The firm

Independence is built, not claimed

CYBERVETTER assesses. It does nothing that would compromise an assessment. There is no product margin to protect, no infrastructure of ours inside the client estate, and no certificate of ours riding on the conclusion.

Every firm that offers assurance says it is independent. The word is only worth anything where it describes a structure rather than an intention. Ours is a structure: three lines of revenue that the market would happily pay us for are permanently outside what we do, and the reasoning for each is written down and published.

Read the commitments

01

Engagements are led by the people who do the work

An engagement is led by a named senior consultant who carries out the assessment personally. The person who scopes the work is the person who examines the evidence, writes the findings and defends them in the debrief. Clients know who holds the pen, and the report is signed by someone who can be questioned on any line in it.

Certifications are held by the individuals doing the assessment, not by the letterhead. Each consultant's certifications and ECSF role mapping are published on their profile.

02

Delivery across Europe and internationally

The firm is based in Constanța, Romania, and delivers across Europe and internationally. Engagements run in English and Romanian, on site or remotely, and are written to be read by boards, auditors and supervisory authorities in the jurisdiction that will ask for them.

03

Methodology drawn from published frameworks

Assessments are conducted against published frameworks rather than a proprietary maturity model. Findings are traceable to a control, a clause or an article, so a client can take the report to an auditor, a regulator or a customer and have it recognised. Where a framework leaves a judgement open, the judgement is stated as such and the reasoning is given.

Framework basis

  • ISO/IEC 27001 · 27002 · 27005
  • NIST CSF · SP 800-53 · SP 800-115
  • ENISA guidance and ECSF
  • European Commission frameworks

04

Experience

The firm's experience spans European institutional programmes, national critical infrastructure, and regulated finance, together with more than fifty audits of EU-funded projects. That work sets the standard the reports are written to: evidence that survives an external auditor reading it without the benefit of the conversation that produced it.

European institutional programmes
Assurance and audit work within programmes run by European institutions and bodies.
National critical infrastructure
Assessment of systems in scope of national critical infrastructure regimes.
Regulated finance
Operational resilience and ICT risk work for supervised financial entities.
EU-funded project audit
More than fifty audits of projects funded through EU instruments.

Ask us something specific

Name the system, the standard and the deadline. We will tell you what an assessment would cover and who would lead it.

Contact