Cybersecurity · GRC
See the assets.Understand the risks.Act methodically.
We help organisations strengthen governance, manage cybersecurity risk and address compliance requirements, including NIS2 and ISO 27001.
Why GRC
Useful security starts with a clear view.
Governance, risk and compliance connect obligations, critical assets and practical decisions. We help organisations structure that view and prioritise their efforts.
GovernanceGive the cybersecurity programme a clear direction.
Cybersecurity governance
Governance connects business objectives, responsibilities, security policies, indicators and management decisions. It prevents cybersecurity from becoming a collection of isolated tools.
We help structure measurable guidelines, responsibility mapping and a readable path for IT, OT, compliance and management teams.
IT/OT riskSee the assets, understand exposure and prioritise treatments.
Risk management
Useful risk assessment starts with visibility: critical assets, dependencies, exposure, threat scenarios, business impacts and existing measures.
The goal is to turn cyber, IT, OT and cyber-physical risks into concrete decisions: accept, reduce, transfer or monitor, with evidence and understandable priorities.
ComplianceConnect NIS2, ISO 27001 and CyFun requirements to real practices.
Cybersecurity compliance
NIS2, ISO 27001, CyFun and sector requirements become useful when they are connected to assets, risks, processes and available evidence.
We help translate frameworks into pragmatic roadmaps, verifiable actions and decisions adapted to the organisation's context.
Cross-sector experience
Different environments, the same need for pragmatism.
- Healthcare
- Transport
- Physical security
- Critical infrastructure
- Public sector
- Banking and financial services
A dual perspective
Professional practice and academic research.
NGUIS combines professional experience in cybersecurity GRC, NIS2, ISO 27001, IEC 62443 and risk assessment with academic research on compliance for software and cyber-physical systems. This dual perspective helps connect regulatory requirements with the technical reality of IT, OT and critical environments.

Institutional watch
Latest cybersecurity news.
The five most recent publications from three Belgian and European institutional sources.
Let us talk
Your context deserves a tailored response.
Tell us briefly about your organisation, obligations or the risk you want to understand and manage.
info@nguis.com