Product · Cyber resilience · Northern Europe

Available

Nordic Cyber Resilience & NIS2 Readiness Assessment

Demonstrable resilience, proportionate to the organisation — not a compliance checklist.

Most cybersecurity assessments produce one of two unsatisfactory results: a highly technical report that management cannot translate into decisions, or a compliance checklist that identifies documentation gaps without establishing whether the organisation could keep operating during a cyber crisis. This assessment starts from your critical services and strategic dependencies, then connects regulatory requirements to operational reality — across every country where you operate.

From

€4,500 excl. VAT EU B2B reverse-charge applies

Request an assessmentDownload the sample deliverable

Five packages depending on your scope — see below. Final scope and price are agreed after qualification.


The difference

Controls that exist, or controls that work?

The objective is not to demonstrate that controls exist. It is to establish whether they are appropriate, implemented, understood, evidenced, tested, monitored — and capable of supporting business resilience. The assessment examines how your critical services depend on people, information, applications, infrastructure, cloud services, suppliers, digital identities, industrial systems, data flows and contractual arrangements.

Context

High digital maturity increases systemic dependence

Nordic organisations are often highly decentralised and digitally connected. A single company may rely on a group identity platform, several national cloud environments, shared ERP infrastructure, outsourced cybersecurity and remote industrial maintenance. That maturity is a strength — and a concentration of dependency. Add cross-border operations and the picture becomes harder to read: NIS2 is a European directive, but it is implemented through national law.

Finland's Cybersecurity Act (124/2025) has been in force since 8 April 2025, with sector-specific supervision. Denmark's national NIS2 act entered into force on 1 July 2025, with sector-specific competent authorities. Dates, authorities, registration duties and reporting arrangements differ. Assessing a group against a single generic reading of NIS2 produces misleading conclusions. Registration duties differ too: in Finland, in-scope entities had to register by 8 May 2025 and have a risk-management model in place by 8 July 2025; in Denmark, self-registration ran until 1 October 2025.

Scope

What the assessment examines

The final scope is agreed at qualification. It may cover all or part of the following, with a target maturity set per domain according to regulation, business criticality, threat exposure, organisational capacity and cost-benefit.

1Executive governance. Board oversight, cyber-risk ownership, risk acceptance, investment governance, crisis decision-making, accountability across subsidiaries.
2Organisational model. Internal roles, local and group responsibilities, privacy coordination, escalation paths, competence, key-person dependency.
3Critical-service mapping. Owner, required availability, acceptable downtime, financial, contractual, regulatory, safety and reputational impact, recovery method, degraded operating mode.
4Asset management. Physical and virtual assets, endpoints, servers, cloud services, identities, industrial equipment.
5Identity and access. Named accounts, multifactor authentication, privileged access, provider and remote access, entitlement reviews.
6Cloud and collaboration. Identity configuration, document sharing, guests, logging, data location and reversibility.
7Backup and recovery. Coverage, frequency, isolation, restoration testing, recovery objectives.
8Continuity and crisis. Scenarios, degraded modes, recovery objectives, procedures, exercises.
9Incident management. Detection, procedure, contacts, logging, notification duties, cross-border coordination.
10Supplier governance. Critical providers, managed services, contracts, security commitments, reversibility.
11Data protection. Classification, sensitive data, GDPR interface, retention.
12OT and production systems. IT-OT governance, remote maintenance, legacy systems, production continuity, physical factors.
13AI use and governance. Tools in use, data sent to platforms, connectors, human validation, governance of use.
Deliverables

Ten management deliverables

Findings, assumptions, limitations and recommendations are documented. Unverified elements are clearly distinguished from available evidence.

Executive cyber resilience report

Regulatory exposure, overall maturity, critical risks, strategic dependencies, priority decisions, investment needs and roadmap.

Country and entity applicability matrix

For each entity: country, activity, sector, potential status, competent authority, registration status, reporting process, unresolved questions and required action.

Critical-service map

Services, entities, countries, processes, data, applications, infrastructure, employees, suppliers and recovery objectives.

Maturity assessment matrix

A six-level model from 0 (not established) to 5 (resilient and adaptive), with current level, target, evidence, gap, priority and owner per domain.

Risk register and supplier criticality matrix

Scenarios with affected services and countries, existing controls, likelihood, impact, residual risk, treatment and accountable owner; suppliers rated on access level, data exposure, substitutability and contractual protection.

Gap matrix, roadmap and dashboard

European and national requirement, current practice, evidence, gap, action, owner and deadline; a prioritised roadmap; and a management dashboard the board can follow without technical expertise.

Preview

What the deliverable looks like

You receive an executive report and a detailed assessment, walked through together in a decision session. The previews below show its structure (Readiness Assessment format).

Page 1 of the deliverable: cover of the Nordic Cyber Resilience and NIS2 Readiness Assessment with the engagement scope table — anonymised client profile with entities in two Nordic countries, trigger for the engagement, domains in scope, format and nature of the engagement.
Engagement scope
Page 2 of the deliverable: executive memorandum contrasting real exposure, what is missing and the decisions required; regulatory applicability analysed country by country with national position, likely status and action; and the critical-service map with maximum downtime, owner and principal dependency.
Country applicability and critical services
Page 3 of the deliverable: maturity matrix rating the domains from current to target level with the principal gap, risk scenarios with business consequence and residual risk, and the supplier and dependency matrix with criticality and required action.
Risk scenarios and supplier matrix
Page 4 of the deliverable: the cross-analysis table defining the four decision categories, the roadmap across four colour-coded horizons, the management dashboard with indicators and twelve-month targets, and the benefits delivered per stakeholder group.
Cross-analysis, roadmap and benefits
Page 5 of the deliverable: recap of the deliverables provided, the Nordic relevance panel, the explicit list of what the engagement is not, and a banner listing the available packages.
Deliverables and exclusions

Representative anonymised sample. The actual deliverable is tailored to your context. Download the full PDF.

