Executive cyber resilience report
Regulatory exposure, overall maturity, critical risks, strategic dependencies, priority decisions, investment needs and roadmap.
Available
Demonstrable resilience, proportionate to the organisation — not a compliance checklist.
Most cybersecurity assessments produce one of two unsatisfactory results: a highly technical report that management cannot translate into decisions, or a compliance checklist that identifies documentation gaps without establishing whether the organisation could keep operating during a cyber crisis. This assessment starts from your critical services and strategic dependencies, then connects regulatory requirements to operational reality — across every country where you operate.
From
Request an assessmentDownload the sample deliverable
Five packages depending on your scope — see below. Final scope and price are agreed after qualification.
The objective is not to demonstrate that controls exist. It is to establish whether they are appropriate, implemented, understood, evidenced, tested, monitored — and capable of supporting business resilience. The assessment examines how your critical services depend on people, information, applications, infrastructure, cloud services, suppliers, digital identities, industrial systems, data flows and contractual arrangements.
Nordic organisations are often highly decentralised and digitally connected. A single company may rely on a group identity platform, several national cloud environments, shared ERP infrastructure, outsourced cybersecurity and remote industrial maintenance. That maturity is a strength — and a concentration of dependency. Add cross-border operations and the picture becomes harder to read: NIS2 is a European directive, but it is implemented through national law.
Finland's Cybersecurity Act (124/2025) has been in force since 8 April 2025, with sector-specific supervision. Denmark's national NIS2 act entered into force on 1 July 2025, with sector-specific competent authorities. Dates, authorities, registration duties and reporting arrangements differ. Assessing a group against a single generic reading of NIS2 produces misleading conclusions. Registration duties differ too: in Finland, in-scope entities had to register by 8 May 2025 and have a risk-management model in place by 8 July 2025; in Denmark, self-registration ran until 1 October 2025.
The final scope is agreed at qualification. It may cover all or part of the following, with a target maturity set per domain according to regulation, business criticality, threat exposure, organisational capacity and cost-benefit.
Findings, assumptions, limitations and recommendations are documented. Unverified elements are clearly distinguished from available evidence.
Regulatory exposure, overall maturity, critical risks, strategic dependencies, priority decisions, investment needs and roadmap.
For each entity: country, activity, sector, potential status, competent authority, registration status, reporting process, unresolved questions and required action.
Services, entities, countries, processes, data, applications, infrastructure, employees, suppliers and recovery objectives.
A six-level model from 0 (not established) to 5 (resilient and adaptive), with current level, target, evidence, gap, priority and owner per domain.
Scenarios with affected services and countries, existing controls, likelihood, impact, residual risk, treatment and accountable owner; suppliers rated on access level, data exposure, substitutability and contractual protection.
European and national requirement, current practice, evidence, gap, action, owner and deadline; a prioritised roadmap; and a management dashboard the board can follow without technical expertise.
You receive an executive report and a detailed assessment, walked through together in a decision session. The previews below show its structure (Readiness Assessment format).
Representative anonymised sample. The actual deliverable is tailored to your context. Download the full PDF.
Demonstration document. © Carrefourduweb. Reproduction and commercial reuse prohibited without written permission.
The assessment does not end with separate lists of strengths and weaknesses. Regulatory exposure, operational criticality, cyber maturity, supplier dependence, investment capacity and strategic projects are cross-analysed to produce four categories of decision. This prevents minor documentation gaps from being placed at the same level as major operational vulnerabilities.
High-impact risks combined with weak control and high regulatory exposure.
Material risks requiring projects, budget or organisational change.
Existing practices that are operationally useful but insufficiently documented or measured.
Controlled risks that require periodic testing and continuous improvement.
From
A rapid executive view of regulatory exposure and major weaknesses.
One entity or limited group scope, executive interviews, limited evidence review, preliminary applicability analysis, maturity snapshot, five to ten priority risks, 90-day action plan and remote executive presentation. Two to three weeks.
From
A complete organisational, operational and regulatory assessment.
One main legal entity, one or several Nordic sites, executive and operational interviews, applicability analysis, critical-service mapping, maturity assessment, risk analysis, supplier review, NIS2 gap analysis and roadmap. Ten deliverables. Six to eight weeks.
From
A harmonised resilience model across several countries.
Several legal entities and countries, common control framework, country deviations, central and local responsibilities, cross-border incident process, consolidated dashboard and group roadmap. Eight to sixteen weeks.
On quotation, normally from €18,000 excl. VAT
For organisations combining business IT, production systems and operational technology: industrial dependency mapping, IT-OT governance, remote maintenance, legacy systems, production continuity and recovery scenarios. Specialist technical partners may be required for intrusive or highly specialised OT work.
On request
Monthly roadmap review, quarterly executive committee, regulatory monitoring, supplier-selection support, risk-register updates, KPI reporting, board decision preparation and annual reassessment.
The engagement runs in twelve stages: initial qualification; international scoping; regulatory applicability mapping; evidence review; interviews and workshops; critical-service and dependency mapping; maturity assessment; risk-scenario analysis; NIS2 and national gap analysis; executive challenge workshop; roadmap design; and a final closing session.
Interviews, workshops, analysis and closing sessions are conducted by video and through secure document spaces. This shortens timelines, makes stakeholders across several countries easier to mobilise and limits the environmental footprint of the engagement. Targeted on-site presence is proposed where industrial installations, physical dependencies or operational practice require it.
Working language: English, to preserve consistency, comparability and group reporting. Local-language support can be organised for interviews, evidence review, country-specific workshops, regulatory terminology and coordination with national specialists.
The assignment establishes rules for document classification, secure sharing, access rights, data location, retention, deletion, version control, interview notes, cross-border transfer and subcontractor confidentiality. Carrefourduweb does not request passwords, private cryptographic keys or privileged production access.
An independent, proportionate reading of your real exposure across every country where you operate. Priorities ranked by their capacity to reduce risk. Knowledge transferred to management and teams.
Unless separately agreed, the engagement includes no penetration test, intrusive scanning, source-code audit, forensic investigation, incident response, operational monitoring, ISO or NIS2 certification, legal advice or binding regulatory audit. These can be entrusted to specialist partners.
The Executive Review to obtain a rapid position; the Readiness Assessment for a complete diagnosis and roadmap; the Multi-Country Assessment to harmonise several entities; the Industrial Assessment where operational technology is in scope.
That is one of the questions the assessment answers, entity by entity and country by country. Many organisations are not regulated directly but receive the requirements through their customers.
It is the international edition, with a materially wider scope: applicability analysed per country rather than per single jurisdiction, a six-level maturity model, a cross-analysis producing four decision categories, a cross-border incident model and group-versus-local responsibilities. That difference is reflected in its positioning.
No. The assessment is organisational and evidence-based. Technical testing can be entrusted to specialist partners where the diagnosis shows it is useful.
No. No ISO certificate or NIS2 attestation is issued. The assessment prepares and documents; it does not certify.
It is common, and the assessment accounts for it: the contractual level of your provider's commitments is one of the points examined.
After a first exchange, we agree scope, package and terms. Final scope and price are confirmed after qualification. Payment is by invoice before the engagement starts. Prices are shown excl. VAT; for EU B2B clients, reverse-charge VAT applies.
From
Leave us your work email and briefly describe your situation: we'll come back to frame the scope, choose the package and confirm the terms. No commitment at this stage.
Available
Security and data protection are ESG axes. Extend the same evidence discipline to your sustainability data — a reliable, reusable base your customers, banks and corporate buyers can verify.
Regulatory analysis current as at 31 July 2026. European timelines change; this page is updated whenever a significant development occurs.