Cybersecurity GRC services

Six clearly bounded engagements for Belgian SMEs. Each one has a defined outcome, a defined end, and me doing the work rather than passing it down a chain.

← Back to home

What I do, and what I deliberately do not

I work at governance level: management systems, risk, evidence, audit. That is where an SME gets the most out of a senior pair of hands, and it is where the decisions that matter actually get made. I do not sell technical implementation, tooling or testing, and I will tell you when that is what you need instead.

Every engagement below is scoped with an end in sight. No open-ended retainers, no project that quietly becomes permanent. You should be able to run the result without me, and if you cannot, the engagement was not finished.

Where to start

If you do not yet know how far you are from where you need to be, start with the gap analysis. If a regulator or a customer has put NIS2 on your desk, start with the scoping conversation, because everything downstream depends on whether you are in scope and how you are classified.

If certification is already decided, start with scope and the Statement of Applicability. They are the cheapest place to think carefully and the most expensive place to guess.

Who you are actually hiring

CySLok is one person. I am CISSP certified and a certified ISO 27001 internal auditor, with thirty years in IT and the last ten in cybersecurity. You deal with me from the first conversation to the closing report, and the work is done by the person you met.

That has a limit worth stating: I take on a small number of engagements at a time, so availability is genuinely finite. It also means nothing gets handed to a junior once the proposal is signed.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call