EmberKat

Security & compliance engineering

Map security requirements to systems, owners and evidence.

NIS2, ISO 27001, product-security and customer requirements become technical controls, implementation work, accountable owners and review evidence.

Discuss the scope
Typical durationUsually 2–4 weeks
Starting priceFrom €12,500 excl. VAT
Commercial basisWritten scope and proposal

Service definition

What the engagement produces

The assessment identifies affected systems, control gaps, required engineering changes, accountable owners and evidence needed for review or audit.

A sequence of sealed graphite artefacts and transparent evidence cases joined by one uninterrupted ember-coloured line.
Evidence chain

Security evidence is strongest when it is produced by delivery: implementation, verification, approval and closure stay connected instead of being reconstructed later.

Scope

Work included in the scope

  1. 01

    Security architecture and trust-boundary review

  2. 02

    NIS2 technical readiness

  3. 03

    ISO 27001 technical-control readiness

  4. 04

    Product-security, SBOM and vulnerability processes

  5. 05

    DevSecOps and secure software delivery

  6. 06

    Control implementation and evidence requirements

Client problems

Use this service when

  1. 01

    Policies exist but technical ownership is unclear.

  2. 02

    Findings return after nominal closure.

  3. 03

    A scanner backlog is used as the risk model.

  4. 04

    Evidence is assembled manually before every review.

Deliverables

Documents and decisions provided

  1. 01

    Security architecture decision record

  2. 02

    Technical control and gap map

  3. 03

    Prioritised engineering backlog

  4. 04

    Control ownership and evidence matrix

  5. 05

    Readiness or remediation plan

From the glossary

remediation
Actually fixing what an assessment found — as opposed to recording it.
ISO 27001
An international standard for how an organisation runs its information security — the management side, not the product.
DevSecOps
Building security checks into the ordinary process of shipping software, rather than testing at the end.
NIS2Directive (EU) 2022/2555
An EU law that holds organisations in important sectors — health, finance, energy, transport, digital — responsible both for their own security and for checking their suppliers.
SBOMSoftware Bill of Materials
A list of every component inside a piece of software — an ingredients label, in a form a machine can read.
The full glossary

Related engagement

Findings Translation Sprint

10 business days. Starting at €6,500 excl. VAT.

View engagement