Skip to content

Compliance, governance & resilience

Support with cyber-risk management under ZInfV-1 and NIS2

We determine which requirements apply to you, compare the actual state with the required measures and prepare a workable improvement plan.

IVSR helps the organization determine which requirements apply to it, compare the actual state with the required measures and set a workable improvement plan.

The review covers governance, organizational and technical aspects and can connect to the existing cybersecurity-system service.

Possible scope

The scope follows the questions the engagement must answer — not the other way round.

  1. 01An initial assessment of whether the organization is in scope, and identification of critical services, assets and suppliers.
  2. 02Review of risk management, policies, procedures and management accountability.
  3. 03Review of incident handling, business continuity, supply-chain security, vulnerability management, cryptography, access and training.
  4. 04An incident-reporting procedure, with contact persons and notification paths.
  5. 05Review of evidence, minutes, logs and performance criteria.
  6. 06An exercise for leadership and technical teams.
  7. 07A prioritised plan for closing the identified gaps.

You receive

A gap report, an overview of requirements and evidence, a measures register, drafts of the core policies, an exercise plan and a management summary.

Who it is for

For essential and important entities, their suppliers, and organizations that want a comparable level of governance even if not formally in scope.

Limitations and boundaries

  • IVSR provides support in preparing and establishing procedures. The final assessment of compliance depends on actual implementation, sector-specific requirements and the positions of the competent authorities.

Who performs what

IVSR
Research, advisory, methods and training
The full role separation

Next step

A confidential introductory conversation

Every engagement starts with a confidential conversation in which we jointly verify the purpose, the authority and the feasibility. Only then do we propose the scope and the way of working.

Arrange a conversation