Our approach
Method over improvisation.
Every Silk Shells Consulting engagement follows the same discipline: independent advice, senior involvement and evidence over assumptions. We adapt the scope to the organization without lowering the standard.
How we work
Seven steps, from defining the perimeter to measuring progress.
01
Understand
We start with the business, regulatory and security perimeter: what the organization does, where it operates and which obligations and risks it must address.
02
Gather
We combine stakeholder interviews, document review and alignment sessions to collect evidence rather than rely on impressions.
03
Assess
We assess the current posture and maturity against the standards, obligations and threat landscape relevant to the organization.
04
Prioritize
We rank gaps by risk and business impact so that investment is directed where it can materially improve the organization's risk profile.
05
Roadmap
We define a roadmap with named owners, timelines, dependencies and resource requirements. Accountability is built in from the outset.
06
Implement
We establish governance, workstreams, checkpoints and executive reporting, remaining close to delivery until the change is embedded.
07
Measure & Adapt
We measure progress continuously and adapt the plan as the organization, its priorities and the threat landscape evolve.
NIS2 — a dedicated approach
From obligation to governance capability.
NIS2 is not a checklist exercise. Our approach helps organizations establish the governance structures, responsibilities and remediation plans required to support compliance readiness. Executive summaries and heatmaps are designed for management decision-making, while detailed evidence remains available for assurance and audit purposes.
01
Security committee design
A decision-making forum with defined membership, responsibilities and cadence.
02
Information gathering
Stakeholder interviews, document review and system mapping across the agreed perimeter.
03
Gap analysis
Assessment of the current posture against applicable NIS2 obligations and supporting requirements.
04
Roadmap development
Prioritized by risk and business impact, with named owners, dependencies and timelines.
05
Remediation planning
Defined remediation workstreams with dependencies and resource requirements made explicit.
06
Implementation support
Governance, delivery checkpoints and hands-on coordination.
07
Executive summaries and heatmaps
Visual reporting designed to support management decisions, with traceable underlying evidence.
08
Board and executive training
Practical training on responsibilities, incident reporting and governance duties.
