RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Five disciplines, thirteen ways to be useful to you.

You do not have to guess the right service. Tell us where you are stuck and we will suggest the shortest route.

I

Compliance

II

Leadership and oversight

III

Artificial intelligence

IV

Training and talks

V

Our own products

Four situations that bring people to us

In each of them there is a first step that takes weeks, not months.

“The categorisation notice arrived and nobody inside has taken the work on.”

CONSEQUENCEThe twelve month deadline runs whether or not a project lead has been named. The people who would have to do the work are usually freed from their other duties too late.

WAY OUTA gap analysis against the thirteen measures gives a scored starting point and a plan with named owners within two to three weeks.

“We have the documentation, but we do not know whether it would pass an audit.”

CONSEQUENCEThe auditor asks for written evidence for 137 controls. A review almost always shows that a large part of the required documentation is missing, more often the evidence of practice than the documents themselves.

WAY OUTAn internal review that simulates the audit procedure, using the same scoring formulas. You know the finding before the auditor arrives.

“The board wants a report on cyber risk and we have no register.”

CONSEQUENCERisk management is the third of the thirteen measures. If the process is not documented, that is a direct non-compliance and grounds for a finding at the audit.

WAY OUTA risk register, a matrix following the NCSC-HR guidelines and a risk treatment plan. Three to six weeks for a medium-sized organisation.

“We rolled out artificial intelligence tools before we wrote the rules.”

CONSEQUENCEMost organisations do not know which artificial intelligence systems they use at all, because they are built into HR, finance and communication tools.

WAY OUTAn inventory and classification by the risk categories of the AI Act, with an acceptable use policy the team can apply straight away.

In all four the first step is the same: establish where you stand, scored and documented. The scope, duration and price of the full programme are estimated only after that.

Engagement models

One model has a fixed end, three run on. The last column matters most: how much of your team’s time it takes. We tell you that before you sign, not after.

MODELWHO IT IS FOR AND WHAT IT SOLVESDURATIONYOUR TIME Project engagementGap analysis, documentation, risk assessment, audit readiness3 to 6 months2 to 4 hours a week per intervieweeAdvisory engagementRegulatory questions, document review, support during an inspection; agreed hours per month12 months and longerAs needed, with no committed timeVirtual CISOLeadership of the security programme without a full-time hire; a monthly fee12 months and longerA monthly meeting with the board, a quarterly reviewExternal data protection officerPublic authorities and organisations with large-scale processing of special categories; an independent function12 months and longerA quarterly review and data subject requests

How we start

Two weeks usually pass between the first call and the start of work. Every step has a deadline, and until you sign all it takes from you is half an hour of conversation.

01 · Day 0

Introductory call, 30 minutes, free of charge

A conversation about your situation, your obligations and your priorities. No slide deck and no commitment. By the end of the call you have an estimate of the scope and a realistic deadline.

02 · 3 to 5 days

Written proposal

A clearly bounded scope, a list of deliverables, a deadline and a price. What the proposal says is what gets delivered.

03 · Week 1

Agreement and start of work

We meet the key people on your side and set up the working framework.

04 · From then on

Delivery and support

You can see how the work is progressing at any time. After the project ends we stay available for questions, changes in the law and preparation for an inspection.

What we do not do

Knowing what someone does not do is as useful as knowing what they do. If you need something from this list, tell us and we will point you further, with no referral fee.

We do not carry out the formal cyber security auditThat calls for the national security certificate, and at state administration bodies the audit is carried out by the Information Systems Security Bureau (ZSIS). We prepare you and help you find an auditor.
We do not sell or resell security toolsWe hold no partner agreements with vendors. We assess and advise, and you run the procurement on your own criteria.
We do not take over the running of your infrastructureWe are not a managed service provider for the day to day operation of systems. We work at the level of governance, documentation and oversight of the programme.
We do not hand over generic templates without a review of where you standDocumentation that did not come out of the real situation fails at the first check of evidence. Saving on that step costs more later.
We do not run penetration testing or digital forensicsFor technical testing and forensic analysis we work with specialist contractors. We help you choose them and set the scope.

How we set scope and price

Price follows scope, and scope follows the findings. That is why we do not quote a figure before we know where you stand. These are the factors that move it, so you can judge the order of magnitude in advance.

WHAT WIDENS THE SCOPE
  • The advanced level of measures instead of the basic one
  • Several sites or separate legal entities in scope
  • Operational technology and industrial control systems
  • Documentation that barely exists
  • Less than three months until an audit or inspection
  • A large number of external suppliers with system access
WHAT NARROWS IT
  • An existing ISO/IEC 27001 management system
  • An internal security lead who takes on part of the work
  • A clearly bounded scope, for example one measure or one system
  • An orderly register of assets and business processes
  • Running Cyber Security Act compliance and data protection as one project
  • Phased delivery aligned with the budget cycle

How we bill

Project engagementA fixed price for a scope and deadline agreed in advance. Scope changes only by written addendum.Advisory engagementA monthly fee for an agreed number of hours, with unused hours carried within the quarter.Virtual CISOA monthly fee based on the level of involvement and the extent of board reporting.
NO HIDDEN ITEMS

The proposal, with the content described in step 02, arrives within three to five working days of the introductory call. Travel costs and third party fees are listed separately or do not arise.

CONFIDENTIALITY

Every engagement begins with a confidentiality agreement, before any data is exchanged.

PRICE LIST

An indicative price list and terms of business are available as a separate document, on request.

Frequently asked questions

The questions we are asked most often before we start.

How does an engagement start?

With a thirty minute introductory call, free of charge. The written proposal follows within three to five working days.

What does it cost?

Price follows scope, and scope is only known after a readiness review. That is why we start with a gap analysis and discuss the full programme with real numbers.

How much of our time does it take?

It depends on the model, but we always tell you before you sign. For a readiness review it is usually a few hours per interviewee over two to three weeks.

Do you work outside Zagreb?

We work across Croatia. Part of the work is remote, while conversations with the board and measure owners are usually in person.

Can we take just one part?

You can. Most clients start with a gap analysis or a single measure and then decide how to continue.

Related pages

The pages that explain the obligations behind these services.

Not sure what you need? Tell us where you are stuck.

Half an hour, no obligation. Tell us where you are stuck and we will tell you what the first step is.

Book a callINFO@RISKORIA.EU · +385 97 737 1345