Home / Services / Regulatory Services & Advisory

Regulatory obligations turned into competitive advantage.

GDPR, NIS2, DORA and the AI Act redefine the responsibilities of those who run an organisation. We help you understand what applies to you, design the right measures and oversee them over time.

Service areas

Three domains, one governance system.

Governance, Risk & Compliance

  • Governance and compliance assessment
  • Gap analysis against NIS2 and ISO/IEC 27001
  • Risk and maturity assessment
  • Framework and control design
  • Compliance audit
Output: policies & procedures · control library · operating model · remediation plan · executive report

Data Protection & Privacy

  • GDPR assessment and gap analysis
  • DPIA – data protection impact assessment
  • Privacy framework and documentation
  • Records of processing activities
  • Audit and ongoing support
Output: privacy policies · privacy framework · records of processing · remediation plan

Operational Resilience & BC

  • Business Impact Analysis (BIA)
  • Operational risk assessment
  • BCM framework (ISO 22301)
  • Crisis management plan
  • Resilience audit (DORA, NIS2)
Output: BIA report · BCM framework · crisis management plan · executive report
Method

Build on your starting point, activate only the essentials.

Technical implementation of the designed measures remains with your teams or technology providers. Where monitoring and response are needed, our SOC plugs in directly.

Ongoing services

Senior expertise, on a subscription.

vCISO

Virtual CISO

Security leadership as a service: strategic direction, KPIs and KRIs, support to the Board and on investments, coordination of training.

Included: security strategy · KPI dashboard · roadmap · periodic reports · audit report
vDPO

Virtual DPO

An external DPO under GDPR Arts. 37–39: compliance monitoring, audits, opinions, data breach support and training.

Included: privacy plan · DPIA · opinions · records of processing

Virtual CISO and Virtual DPO are delivered on an annual subscription, priced on scope, days and service level.

FAQ

Advisory frequently asked questions

How do we know if NIS2 applies to us?

It depends on sector, size and role in the supply chain. We check this with you in the introductory meeting and, if needed, support your registration with the national authority.

Can we activate a single service?

Yes, every service is modular. Many clients start with a gap analysis and then decide how to proceed.

How is pricing defined?

Based on tier (Professionals, SMEs, Enterprise/Public) and scope. The quote follows a free introductory meeting: email us at info@cycalhub.com.