Cybersecurity · GRC

See the assets.Understand the risks.Act methodically.

We help organisations strengthen governance, manage cybersecurity risk and address compliance requirements, including NIS2 and ISO 27001.

Why GRC

Useful security starts with a clear view.

Governance, risk and compliance connect obligations, critical assets and practical decisions. We help organisations structure that view and prioritise their efforts.

GovernanceGive the cybersecurity programme a clear direction.

Cybersecurity governance

Governance connects business objectives, responsibilities, security policies, indicators and management decisions. It prevents cybersecurity from becoming a collection of isolated tools.

We help structure measurable guidelines, responsibility mapping and a readable path for IT, OT, compliance and management teams.

  • GRC
  • policies
  • objectives
  • indicators
IT/OT riskSee the assets, understand exposure and prioritise treatments.

Risk management

Useful risk assessment starts with visibility: critical assets, dependencies, exposure, threat scenarios, business impacts and existing measures.

The goal is to turn cyber, IT, OT and cyber-physical risks into concrete decisions: accept, reduce, transfer or monitor, with evidence and understandable priorities.

  • risk assessment
  • IT/OT
  • critical assets
  • risk treatment
ComplianceConnect NIS2, ISO 27001 and CyFun requirements to real practices.

Cybersecurity compliance

NIS2, ISO 27001, CyFun and sector requirements become useful when they are connected to assets, risks, processes and available evidence.

We help translate frameworks into pragmatic roadmaps, verifiable actions and decisions adapted to the organisation's context.

  • NIS2
  • ISO 27001
  • IEC 62443
  • CyFun
  • evidence

Cross-sector experience

Different environments, the same need for pragmatism.

  • Healthcare
  • Transport
  • Physical security
  • Critical infrastructure
  • Public sector
  • Banking and financial services

A dual perspective

Professional practice and academic research.

NGUIS combines professional experience in cybersecurity GRC, NIS2, ISO 27001, IEC 62443 and risk assessment with academic research on compliance for software and cyber-physical systems. This dual perspective helps connect regulatory requirements with the technical reality of IT, OT and critical environments.

Portrait of Guillaume Nguyen

Institutional watch

Latest cybersecurity news.

The five most recent publications from three Belgian and European institutional sources.

Loading news…

Let us talk

Your context deserves a tailored response.

Tell us briefly about your organisation, obligations or the risk you want to understand and manage.

info@nguis.com