Expertise

Deep expertise.
Practical application.

We work across the full landscape of security and risk — from governance and strategy to architecture and compliance. Every area feeds into your managed office, tailored to what your organisation actually needs.

Where organisations come to us

Start with the situation you’re in.

Most organisations don’t arrive looking for a “capability.” They arrive with a problem, a deadline, or a question from the board. Find yours.

A new regulation now applies to us

NIS2, the EU AI Act, CRA, or DORA has landed — you need to know what it means and what to do.

See the regulations

⟶

A new regulation now applies to us

NIS2, the EU AI Act, CRA, or DORA has landed — you need to know what it means and what to do.

See the regulations

⟶

We’re adopting AI

You’re deploying AI and need governance, risk, and EU AI Act readiness before it scales.

AI Security & Compliance

⟶

We’re adopting AI

You’re deploying AI and need governance, risk, and EU AI Act readiness before it scales.

AI Security & Compliance

⟶

We’re worried about cybercrime

Organised cybercrime is the most likely cause of serious disruption — and you want your exposure understood and your response planned.

Organised cybercrime

⟶

We’re worried about cybercrime

Organised cybercrime is the most likely cause of serious disruption — and you want your exposure understood and your response planned.

Organised cybercrime

⟶

A supplier was breached

A partner or service provider has been hit, and you need to understand and manage your supply-chain exposure.

Supply-chain risk

⟶

A supplier was breached

A partner or service provider has been hit, and you need to understand and manage your supply-chain exposure.

Supply-chain risk

⟶

We need to manage insider risk

Accidental or deliberate, the risk from inside needs governance and proportionate controls — handled with care.

Insider risk

⟶

We need to manage insider risk

Accidental or deliberate, the risk from inside needs governance and proportionate controls — handled with care.

Insider risk

⟶

We’re facing an audit or certification

ISO 27001, BIO2.0, or a client requirement — and you need to be ready.

Frameworks & standards

⟶

We’re facing an audit or certification

ISO 27001, BIO2.0, or a client requirement — and you need to be ready.

Frameworks & standards

⟶

We’re migrating to cloud or transforming

Major change is coming, and security needs to be designed in — not bolted on afterwards.

Architecture & Transformation

⟶

We’re migrating to cloud or transforming

Major change is coming, and security needs to be designed in — not bolted on afterwards.

Architecture & Transformation

⟶

The board wants assurance

Leadership needs clear answers on risk and security — and someone accountable for them.

Governance & Risk

⟶

The board wants assurance

Leadership needs clear answers on risk and security — and someone accountable for them.

Governance & Risk

⟶

We’ve outgrown ad hoc security

Security has become too important to handle informally, but a full internal team isn’t realistic yet.

The Managed Office

⟶

We’ve outgrown ad hoc security

Security has become too important to handle informally, but a full internal team isn’t realistic yet.

The Managed Office

⟶

Featured · Timely

The regulations shaping the next few years.

New EU regulation is the most common reason organisations come to us. Here’s where the pressure is right now.

Not sure where you stand?

Start with a free scoping check to see what applies to you. From there, a focused assessment — like a NIS2 Gap Analysis or AI Readiness Scan — gives you the full picture, and can lead straight into a managed partnership.

Not sure where you stand?

Start with a free scoping check to see what applies to you. From there, a focused assessment — like a NIS2 Gap Analysis or AI Readiness Scan — gives you the full picture, and can lead straight into a managed partnership.

Topics & Regulations

Browse everything we work across.

Regulations, frameworks, and specific topics — each tied to the capability it sits under. Filter by capability to find what’s relevant to you.

All

Governance

Risk

Strategy

Architecture & Transformation

Compliance

Regulation

Compliance

NIS2

The EU's updated cybersecurity directive expanded scope across 18 sectors, strict incident reporting, supply-chain security, and personal accountability for management.

Explore

⟶

Regulation

Compliance

NIS2

The EU's updated cybersecurity directive expanded scope across 18 sectors, strict incident reporting, supply-chain security, and personal accountability for management.

Explore

⟶

Regulation

Compliance

EU AI Act

The world's first comprehensive AI regulation — a risk-based framework with obligations that scale from transparency to strict conformity, for organisations that build or use AI.

Explore

⟶

Regulation

Compliance

EU AI Act

The world's first comprehensive AI regulation — a risk-based framework with obligations that scale from transparency to strict conformity, for organisations that build or use AI.

Explore

⟶

Regulation

Compliance

Cyber Resilience Act (CRA)

EU security requirements for products with digital elements — secure-by-design, vulnerability handling, and lifecycle obligations for anyone making or selling connected hardware and software.

Explore

⟶

Regulation

Compliance

Cyber Resilience Act (CRA)

EU security requirements for products with digital elements — secure-by-design, vulnerability handling, and lifecycle obligations for anyone making or selling connected hardware and software.

Explore

⟶

Regulation

Compliance

DORA

The EU's digital operational resilience regulation for the financial sector — covering ICT risk management, incident reporting, resilience testing, and third-party oversight.

Explore

⟶

Regulation

Compliance

DORA

The EU's digital operational resilience regulation for the financial sector — covering ICT risk management, incident reporting, resilience testing, and third-party oversight.

Explore

⟶

Framework

Compliance

ISO 27001

The international standard for information security management. We design, implement, and run the ISMS — and take you to certification and beyond.

