Advisory
Cyber & technology risk
A useful risk program makes trade-offs visible and gives teams a practical way to act. We bring structure to complex technology environments without losing sight of how the business actually operates.
The mandate
See the risk clearly. Build the controls that matter.
From risk assessment and security strategy to control design and operating models, we connect technical decisions to business exposure.
Discuss this workHow we help
- Enterprise and technology risk assessment
- Security strategy and target operating model
- Control design and policy architecture
- Third-party and supply chain risk
- Board and executive risk reporting
What the work produces
- A risk register tied to business decisions
- A prioritized, owned remediation roadmap
- Controls that can be operated and evidenced
Common questions
Clarify the mandate before delivery.
What is the practical output of a cyber risk assessment?
A useful assessment identifies the most important exposures, the evidence behind them, the available treatment choices, and who will decide and act. A score alone does not provide a plan.
Can the same assessment support ISO/IEC 27001 or NIST CSF 2.0?
Yes, a well-scoped assessment can inform an ISMS risk treatment plan and a CSF Current and Target Profile. Each framework still has its own required structure and decisions.
How should third-party risk be included?
Start with the suppliers and outsourced services on which critical operations depend. Assess their access, data, service continuity, and contractual obligations in the context of the service they provide.
Work with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.