Skip to content

Security & Compliance

Evidence, not policies

Controls, evidence and recovery for estates that fall under NIS2, DORA or sector regulation. Regulators have stopped accepting policy documents as proof — the work is now in the systems.

What the work is

Regulation, translated into engineering

We scope the gap against the requirement that applies to you, then close it on the systems you actually run.

  • Gap assessment against NIS2, DORA and sector requirements
  • Backup, recovery and business continuity, designed and then tested
  • Identity, access and privilege review
  • Hardening, monitoring and audit logging that produces usable evidence
  • Incident response planning and tabletop exercises
  • Supplier and third-party risk, including your own position in someone else’s supply chain

If you supply an essential entity, NIS2 reaches you too. Most companies find this out from a customer questionnaire rather than from a regulator.

Where we sit

On both sides of the supplier line

Malta’s financial services and remote gaming operators sit directly under DORA and MFSA expectations, and their technology suppliers sit under them by extension. We work on both sides of that line.

Penetration testing

We do not run penetration tests ourselves. We coordinate testing with Axelia Cybersecurity and own the remediation that follows, so the findings turn into fixed systems rather than a report you are left holding.

Testing partner: Axelia Cybersecurity

Let’s talk about what you’re running

Tell us about your infrastructure and where it is holding you back. We will come back to you with a considered view, not a sales script.