GRC should improve the quality of decisions.

It connects business stakes, critical assets, threats, obligations and security measures.


Three pillars. One complete view.

Each engagement can be run on its own or as part of a wider transformation programme, in France, Switzerland and the European Union.

A — Governance

Decide and steer

  • ✓ Maturity assessment
  • ✓ Governance model
  • ✓ Policy framework
  • ✓ Risk appetite
  • ✓ Executive dashboards
  • ✓ CISO / GRC as a Service

B — Risk

Understand and prioritise

  • ✓ Risk mapping
  • ✓ Supplier risk
  • ✓ Security in projects
  • ✓ Cyber internal control
  • ✓ Exceptions and risk acceptance
  • ✓ Treatment plans

C — Compliance

Prove and maintain

  • ✓ FINMA · LPD · GDPR
  • ✓ NIS2 · DORA · CMMC
  • ✓ ISO 27001 / 27002 · NIST CSF
  • ✓ CIS Controls · COBIT
  • ✓ PCI DSS · SWIFT CSCF · IEC 62443
  • ✓ Audit preparation and upkeep

Your meta-framework remains the master reference.

We map regulations and frameworks onto your own control model. A single control can then meet several obligations, without stacking frameworks or multiplying evidence.

What this changes

Multi-framework mapping

Tailored controls

Evidence reuse

Consolidated gap analysis

Group reporting

Six engagements built to deliver.

A clear scope, precise deliverables and findings presented for operational teams and decision-makers alike.

Maturity assessment

Get an objective view of your level of control and prioritise investments.

Heatmap · Gap analysis · Roadmap

Cyber risk mapping

Link threat scenarios to assets, processes and business impacts.

Register · Scenarios · Treatment plans

Cyber governance

Clarify who decides, who executes, who controls and how risks are escalated.

Target model · RACI · KPI / KRI

Compliance & frameworks

Translate FINMA, LPD, GDPR, NIS2, DORA, CMMC and your internal frameworks into actionable, demonstrable measures.

Applicability · Meta-framework mapping · Compliance plan

Supplier risk

Segment third parties, assess dependencies and steer remediation plans.

TPRM policy · Scoring · Third-party register

Cyber internal control

Check that requirements are applied and maintained over time.

Control catalogue · Testing · Tracking dashboard


From assessment to industrialisation.

A method suited to your maturity, your regulatory context and your organisation's priorities.

Four steps

We start at the step that matches what already exists.

  1. 01 Assess — understand the context, critical assets, requirements and gaps.
  2. 02 Structure — define responsibilities, processes, policies and decision rules.
  3. 03 Implement — turn recommendations into managed actions, controls and evidence.
  4. 04 Industrialise — set up continuous monitoring, automation and executive reporting.

Engagement formats

From a few days of scoping to ongoing support.

  • A

    Rapid assessment

    Short scoping to identify priorities.

  • B

    Fixed-price engagement

    Defined scope, deliverables and timeline.

  • C

    Transformation programme

    Support across several GRC workstreams.

  • D

    Part-time expertise

    Ongoing support or interim engagement.

Expertise grounded in operational reality.

The Federation of Cyber Experts brings together complementary expertise to address governance, risk and compliance alongside technical security.

Pragmatic approach

Deliverables designed to be used, managed and maintained.

Multidisciplinary view

Governance, risk, compliance, audit, technical security and resilience.

Language for decision-makers

Findings linked to impacts, trade-offs and priorities.

Skills transfer

Support that builds lasting team autonomy.

Let's talk about your
GRC priorities.

Initial assessment · Review of an existing set-up · Transformation programme