MS
MS-Security Consulting
Services catalogue

Cybersecurity consulting services

I provide focused and documented support based on the scope, risks and constraints of each team.

Cybersecurity governance, risk and compliance

I help organizations structure and improve their cybersecurity approach.

  • EBIOS RM risk assessments
  • ISO/IEC 27001:2022 audit preparation
  • Support with DORA and PCI DSS requirements
  • Security policies, procedures and standards
  • Security control planning and monitoring

ISO 27001 consulting

I can support an ISO/IEC 27001:2022 approach by connecting documented requirements with controls operated in practice.

  • Review of scope and applicable requirements
  • Preparation of documentation and evidence
  • Review of policies, procedures and control plans
  • Identification and prioritisation of gaps
  • Preparation for audit discussions

EBIOS RM risk assessment

I support the preparation and documentation of risk assessments based on the EBIOS RM method.

  • Assessment scoping and stakeholder mapping
  • Risk source and feared event documentation
  • Scenario construction and review
  • Risk and security measure prioritisation
  • Actionable reporting for teams

DORA compliance support

I can help structure practical actions around DORA requirements, based on the organization’s scope and maturity.

  • Review of applicable requirements
  • Control and responsibility mapping
  • Digital resilience action tracking
  • Documentation and evidence preparation
  • Coordination with relevant teams

Operational security

I help implement practical controls that contribute to protecting information systems.

  • Access and permission reviews
  • Technical security controls
  • Vulnerability management and monitoring
  • Configuration hardening
  • Phishing awareness campaigns
  • Remediation tracking and documentation

Security controls automation

I design tools and automations to reduce manual work, make controls more reliable and improve reporting.

  • Python scripts
  • REST API integrations
  • Security dashboards and KPIs
  • Recurring control automation
  • Result centralisation
  • Automated reporting and distribution