISO 27001 OT-scope extensions, backed by engineers who actually work in industrial environments — not a checklist applied from a desk.

AI & Software Engineering
AI Act readiness, from the builders

EU AI Act compliance with the people who build and run the AI systems contributing the technical clauses — approved providers, tooling, data-handling rules — while we own the governance layer on top.

Internal delivery
Controls that get built, not filed

When a control implies new tooling, integration, or engineering, it is implemented by the group — not left as a line item in a report for you to resource alone.

06 / Proven on ourselves

We are our own first client.

We did not decide to offer this externally and then go looking for a method. We built it to govern a scaling, multi-country group — and we run all of it on ourselves, continuously, through the external audit cycle. We have also delivered it for clients: ISO 27001 and ISO 20000 certifications, GDPR programmes, and CISO- and DPO-as-a-Service engagements for organisations we already serve. What is new in 2026 is simply that we are opening this to new client relationships.

25Years of IT, security and governance discipline behind the practice
6Countries in the group today — every entity in scope, group-wide by default
4Core ISO standards integrated and maintained, plus related standards
2Independent security credentials held — SOC 2 and CREST
100%Of group entities under GDPR compliance, with an in-house DPO
01

Integrated ISO portfolio

Information security, service management, anti-bribery, business continuity and related standards — maintained as one system, not a drawer of separate certificates.

02

Group Data Protection Officer

The DPO function run in-house across every entity — GDPR monitoring, data-subject requests, processing advisory, privacy posture.

03

Four-level risk framework

Project, standard-specific, value-chain and enterprise risk — an operational framework, not a theoretical one, maturing toward a platform home.

04

Whistleblowing channel

A group-wide channel administered across all entities, with reports reviewed and directive compliance assured.

05

EcoVadis bronze

An external sustainability rating earned, with a roadmap toward silver — the same ESG work clients increasingly need.

06

Internal audit, as conversation

A continuous audit cycle organised around decisions and management truth — the methodology we hand a client, run on us first.

Everything here, we run on ourselves first — and several pieces, we already run for clients.
07 / Who it's for

Who comes to us.

In NIS2 scope

Essential and important entities — and the suppliers who sit inside their supply chain and now have to demonstrate compliance to keep the contract.

Suppliers to Western Europe

Organisations whose multinational or EU customers require evidence of compliance as a condition of doing business. Local enforcement may be quiet; the customer's procurement team is not.

Pursuing or holding ISO

Companies that want certification to be real — to win the tender and survive the surveillance audit — rather than a framed document that cracks under inspection.

Deploying AI

Teams putting AI into production who need to classify it, govern it, and answer the EU AI Act questions their partners are starting to ask.

OT & industrial operators

Plants and infrastructure operators needing IEC 62443 and OT-scope security governance — with people who understand the environment they are securing.

EU-funded buyers

Where ESG and compliance requirements are written into the tender — an area we navigate for our own programmes and partnerships.

08 / How we work

What an engagement looks like.

No two compliance journeys start in the same place, but the shape is consistent. We meet you where you are, build with your people, and stay long enough that the result holds without us.

Step 01Conversation

Thirty minutes on your obligations, your customers' demands, and where you stand today. An honest read on what is realistic.

Step 02Gap analysis

Your current posture mapped against the frameworks you must meet. Gaps named, prioritised, and costed.

Step 03Build together

Policies and processes written with your team — internal ownership from day one, so the system is yours, not ours.

Step 04Implement & evidence

The controls engineered through our practices where you need it, and the evidence package assembled as you go.

Step 05Audit & sustain

Internal audit as a conversation, the external audit as a confirmation — and the evidence kept current, year after year.

One honest note on how we work: we are selective, and we scale the team to genuine demand rather than promising a bench we have not staffed. If a paper certificate is what you are after, we are the wrong firm and will say so. If compliance that survives contact with a real audit is the goal, that is exactly the work we want.

09 / FAQ

Questions we get.

What does the Governance, Risk & Compliance practice actually do?

We help organisations meet the standards and regulations they are measured against — ISO 27001, 20000, 22301 and 37001, plus NIS2, GDPR, the EU AI Act, TISAX and others — and keep meeting them. We run gap analysis, build the management system with your team, help engineer the controls through our sibling practices, and assemble audit-ready evidence. We also provide senior leadership as a service through CISO-as-a-Service and DPO-as-a-Service.

