Services · Cyber Risk International

Assurance your board can stand behind.

Fixed-scope assessments, independent validation, embedded senior advisors and board education — all delivered through the CyberPrism platform, so every finding is evidenced, every roadmap is live, and every report is written for the boardroom.

Assess

"Where do we actually stand?"

Fixed-scope, evidence-based assessments that establish your true position against the regulation that matters to you — each one delivered on CyberPrism and closed with a board-ready report.

Central Bank of Ireland headquarters, Dublin
Supervisory expectations are rising — know where you stand before they ask.

DORA Readiness Assessment

A structured gap analysis across DORA's pillars — ICT risk management, incident reporting, resilience testing, third-party risk and oversight — closed with a prioritised remediation roadmap.

Who it's for
Financial entities and credit unions in DORA scope
What you get
Evidenced gap analysis, prioritised roadmap, board-ready report
Duration
4–6 weeks
Fee
Fixed, agreed after a scoping call

NIS2 Readiness Assessment

Starts with the question most organisations can't yet answer: are you in scope — and as an essential or important entity? Then a gap analysis against your NIS2 obligations, with management accountability front and centre.

Who it's for
Operators in NIS2 sectors and their key suppliers
What you get
Scope & tier determination, gap analysis, remediation roadmap, board report
Duration
4–6 weeks
Fee
Fixed, agreed after a scoping call

EU AI Act Governance Assessment

Role and risk classification for your AI systems, and a governance gap analysis mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001 — with a proportionate plan to close what matters.

Who it's for
Organisations providing or deploying AI systems
What you get
Classification, mapped gap analysis, proportionate remediation plan
Duration
3–5 weeks
Fee
Fixed, agreed after a scoping call
Start here · Free

EU Regulatory Health Check

Not sure which of these applies to you, or where you'd score? Get an instant, theme-by-theme readiness score across DORA, NIS2 or the EU AI Act — no cost, no obligation.

Who it's for
Any organisation unsure where to start
What you get
Instant readiness score and priority focus, by regulation
Duration
About 4 minutes
Fee
Free

Third-Party & Supply Chain Assessment

Your resilience is only as strong as your critical providers. A structured review of your supplier estate — register of information, criticality tiering, and oversight gaps against DORA and NIS2 third-party obligations.

Who it's for
Organisations dependent on critical ICT providers
What you get
Supplier register review, criticality tiering, oversight gap analysis
Duration
Agreed at scoping
Fee
Fixed, agreed after a scoping call

Board & Executive Briefings

High-impact briefings that turn threat trends and regulatory change into clear board decisions — plus certified executive programmes through our exclusive ICTTF / EU Cyber Academy partnership.

Who it's for
Boards and senior leadership teams
What you get
Tailored briefings, certified training pathways, evidence of board competence
Duration
Single sessions or ongoing programmes
Fee
Fixed, agreed after a scoping call
Assure

"Is what we're reporting actually true?"

Reported maturity and operational reality are rarely the same thing. Our flagship engagement closes that gap.

Independent Validation Assessment

  • Challenge-and-evidence method — we don't take reported posture at face value; every claim is tested against what can be proven.
  • CRI as your independent third line — validation from outside your management chain, free of delivery bias.
  • A full audit trail in CyberPrism — every finding is logged, evidenced and traceable.
  • Findings in board language — decision-ready conclusions, not auditor-speak.
  • A shareable opinion — a confidence rating you can put in front of your board, regulator or partners.
Who it's for
Boards and regulated entities that need independent assurance over what's being reported to them
What you get
Independently validated posture, confidence rating, shareable opinion
Duration
4–8 weeks
Fee
Fixed, agreed after a scoping call
Architect & Execute

"Help us build it and run it."

When the assessment is done and the roadmap is agreed, most organisations need one more thing: senior ownership to make it happen.

CRI advisors working embedded with a client team
From a single fractional advisor to a full resilience team.

Incident Readiness & Governance

Independent advisors at your board's side before, during and after an incident — so the worst week of your year is governed, evidenced and defensible. We govern the response and the reporting; your technical responders handle the forensics.

  • Before — executive tabletop exercises and incident classification & reporting playbooks aligned to DORA (Arts. 17–19) and NIS2 deadlines.
  • During — an independent senior advisor beside the board: decisions, escalation, regulator and stakeholder communication.
  • After — independent post-incident review, lessons-learned evidence and board reporting.
Who it's for
Boards that must govern, classify and report incidents under DORA and NIS2
What you get
Tabletops & playbooks, board-side advisory through live incidents, independent post-incident review
Duration
Readiness at fixed scope; retained advisory ongoing
Fee
Fixed, agreed after a scoping call (readiness) · Monthly retainer (retained advisory)

Fractional vDORO & vCISO

A named senior owner for your digital resilience: board-ready oversight, structured challenge, and a credible regulatory interface — without the cost or delay of a full-time hire.

Who it's for
Organisations needing leadership-level ownership of resilience and security
What you get
Embedded senior advisor in a fractional role, governance oversight, regulator-facing support
Duration
Ongoing, fractional
Fee
Monthly retainer

Digital Resilience Programme

Resilience run as a continuous programme, not a one-off project: a monthly session with your dedicated senior advisor, a live roadmap maintained in CyberPrism, and a quarterly board update.

Who it's for
Organisations committed to sustained, governed progress
What you get
Monthly senior advisor sessions, live CyberPrism roadmap, quarterly board update
Duration
12 months
Fee
Annual programme fee
The platform behind every engagement

One assessment. Every framework. A live audit trail.

Every CRI engagement runs on CyberPrism, our digital resilience platform — assess once, and see your posture through the lens of each framework that applies to you, with every finding evidenced and every change tracked.

NIST CSF 2.0DORANIS2EU AI ActSector overlaysThreatLens
The CyberPrism digital resilience dashboard

Book a scoping call

Every engagement starts with a short, no-obligation scoping conversation — or call us on +353 (0)1 905 3260.