Services
Partners
Use cases
Clients
Company
Contact
FRENDE

Audit & Advisory GRC

Align cybersecurity with business, regulatory and risk priorities, with deliverables your executive team can act on directly.

Audit & Advisory GRC

Steer cybersecurity, continuously.

We align your security with risk and regulation — assess, build, prove, improve — with deliverables your executive team can act on directly.

ISO 27001NIST CSFNIS2DORA
Continuous improvement loop of governance GOVERNANCE AssessBuildProveImproveISMS
Services

Services in detail

Governance and strategy

Defining the cybersecurity strategy, the policies and the organisation.

Risk management and assessment

Identifying, evaluating and treating risk using recognised methodologies.

Audit and gap analysis

Assessing maturity and gaps against the frameworks you are targeting.

Compliance and regulation

Support on ISO 27001, NIST CSF, the Swiss ICT Minimum Standard, NIS2, DORA, GDPR and FADP.

Table top exercises (TTX)

Crisis simulation exercises to test coordination and decision-making.

Response plans & playbooks (IRP)

Formalising incident response procedures.

BCP, BIA & DRP

Business continuity, impact analysis and disaster recovery.

What you get

Deliverables & approach

  • Deliverables aimed at decisions
  • Recognised frameworks and standards
  • A pragmatic approach, fitted to the business
  • Support over the long term
Request a quote
Frequently asked questions

Frequently asked questions

With the risk assessment, almost always. A certification obtained without one produces a management system describing a theoretical organisation: expensive to maintain and disconnected from real threats. The risk assessment is in any case a requirement of the standard, not an optional first step. If the deadline is contractual — a client, a tender — a gap analysis says within weeks what separates the current state from the target, and what certification will really cost.

They are built to be accepted: policies, risk assessment, statement of applicability and evidence follow the structure the target frameworks expect. An auditor does not validate a document, though, they validate a practice — a process described but not applied shows up in interview. That is why we prefer a short corpus that is genuinely maintained to exhaustive documentation nobody keeps alive.

No, and nobody can do both. Certification is issued by an accredited body, independent from whoever advised: that independence is the very condition of its worth. We prepare you — gap analysis, building the management system, assembling the evidence, support during the audit — and the certification body then steps in. A provider promising the certificate itself is selling either a mock audit or a conflict of roles.

Let's talk about your scope.

A technical conversation, with no commitment, to frame your need and propose the most relevant engagement.