Advisory and governance
Beyond compliance: we build resilience
Spirity helps leadership teams understand their real cyber risks, meet regulatory expectations, and build a security roadmap that is practical, business-focused, and ready for audits.
Three things a security advisor is actually for
Strategic roadmapping
We help you identify security priorities, plan improvements, and align cybersecurity investments with business goals.
Regulatory alignment
We support readiness for NIS2, DORA and ISO 27001 — and for the twenty or so other frameworks a customer, a regulator or a US parent company can put in front of you.
Executive guidance
We translate cyber risk into business-level decisions, reports, and priorities for leadership teams.
The other frameworks we assess against
NIS2, DORA and ISO 27001 are what European clients ask for most. They are not the only obligations that arrive, and each of these is a fixed-scope assessment rather than a programme.
Assess, architect, sustain
The same three movements on every engagement — the depth of each is what changes.
- 01
Assess
We review your current security posture, compliance needs, risks, and business priorities, and turn them into a picture leadership can act on.
- 02
Architect & deploy
Our experts design a governance and risk framework tailored to you, integrating strategic transformation with technical controls to build a compliant digital foundation.
- 03
Optimize & sustain
We provide continuous oversight and board-level advisory so your organization stays resilient as threats and regulations change.
Where advisory work concentrates
Five areas cover the majority of what leadership teams ask us to fix.
- 01
Governance & strategy
Define policies, responsibilities, reporting structures, and leadership ownership for cybersecurity.
- 02
Risk management
Identify, evaluate, and prioritize cyber risks based on their real business impact rather than on generic severity scores.
- 03
Compliance & audit readiness
Prepare for NIS2, DORA, ISO 27001, customer audits, and security questionnaires — with the evidence already assembled.
- 04
Business transformation
Support secure modernization, cloud adoption, and process improvement without adding unnecessary risk.
- 05
Third-party risk
Extend your security perimeter to vendors and partners so a weak link outside the organization does not become a breach inside it.
Three programmes this work often becomes
There is an audit date
When the advisory question turns out to be a deadline — NIS2, ISO 27001, or a customer’s audit — the work becomes a risk-based programme that ends in a mock-audited GO or NO-GO decision.
You are twenty to a few hundred people
At that size the problem is rarely that nobody knows what to do. It is that nobody owns it. What the published measurements say about companies this size, and which service answers which part.
The audit already happened
When the findings are already written down and the deadline was somebody else’s to set, the work is remediation: ranked fixes with owners and dates, and the evidence that they actually run.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
Scope and duration, not quality. Advisory is bounded work with a beginning and an end — a risk assessment, a roadmap, a governance framework, readiness for one particular standard. A vCISO is somebody holding the security leadership role continuously: making the decisions week to week and answering for them. Most organisations start with the first and move to the second when they realise the decisions keep arriving whether or not anyone is there to make them. Some go the other way and use advisory to sanity-check a CISO they already employ. If you are not sure which you need, that is a conversation rather than a proposal.
Because the report is the cheap part and we would rather not be paid for it alone. Every recommendation carries an owner, a date and a position in a sequence — and the sequence is what most reports skip, which is how a hundred and forty findings arrive at once and none of them get done. Where you want it, the same team carries the work through; where we are not the right people to do it, we say so and track it to completion anyway rather than closing the engagement at handover. And if what you actually want is the document — for a board, a buyer, an auditor — tell us, and we will scope that instead, for less.
With what you have, not what you ought to have. The first movement is always assessment: your current posture, the obligations that apply to you, your real risks and your business priorities, turned into a picture leadership can act on rather than a list of findings. That is deliberately the cheapest part of any engagement, because it is what makes everything after it arguable. There is also a free self-assessment on this site that takes a few minutes — for a smaller organisation it is often enough to make the first conversation a useful one.
By starting from business impact rather than from a severity score. A critical-rated vulnerability on a system nobody can reach and which holds nothing is not your first problem; an unremarkable misconfiguration on the system your revenue runs through is. So the assessment has to establish what genuinely matters to you before it ranks anything — which systems, which data, which processes you could not be without for a day, and who would notice. Generic severity is what produces a risk register nobody reads and a roadmap nobody follows.
Not “yes” — nobody credible says yes. What a board can act on is a small number of things: where you stand against the standard you have chosen, what has changed since they last asked, what risk you are carrying deliberately, and what you need from them in order to change it. Translating between technical reality and that conversation is one of the three things this service exists for, and reporting in that shape is part of what you get rather than something your team assembles afterwards at midnight.
With whether they apply to you and over what scope, which is less obvious than it sounds and is where most of the wasted effort goes. After that the work is much the same whichever regime it is: settle what is in scope, measure against the requirements, rank the gaps by risk and by how hard they are to close, and assemble the evidence as you go rather than in the fortnight before an audit. The order matters more than the framework — governance, knowing what you have and a risk picture come before monitoring and detection, whatever the standard is called. And if you already have a date in the calendar, that is a different and more urgent shape of engagement.
Either, and we will tell you which before you commit to anything. We do implementation work — deploying and configuring security tooling, hardening, firewall and network work — so the advice can be carried through by the people who wrote it, which avoids the translation losses that make good roadmaps fail. But the advice does not depend on our doing it. Some of it belongs with your own team, and some with a supplier you already have, and saying so is part of what you are paying us for. A recommendation that can only be delivered by the firm that made it is worth reading twice.
That is most of the value, and it is easier for us than for somebody on your payroll. We have written the comparison that argued against a product we could have sold. Our hardening work routinely defers findings rather than recommending them, where the change carries more risk than the gap does. And we will say when something is not worth fixing, which is a harder sentence to write than a list of everything that could theoretically be improved. We are also certified against ISO/IEC 27001 ourselves — somebody audits us on the same basis we are asking you to accept, which makes the bluntness easier in both directions.
Three shapes. A paid one-off assessment runs in weeks at a fixed price, and is the usual way in. A fixed-scope project — a governance framework, a roadmap, readiness for one standard — is scoped and priced up front against a defined deliverable, so you know what you are buying before you buy it. Continuous advisory, where we hold the role rather than visit it, is the vCISO engagement: monthly, on a twelve-month minimum. What moves the number in every case is scope — how many systems and sites are in it, which regime applies, and how much of the work you want to keep in-house.
Ready to get started?
Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.