
PRACTICE 02 — TRANSFORMATION
DORA, NIS2, operational resilience — delivered as a better way of working, not another binder for the shelf.
THE PROBLEM
0
PAGES OF POLICY HAVE EVER
STOPPED AN ATTACK ON THEIR
OWN. PEOPLE AND HABITS DO.
The pattern is familiar. A regulation lands, a programme is stood up, a big firm arrives with a maturity model — and a year later you own a few hundred pages nobody reads and a set of controls people quietly work around.
DORA and NIS2 aren't document requests. They ask whether your firm actually behaves differently under stress — and that's a question about your operating model, not your paperwork.
HOW A PROGRAMME RUNS
WEEKS 0–6
We map how security actually works day to day, not how the documents say it does. You get an honest picture of the gaps, in priority order.
WEEKS 6–10
Operating model, controls and priorities agreed with your executives. The change has owners before it has milestones.
WEEKS 10–26
We work inside your teams — retiring controls nobody can explain, building fewer and sharper ones, and testing them until they hold.
FROM WEEK 26
Capability moves across to your people, cadence by cadence. What still works a year later is the point.
WHERE WE'RE USUALLY CALLED IN
RELATED
EU digital operational resilience, in force since January 2025. →
EUThe wider EU cyber baseline, with board accountability. →
SECTORHow we work with energy, water, transport, health and digital operators. →
CASEWhat this looks like in practice inside a UK government department. →
TOOLThe system we steer programmes with — scope decisions, framework coverage and board packs from live data. →
We'd rather leave you a better firm than a thicker binder.
Start a conversation