Skip to content

Solutions / By sector

Government & Public Sector

EU-registered, with experience supporting cross-border investigations across six regions.

What you receive

  • EU data residency by default
  • Cross-border investigation support
  • Public procurement documentation
  • Security clearance available

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A hacktivist campaign has named your agency

    Politically timed denial of service and defacement usually arrive with a published schedule and aim at the pages citizens read, not the systems that matter. The measure is visibility rather than damage — and the risk is that the noise covers something quieter.

  • 02

    You have to buy this through a tender

    Under EU procurement rules the technical specifications and the award criteria go into the documents before the process opens, and even in a procedure that allows negotiation those two are the ones that cannot be changed afterwards. A requirement written loosely at that stage constrains every year of the contract.

  • 03

    The records in the register cannot be reissued

    A card is replaced and a password rotated; a national identifier, a land title or a health record is not. After a breach the work shifts from containment and reissue to notification, long-term monitoring and a public account of what was actually taken.

How it runs

  1. 01

    Where you actually are

    A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.

  2. 02

    What the obligation really requires

    We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.

  3. 03

    A scoped programme

    The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.

  4. 04

    Evidence, not a gap report

    The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Systems accredited for classified national-security material sit outside this, because that work runs under national authority rules, not commercial terms.

  • We do not draft policy, legislation or a national cyber strategy — the work here is technical, and the policy layer stays with your own officials.

  • The GDPR breach-notification workflow itself is built under By mandate; this covers the investigation and the evidence that feed into it.

Measured against

Directive 2014/24/EU
Technical specifications go into the procurement documents under Article 42 and award criteria under Article 67. Where the procedure allows negotiation, Article 29 keeps the minimum requirements and the award criteria off the table.
Regulation (EU, Euratom) 2023/2841
Sets cybersecurity risk-management and reporting duties for EU institutions and agencies, with CERT-EU as the reporting point.
eIDAS, Regulation (EU) No 910/2014 as amended by (EU) 2024/1183
Article 5a obliges each Member State to provide at least one European Digital Identity Wallet; certification requirements sit in Article 5c.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Will the incident end up in the public record?

Assume it will. Public bodies face freedom-of-information requests, parliamentary questions and audit-office review, so the report is written knowing it may be read by people who were not in the room — which changes the wording, not the findings.

Can attribution be ready for a public statement?

Rarely. Technical attribution to a named group takes weeks and usually stays probabilistic, while the statement is wanted within a day — so an honest early statement describes what happened and what citizens should do, and names nobody.

What makes a cross-border investigation slower?

Evidence held in another jurisdiction moves through mutual legal assistance or a provider's own disclosure process, and retention periods differ enough that logs can expire while the request is still in transit. The technical work is rarely the bottleneck.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.