Security compliance and operations for energy operators.
ISO 27001, NIS2 and GDPR mapped to one control set. Corporate IT and the plants you run evidenced in the same record. Technical gaps closed in the same platform.
One control set for every requirement.
The tools a heat network or decentralised energy operator needs to answer authorities, municipal clients and auditors from one record.
Map a control once, satisfy every framework.
Live completion for ISO 27001, NIS2 and GDPR from one control set, so the national transposition that binds you and the certification a municipal client asks for are answered by the same work.
The plant and the office, one inventory.
Laptops, servers, identity and cloud beside the operational technology running your sites, with classification and ownership, joined through a read-only feed from the monitoring you already run.
An unpatchable asset is managed, not ignored.
Availability comes first and some assets can never be touched, so the register carries the treatment, the owner and the deadline rather than a permanent red line.
The pack is current when the authority asks.
Control state with dates, risk decisions with owners and management approvals, generated on demand for an authority, an auditor or a municipal client.
Security events, triaged by business impact.
Agents stream events into the platform; what escalates is what matters to keeping supply on, not what scored highest on a generic scale.
Sovereign by design.
Hosted on EU-owned infrastructure with European data residency. The models we run are open source, on our own hardware or served by European providers. Your data is never used to train a model.
The frameworks energy operators are asked for.
NIS2
Energy is one of the sectors the regime treats as most critical, and district heating and cooling is named in its own right. The ten risk measures mapped to one control set.
ISO 27001
The certification municipal clients and commercial counterparties ask for. Controls, statement of applicability and evidence held in the platform.
GDPR
Applies wherever metering and billing data identifies a household. Mapped to the same controls, evidenced once.
Start with the audit.
Fixed scope, priced by company size.
Security Audit
An independent vCISO Security Audit returns a ranked gap list against every framework in scope. The starting roadmap, and the document you show a customer.
Platform
GRC and Security Operations, switched on from day one. Annual contract, monthly billing, priced by employee band.
vCISO
A named security lead where a contract requires one. Scoping, risk decisions, audit-facing guidance, management reporting.