Security and resilience leads
People responsible for security measures, incident readiness, suppliers and evidence across an operating environment.
A scoped service for organisations that need to organise cybersecurity governance, risk measures, incident evidence and cross-border responsibilities around a defined context.
Who this is for
People responsible for security measures, incident readiness, suppliers and evidence across an operating environment.
Owners who need a bounded view of responsibilities, dependencies and questions requiring local legal interpretation.
Questions this addresses
Entities, services, suppliers and dependencies are not yet connected to one evidence and responsibility picture.
Incident, continuity, risk and reporting records need to be located, related and tested against the agreed question.
What we examine
The selected roles, decisions, risk process, security measures and oversight records in the engagement perimeter.
Incident handling, continuity, supplier dependencies, access, monitoring and improvement records relevant to the question.
What you receive
A structured view of entities, services, owners, dependencies and relevant evidence sources.
A bounded register of open questions, evidence gaps and proportionate next actions for the agreed context.
What success looks like
The organisation can identify who owns each priority question and which evidence supports the current view.
Incident and resilience questions have a documented next verification step and escalation route.
Cross-border perimeter
Cross-border entities, critical dependencies, suppliers and evidence custodians are recorded explicitly.
Common security themes are separated from local authority, reporting and language questions.
Limits and dependencies
The review does not decide national applicability or replace advice on local implementation and reporting duties.
The output is limited to the entities, services, suppliers, records and time window agreed for the assignment.
Engagement levels
A first, bounded review of roles, evidence and open questions. It identifies what to clarify; it is not assurance, an audit or a certification.
An evidence-led conclusion for the agreed scope, evidence date and criteria. It does not create a universal compliance conclusion.
A more formal examination of agreed criteria, records and controls. The audit scope, method and reporting basis are set in the engagement letter.
Certification is a separate route performed by an appropriate certification body. This service does not issue a certificate or replace that body’s process.
Scope note
This is a bounded evidence review around selected NIS2-related questions. It is not legal advice, an audit opinion, regulatory approval or a certification.
Official contacts
Maison Sasson ltd - United Kingdom