How are you different from firms that just sell certificates?

A certificate handed over in two weeks with no change to how the business runs looks identical to a real one — until the day it has to do something, whether that is a serious audit or a real attack. Our methodology asks you to do the actual work of process reform; we support, advise, engineer and audit, but the operational change is yours to own. It is the only kind of compliance that protects you. And we run every methodology on ourselves first, across the whole group, before we put it in front of a client.

Have you done this for clients, or only internally?

Both. Beyond running the full programme on our own group, we have delivered compliance work for clients we already serve — ISO 27001 and ISO 20000 certifications, GDPR programmes, and CISO- and DPO-as-a-Service engagements. Those were organisations with whom we already do significant business. What is new is that we are now opening the practice to new client relationships in its own right.

What is CISO-as-a-Service, and what is DPO-as-a-Service?

They are senior security and privacy leadership without a full-time hire. A virtual CISO gives you security strategy, governance and board-ready reporting; a Data Protection Officer fulfils the GDPR role on your behalf. Both are drawn from the same Group CISO and DPO functions that govern our own group across every entity, so you get operational depth rather than a title.

How do you handle NIS2?

NIS2 has two halves. Our Group CISO and Infrastructure & Cybersecurity practice own the technical controls; this practice owns the governance wrapper — policies, risk assessments, incident-reporting procedures aligned to the 24-hour early-warning and 72-hour notification duties, supply-chain compliance evidence, and the proof package a supervisory authority or a customer's auditor expects. Because both halves sit inside one group, you do not have to stitch two providers together.

Do you cover GDPR and act as a Data Protection Officer?

Yes. We run a privacy programme end to end — records of processing, data-subject request handling, processing agreements, and the overall privacy posture — and we can act as your external Data Protection Officer. We perform the same role for our own group across all entities.

What about the EU AI Act?

We classify your AI systems against the Act's risk categories, build the AI governance policy, and prepare the transparency and human-oversight posture your partners are beginning to ask about. The work is done jointly with our AI & Software Engineering practice, who contribute the technical clauses while we own the governance layer — the same dual-authority model we run internally.

Which frameworks and standards do you work across?

The ISO family (27001, 20000, 22301, 37001), NIS2, GDPR, the EU AI Act, TISAX, IEC 62443 for OT, and CSRD and ESG for sustainability, along with SOC 2 and CREST — both held by the group. Most of these we maintain on our own group first, which is why we can speak to them from practice rather than theory.

In which countries do you operate?

Six countries in Central and South-East Europe — Bulgaria, Croatia, Serbia, Slovenia, Bosnia and Herzegovina, and North Macedonia — with Western-European expansion in progress through planned acquisitions. Our governance mandate is group-wide by default, so multi-entity and multi-country compliance is the normal case for us, not the exception. Headquarters in Sofia, Bulgaria.

10 / Why us

Why work with us.

  • 01
    We run it on ourselves first.Every methodology we offer is one we already operate across the group — an integrated ISO portfolio, a group DPO, a four-level risk framework, a continuous audit cycle. We are our own proof.
  • 02
    Advise, build, and operate — under one roof.A pure-play consultancy leaves you with a recommendation. We can engineer the controls too, through our infrastructure, OT and AI practices, so advice does not die in the gap before implementation.
  • 03
    Genuine compliance, not a paper certificate.We ask you to do the real work of process reform, because that is the only thing that survives a serious audit. Slower to earn; far harder to lose.
  • 04
    A group view across every entity.Multi-country, multi-entity governance is our normal operating reality. If you are scaling, acquiring, or operating across borders, that is the problem we already solve for ourselves.
  • 05
    The second line, done honestly.We tell management the truth, uncomfortable findings included. Governance only works when the people relying on it trust its read on where the gaps actually are.
  • 06
    Senior leadership on tap.CISO-as-a-Service and DPO-as-a-Service give you experienced security and privacy leadership for the long haul, without carrying a full-time executive on the books.
Let's talk

Start with a thirty-minute conversation.

Tell us what you are measured against — the regulation bearing down, the customer asking for evidence, the certification you need to win or keep. Thirty minutes with the practice will give you an honest read on what is realistic, where to start, and what genuine compliance will take. The gap analysis usually follows.

Request a meeting →