Cyber security and artificial intelligence advisory
We know what is required of you and how it is proven.
We work with essential and important entities on the Cyber Security Act, on artificial intelligence and on personal data protection. We say who does what, in what order, and what proves it.
One cube is 20% of the requirements within a measure that have evidence. Grey columns are measures below the threshold. The threshold is our own readiness indicator, not a statutory one; scoring thresholds are set per sub-measure and level in ZSIS Annex B. Example from a readiness review.
SOA · competent authority outside state administration UVNS · expert supervision of state administration bodies NCSC-HR · incident reporting AZOP · personal data breaches
Thirteen measures, one piece of evidence at a time
01
We map the current state
A score for each of the 137 controls and a list of missing evidence. Two to three weeks.
02
We close the gaps
Policies, procedures, the risk register and the records behind every measure.
03
We review the file before the auditor
We go through the documentation the way the auditor will, before they arrive.
A gap analysis report scored by sub-measure and control
An asset register and threat catalogue fitted to your sector
A risk register, a matrix following the NCSC-HR guidance and a risk treatment plan
A compliance plan with priorities, owners and resource estimates
An internal review report that simulates the audit procedure
A mapping of your certificates and standards onto the thirteen measures
Frequently asked questions about the Act
Where there is one, the answers cite the article of the Act or the Regulation.
Who is an essential and who is an important entity under the Act?
+Essential entities undergo an independent audit, important entities carry out a self assessment. The competent authority notifies you of your category, which follows from sector and size, with exceptions for the four critical healthcare activities and for state administration bodies.
What are the thirteen measures and where do they come from?
+The thirteen measures from the Regulation break down into 99 sub-measures and 137 controls, across three levels of implementation: basic, intermediate and advanced. Every control calls for written evidence. They range from the security policy and risk management to cryptography, supply chain and physical protection.
What is the compliance deadline?
+Twelve months from delivery of the categorisation notice, under Article 26(5) of the Act. The clock runs whether or not anyone has been named to lead the work, so organisations that wait for that appointment usually lose the first quarter.
What is the deadline for reporting a significant incident?
+An early warning to the competent CSIRT within 24 hours, an initial incident notification within 72 hours, and a final report within 30 days. Where personal data are affected, a parallel notification goes to the data protection authority within 72 hours.
How does the Act relate to the AI Act?
+Both call for the same kind of evidence: a register of systems, a risk assessment, oversight and records. If you keep the register of artificial intelligence systems apart from the asset register, you do the work twice. Cyber security is the foundation; AI governance builds on the same documentation.
We prepare you for the audit. We do not carry it out.
A formal audit is carried out by a provider holding the national security certificate, and for state administration bodies by ZSIS. Riskoria does not hold that certificate. A body that built the management system may not also assess it, and that separation protects you.