Demonstration document. © Carrefourduweb. Reproduction and commercial reuse prohibited without written permission.

Cross-analysis

Four categories of decision

The assessment does not end with separate lists of strengths and weaknesses. Regulatory exposure, operational criticality, cyber maturity, supplier dependence, investment capacity and strategic projects are cross-analysed to produce four categories of decision. This prevents minor documentation gaps from being placed at the same level as major operational vulnerabilities.

Protect immediately

High-impact risks combined with weak control and high regulatory exposure.

Structure and invest

Material risks requiring projects, budget or organisational change.

Formalise and evidence

Existing practices that are operationally useful but insufficiently documented or measured.

Monitor and optimise

Controlled risks that require periodic testing and continuous improvement.

Packages

Five packages, by scope

Nordic NIS2 Executive Review

From

€4,500 excl. VAT

A rapid executive view of regulatory exposure and major weaknesses.

One entity or limited group scope, executive interviews, limited evidence review, preliminary applicability analysis, maturity snapshot, five to ten priority risks, 90-day action plan and remote executive presentation. Two to three weeks.

Multi-Country Cyber Resilience Assessment

From

€25,000 excl. VAT

A harmonised resilience model across several countries.

Several legal entities and countries, common control framework, country deviations, central and local responsibilities, cross-border incident process, consolidated dashboard and group roadmap. Eight to sixteen weeks.

Specialised engagements

Industrial Cyber Resilience Assessment

On quotation, normally from €18,000 excl. VAT

For organisations combining business IT, production systems and operational technology: industrial dependency mapping, IT-OT governance, remote maintenance, legacy systems, production continuity and recovery scenarios. Specialist technical partners may be required for intrusive or highly specialised OT work.

Cyber Governance Advisory Subscription

On request

Monthly roadmap review, quarterly executive committee, regulatory monitoring, supplier-selection support, risk-register updates, KPI reporting, board decision preparation and annual reassessment.

Delivery

Remote-first, twelve stages

The engagement runs in twelve stages: initial qualification; international scoping; regulatory applicability mapping; evidence review; interviews and workshops; critical-service and dependency mapping; maturity assessment; risk-scenario analysis; NIS2 and national gap analysis; executive challenge workshop; roadmap design; and a final closing session.

Interviews, workshops, analysis and closing sessions are conducted by video and through secure document spaces. This shortens timelines, makes stakeholders across several countries easier to mobilise and limits the environmental footprint of the engagement. Targeted on-site presence is proposed where industrial installations, physical dependencies or operational practice require it.

Working language: English, to preserve consistency, comparability and group reporting. Local-language support can be organised for interviews, evidence review, country-specific workshops, regulatory terminology and coordination with national specialists.

Confidentiality

Information handling

The assignment establishes rules for document classification, secure sharing, access rights, data location, retention, deletion, version control, interview notes, cross-border transfer and subcontractor confidentiality. Carrefourduweb does not request passwords, private cryptographic keys or privileged production access.

Terms of the engagement

What it is, and is not

What it is

An independent, proportionate reading of your real exposure across every country where you operate. Priorities ranked by their capacity to reduce risk. Knowledge transferred to management and teams.

What it is not

Unless separately agreed, the engagement includes no penetration test, intrusive scanning, source-code audit, forensic investigation, incident response, operational monitoring, ISO or NIS2 certification, legal advice or binding regulatory audit. These can be entrusted to specialist partners.

FAQ

Questions you're likely to ask

The Executive Review to obtain a rapid position; the Readiness Assessment for a complete diagnosis and roadmap; the Multi-Country Assessment to harmonise several entities; the Industrial Assessment where operational technology is in scope.

That is one of the questions the assessment answers, entity by entity and country by country. Many organisations are not regulated directly but receive the requirements through their customers.

It is the international edition, with a materially wider scope: applicability analysed per country rather than per single jurisdiction, a six-level maturity model, a cross-analysis producing four decision categories, a cross-border incident model and group-versus-local responsibilities. That difference is reflected in its positioning.

No. The assessment is organisational and evidence-based. Technical testing can be entrusted to specialist partners where the diagnosis shows it is useful.

No. No ISO certificate or NIS2 attestation is issued. The assessment prepares and documents; it does not certify.

It is common, and the assessment accounts for it: the contractual level of your provider's commitments is one of the points examined.

After a first exchange, we agree scope, package and terms. Final scope and price are confirmed after qualification. Payment is by invoice before the engagement starts. Prices are shown excl. VAT; for EU B2B clients, reverse-charge VAT applies.

Next step

Request an assessment

From

€4,500 excl. VAT

Leave us your work email and briefly describe your situation: we'll come back to frame the scope, choose the package and confirm the terms. No commitment at this stage.

Other engagements

Where to go next

Available

Nordic & European CSRD / ESG Data Readiness

Security and data protection are ESG axes. Extend the same evidence discipline to your sustainability data — a reliable, reusable base your customers, banks and corporate buyers can verify.

€4,900 excl. VAT
See the assessment →

Regulatory analysis current as at 31 July 2026. European timelines change; this page is updated whenever a significant development occurs.

Know where you stand before you invest.