Cybersecurity
NIS2 & DORA Resilience Testing
Security testing and evidence for NIS2 and DORA, including threat-led penetration testing based on TIBER-EU.
Scope
What we deliver
NIS2 and DORA make regular security testing a legal duty for many organisations in the EU, and supervisors expect evidence. We plan and carry out the testing your obligations require, and give you documentation that management and auditors can use directly.
Gap assessment
Where you stand against NIS2 or DORA testing requirements.
Threat-led testing
Tests based on the threats relevant to your sector, following TIBER-EU.
Vulnerability and penetration tests
The regular technical testing programme.
Third-party risk
Review of critical ICT suppliers and contracts.
Management reporting
Clear status for the management body, which is accountable.
Evidence pack
Documentation prepared for supervisors and auditors.
Frameworks we work with
We combine the testing requirements of each framework into one programme, so you do not test the same systems twice.
NIS2 Art. 21
Cybersecurity risk management measures
NIS2 Art. 23
Incident reporting obligations
DORA Art. 24 to 25
Digital operational resilience testing
DORA Art. 26
Threat-led penetration testing (TLPT)
TIBER-EU
Threat intelligence based red teaming
ISO/IEC 27001
Information security management
What you receive
- 01 Gap assessment and roadmap
- 02 Annual testing programme
- 03 Test reports with remediation plan
- 04 Third-party risk summary
- 05 Evidence pack for supervisors
Questions we often hear
Does NIS2 apply to us?
NIS2 covers medium and large organisations in many sectors, from energy and health to digital services and manufacturing. We help you confirm whether you are in scope.
Can you carry out a full DORA TLPT?
We deliver threat-led testing based on TIBER-EU and can act as the red team provider. Formal TLPT is coordinated with your supervisor, and we help you prepare for that process.
Do you also help with Lithuanian requirements?
Yes. Lithuania transposed NIS2 into national law. We take the national requirements and reporting rules into account.
Related
Web Application Penetration Testing
OWASP-aligned manual and automated testing of web apps, APIs and authentication flows.
Learn moreNetwork & Infrastructure Testing
Internal and external network assessments, Active Directory and cloud perimeter reviews.
Learn moreMobile Application Security
iOS and Android testing based on OWASP MASVS, including reverse engineering.
Learn more