Skip to content
Silk Shells Consulting

Our approach

Method over improvisation.

Every Silk Shells Consulting engagement follows the same discipline: independent advice, senior involvement and evidence over assumptions. We adapt the scope to the organization without lowering the standard.

How we work

Seven steps, from defining the perimeter to measuring progress.

  1. 01

    Understand

    We start with the business, regulatory and security perimeter: what the organization does, where it operates and which obligations and risks it must address.

  2. 02

    Gather

    We combine stakeholder interviews, document review and alignment sessions to collect evidence rather than rely on impressions.

  3. 03

    Assess

    We assess the current posture and maturity against the standards, obligations and threat landscape relevant to the organization.

  4. 04

    Prioritize

    We rank gaps by risk and business impact so that investment is directed where it can materially improve the organization's risk profile.

  5. 05

    Roadmap

    We define a roadmap with named owners, timelines, dependencies and resource requirements. Accountability is built in from the outset.

  6. 06

    Implement

    We establish governance, workstreams, checkpoints and executive reporting, remaining close to delivery until the change is embedded.

  7. 07

    Measure & Adapt

    We measure progress continuously and adapt the plan as the organization, its priorities and the threat landscape evolve.

NIS2 — a dedicated approach

From obligation to governance capability.

NIS2 is not a checklist exercise. Our approach helps organizations establish the governance structures, responsibilities and remediation plans required to support compliance readiness. Executive summaries and heatmaps are designed for management decision-making, while detailed evidence remains available for assurance and audit purposes.

  1. 01

    Security committee design

    A decision-making forum with defined membership, responsibilities and cadence.

  2. 02

    Information gathering

    Stakeholder interviews, document review and system mapping across the agreed perimeter.

  3. 03

    Gap analysis

    Assessment of the current posture against applicable NIS2 obligations and supporting requirements.

  4. 04

    Roadmap development

    Prioritized by risk and business impact, with named owners, dependencies and timelines.

  5. 05

    Remediation planning

    Defined remediation workstreams with dependencies and resource requirements made explicit.

  6. 06

    Implementation support

    Governance, delivery checkpoints and hands-on coordination.

  7. 07

    Executive summaries and heatmaps

    Visual reporting designed to support management decisions, with traceable underlying evidence.

  8. 08

    Board and executive training

    Practical training on responsibilities, incident reporting and governance duties.