Risk Management & Resilience
We help organisations establish practical risk, control and resilience arrangements that support decisions, ownership and recovery — not only reporting.
When organisations call us
- A risk register exists but has never changed a decision.
- There is no approved risk appetite — so every dispute is decided ad hoc.
- Dependence on technology, cloud, vendors and data grows faster than the control environment.
- Incidents repeat and remediation does not close; resilience obligations (DORA, NIS2, CRA reporting from September 2026) are approaching or already apply.
- The board needs a synthetic view of exposure and actions — one page, current, honest.
Questions we help answer
- Which risks are material to our model — and who owns each response?
- What is our tolerance, in words a manager can apply on a Tuesday afternoon?
- Are our continuity and incident arrangements tested, or theoretical?
- Which third parties could stop the business, and what do we hold against that?
How we can support
- Risk framework design — taxonomy, appetite, assessment cycle and governance that fit your scale.
- Operational and ICT resilience — critical services mapping, scenarios, testing plans; DORA-aligned where relevant.
- Third-party and concentration risk — tiering, requirements, monitoring and exit thinking.
- Incident readiness — playbooks, roles, communication and reporting duties (including CRA/NIS2 timelines).
- Control environment — linking risks to controls to evidence, without parallel bureaucracies.
- Board risk reporting — top-risk dashboards and escalation thresholds.
Typical work products
Risk taxonomy and appetite statement, risk register with owners, resilience and continuity plans, scenario exercise materials, incident playbooks, third-party risk methodology, board risk dashboard, remediation tracker.
Insights
Could You File an Incident Report in 24 Hours? Test It This Month
From 11 September 2026 the CRA gives manufacturers 24 hours for an early warning after they learn of an exploited…
Read →Third-party risk without the questionnaire flood
Two hundred identical questionnaires produce a folder of PDFs and no control. Triage vendors by criticality, collect evidence from the…
Read →CRA reporting starts 11 September 2026: 21-day countdown for products with digital elements
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents — 24-hour early warning included. The rest…
Read →Bring clarity to the next decision.
A first conversation is free of charge, confidential and without obligation.