What we do

Risk Management & Resilience

We help organisations establish practical risk, control and resilience arrangements that support decisions, ownership and recovery — not only reporting.

When organisations call us

  • A risk register exists but has never changed a decision.
  • There is no approved risk appetite — so every dispute is decided ad hoc.
  • Dependence on technology, cloud, vendors and data grows faster than the control environment.
  • Incidents repeat and remediation does not close; resilience obligations (DORA, NIS2, CRA reporting from September 2026) are approaching or already apply.
  • The board needs a synthetic view of exposure and actions — one page, current, honest.

Questions we help answer

  • Which risks are material to our model — and who owns each response?
  • What is our tolerance, in words a manager can apply on a Tuesday afternoon?
  • Are our continuity and incident arrangements tested, or theoretical?
  • Which third parties could stop the business, and what do we hold against that?

How we can support

  • Risk framework design — taxonomy, appetite, assessment cycle and governance that fit your scale.
  • Operational and ICT resilience — critical services mapping, scenarios, testing plans; DORA-aligned where relevant.
  • Third-party and concentration risk — tiering, requirements, monitoring and exit thinking.
  • Incident readiness — playbooks, roles, communication and reporting duties (including CRA/NIS2 timelines).
  • Control environment — linking risks to controls to evidence, without parallel bureaucracies.
  • Board risk reporting — top-risk dashboards and escalation thresholds.

Typical work products

Risk taxonomy and appetite statement, risk register with owners, resilience and continuity plans, scenario exercise materials, incident playbooks, third-party risk methodology, board risk dashboard, remediation tracker.

Insights

Bring clarity to the next decision.

A first conversation is free of charge, confidential and without obligation.

Discuss a challenge