Cyber resilience

What is Compliance & Governance and when do you choose it?

Compliance & Governance: grip on NIS2, ISO 27001, NEN processes, audits and supplier questionnaires, with demonstrable controls.

Need support? +31 45 303 0003 Advice or a quote? +31 45 303 0232

Available across the EU, delivered remotely.

More and more organisations face requirements around information security, risk management, privacy, cyber resilience and demonstrable controls. Think of NIS2, ISO 27001, supplier audits, cyber insurance and internal governance requirements.

Compliance & Governance helps organisations gain insight into the risks, responsibilities, technical measures and documentation needed to maintain demonstrable control over the ICT environment.

With Compliance & Governance, B/Focused supports organisations in improving cyber resilience, preparing for audits and clarifying controls without immediately falling into complex certification processes.

Why do organisations choose Compliance & Governance?

Insight into Compliance requirements

More and more organisations face requirements around information security, privacy, cyber resilience and governance. Gaining insight into relevant laws and regulations creates clarity about responsibilities, risks and required measures.

Increased Cyber resilience

Compliance is not only about documentation but also about demonstrable controls. By paying attention to monitoring, back-up, security awareness, access management and risk management, the organisation’s cyber resilience is strengthened.

Demonstrable Controls

Customers, auditors, cyber insurers and regulators increasingly ask how risks are managed. Recording processes, measures and responsibilities creates demonstrable control over the ICT environment.

Support with Audits & Questionnaires

Many organisations face supplier questionnaires, audit requests or compliance checks. A structured approach helps provide quicker insight into security measures, processes and documentation.

Better Documentation & Governance

A well-documented environment helps organisations manage changes, risks, responsibilities and procedures better. This increases continuity and reduces dependence on individual knowledge.

Part of Technology Alignment

Compliance is not separate from the ICT strategy. Within Technology Alignment, we periodically review topics such as lifecycle management, back-up strategies, cyber resilience, network architecture, Microsoft 365, documentation and compliance-related points of attention.

Which components can be part of a Compliance & Governance process?

NIS2 & Cyber resilience

Support with risk analyses, cyber resilience measures, governance requirements and demonstrable controls that contribute to NIS2-related obligations.

ISO 27001 Support

Support with the ICT-related components of ISO 27001 such as risk management, information security, documentation, technical measures and audit preparation.

NEN Standards

Support with technical documentation, management processes, availability, continuity and other ICT-related components that are recorded within NEN processes.

ISO Quality Management

Support with process descriptions, documentation, supplier management, change management and other ICT components that are part of quality and improvement processes.

Technology Alignment

With Technology Alignment, we periodically review lifecycle management, Microsoft 365, documentation, security measures, infrastructure, back-up strategies and compliance points of attention.

Security awareness & Risk management

Managed SOC, Security Awareness, Penetration testing, Back-up & Disaster Recovery and other measures that contribute to demonstrable management of cyber risks.

Documentation & Governance

Documentation of processes, systems, infrastructure, responsibilities and technical measures so that audits and checks can be prepared more easily.

Audit preparation & Supplier questionnaires

Support with supplier assessments, security questionnaires, cyber insurance, audit requests and making controls demonstrable.

Technology Alignment

Within our Technology Alignment approach, we periodically review lifecycle management, Microsoft 365, cyber resilience, documentation, back-up strategies, network architecture and compliance-related points of attention.

Documentation & Recording

Many audits and assessments depend on demonstrability. That is why we support organisations in recording systems, processes, changes, responsibilities and technical measures.

Measures in Practice

Compliance does not only consist of policy and procedures. Controls such as monitoring, back-up, Security Awareness, penetration testing, access management and network segmentation contribute to demonstrable cyber resilience.

Continuous Improvement

Laws, regulations, technology and risks continuously develop. That is why we look not only at the current situation but also at future developments so that organisations maintain grip on their ICT environment.

Practical example: Compliance as part of Technology Alignment

An organisation working on a NEN process asked additional questions about its ICT environment and compliance requirements. During the assessment, it turned out that a large part of these questions were already covered within our Technology Alignment approach.

The remaining points of attention were worked out together with the customer and then included in our Technology Alignment methodology so that they are automatically taken into account in future assessments.

During the analysis, several improvement points also emerged. These were translated into concrete project proposals that allowed the organisation to further strengthen its ICT environment. At the same time, it turned out that some of the measures proposed from the standards framework were already covered in practice in a different way. This prevented additional investments without making concessions to the underlying objectives.

This approach ensures that compliance is not only used to make risks visible, but also to prevent unnecessary investments and implement improvements in a targeted way.

Technology Alignment

Many compliance, audit and governance issues touch on topics that are periodically reviewed within Technology Alignment.

Think of:

  • Lifecycle Management
  • Microsoft 365
  • Back-up & Disaster Recovery
  • Cyber resilience
  • Network & Infrastructure
  • Documentation & Governance
  • Compliance-related points of attention

These periodic reviews create insight into risks, improvement points and measures relevant to compliance, audit and certification processes.

More about Technology Alignment

Frequently asked questions

What exactly does B/Focused's Compliance & Governance involve?

Compliance & Governance helps organisations gain insight into the risks, responsibilities, technical measures and documentation needed to maintain demonstrable control over the ICT environment. This allows you to improve cyber resilience and prepare for audits without immediately entering a heavy certification process.

Which laws, regulations or standards can B/Focused help with?

B/Focused supports the ICT-related components of NIS2, ISO 27001, NEN standards and ISO quality management. This involves risk management, information security, documentation, technical measures and audit preparation.

Does B/Focused also help with questionnaires from suppliers or customers?

Yes, B/Focused supports supplier assessments, security questionnaires, cyber insurance and audit requests. A structured approach helps provide quicker insight into security measures, processes and documentation.

What is the connection between Compliance & Governance and Technology Alignment?

Compliance is not separate from the ICT strategy and is addressed within Technology Alignment. This periodically reviews topics such as lifecycle management, back-up strategies, cyber resilience, network architecture, Microsoft 365, documentation and compliance-related points of attention.

Can you give an example of how this works in practice?

At an organisation working on a NEN process, it turned out that a large part of the additional questions were already covered within our Technology Alignment approach. The remaining points of attention were worked out together with the customer, which prevented unnecessary investments and allowed improvements to be implemented in a targeted way.

Getting acquainted · which step suits your organisation?

You will be speaking with Ralph Dykstra

Founder and owner of B/Focused

A conversation of about 30 minutes in which we get to know your organisation and look at the challenges, risks and opportunities in your IT environment.

Advice or a quote? Sales
+31 45 303 0232
Need support? Service desk
+31 45 303 0003