Explore

⟶

Framework

Compliance

ISO 27001

The international standard for information security management. We design, implement, and run the ISMS — and take you to certification and beyond.

Explore

⟶

Framework

Compliance

BIO2

The information-security baseline for Dutch government — the successor to the BIO, aligned to ISO 27001/27002 and more strongly risk-based.

Explore

⟶

Framework

Compliance

BIO2

The information-security baseline for Dutch government — the successor to the BIO, aligned to ISO 27001/27002 and more strongly risk-based.

Explore

⟶

Framework

Compliance

NEN 7510

The Dutch standard for information security in healthcare — an ISO 27001-based management system with healthcare-specific controls for protecting patient data.

Explore

⟶

Framework

Compliance

NEN 7510

The Dutch standard for information security in healthcare — an ISO 27001-based management system with healthcare-specific controls for protecting patient data.

Explore

⟶

Topic

Risk

Organised Cybercrime

The most likely cause of serious disruption for most organisations. We help you understand your exposure, prioritise defences, and govern your response — calmly and proportionately.

Explore

⟶

Topic

Risk

Organised Cybercrime

The most likely cause of serious disruption for most organisations. We help you understand your exposure, prioritise defences, and govern your response — calmly and proportionately.

Explore

⟶

Topic

Risk

Supply-Chain & Third-Party Risk

Your security is only as strong as your suppliers'. We help you assess, govern, and continuously manage third-party and supply-chain risk — now a direct requirement under NIS2 and DORA.

Explore

⟶

Topic

Risk

Supply-Chain & Third-Party Risk

Your security is only as strong as your suppliers'. We help you assess, govern, and continuously manage third-party and supply-chain risk — now a direct requirement under NIS2 and DORA.

Explore

⟶

Topic

Risk

Insider Risk

Not every threat comes from outside. We help you manage insider risk — accidental and deliberate — through governance, culture, and proportionate controls, handled with care.

Explore

⟶

Topic

Risk

Insider Risk

Not every threat comes from outside. We help you manage insider risk — accidental and deliberate — through governance, culture, and proportionate controls, handled with care.

Explore

⟶

Topic

Risk

Physical & Environmental Risk

Floods, fire, and power loss don't just damage buildings — they take systems and data offline. We help you understand and govern the physical risks to your IT, and plan for continuity.

Explore

⟶

Topic

Risk

Physical & Environmental Risk

Floods, fire, and power loss don't just damage buildings — they take systems and data offline. We help you understand and govern the physical risks to your IT, and plan for continuity.

Explore

⟶

Topic

Architecture & Transformation

Enterprise Security Architecture

A business-driven, enterprise-wide architecture that links security to strategy — from business context down to logical and physical design, so every control traces back to a goal.

Explore

⟶

Topic

Architecture & Transformation

Enterprise Security Architecture

A business-driven, enterprise-wide architecture that links security to strategy — from business context down to logical and physical design, so every control traces back to a goal.

Explore

⟶

Topic

Risk

Risk Management

The living discipline of identifying, assessing, treating, and monitoring risk — aligned to your appetite, so you take the right risks knowingly.

Explore

⟶

Topic

Risk

Risk Management

The living discipline of identifying, assessing, treating, and monitoring risk — aligned to your appetite, so you take the right risks knowingly.

Explore

⟶

Topic

Strategy

Security Strategy

Setting direction and priorities for security — a sequenced, realistic roadmap aligned to your objectives and risk, not a wish list of everything.

Explore

⟶

Topic

Strategy

Security Strategy

Setting direction and priorities for security — a sequenced, realistic roadmap aligned to your objectives and risk, not a wish list of everything.

Explore

⟶

Topic

Architecture & Transformation

Information Security Architecture

The structured design of security controls across your technical estate — identity, network, data, cloud, endpoints — as one coherent system aligned to your risks.

Explore

⟶

Topic

Architecture & Transformation

Information Security Architecture

The structured design of security controls across your technical estate — identity, network, data, cloud, endpoints — as one coherent system aligned to your risks.

Explore

⟶

Topic

Risk

Risk Assessment

The rigorous, repeatable process of identifying and evaluating risk — likelihood, impact, and priority — so decisions rest on a clear picture, not guesswork.

Explore

⟶

Topic

Risk

Risk Assessment

The rigorous, repeatable process of identifying and evaluating risk — likelihood, impact, and priority — so decisions rest on a clear picture, not guesswork.

Explore

⟶

Topic

Risk

Risk Treatment

Deciding and implementing how to address each risk — mitigate, transfer, avoid, or accept — and tracking what's left, deliberately rather than by default.

Explore

⟶

Topic

Risk

Risk Treatment

Deciding and implementing how to address each risk — mitigate, transfer, avoid, or accept — and tracking what's left, deliberately rather than by default.

Explore

⟶

Topic

Governance

Information Security Governance

Directing and overseeing security: the structures, roles, accountability, and policy that make it a managed discipline rather than something that happens ad hoc.

Explore

⟶

Topic

Governance

Information Security Governance

Directing and overseeing security: the structures, roles, accountability, and policy that make it a managed discipline rather than something that happens ad hoc.

Explore

⟶

TRUSTED BY ORGANISATIONS ACROSS EUROPE

DENSO
DataVance
De Haagse Hogeschool
De Haagse Hogeschool
BUSS Terminal Eemshaven

Looking for expertise in a specific area?

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.