Skip to content
Silk Shells Consulting

Our approach

A disciplined method. Tailored to the mandate.

Every Silk Shells Consulting engagement is grounded in the same principles: independent judgment, senior involvement, and evidence over assumptions. We adapt the scope to the organization, its operating reality, and the decisions leadership must make. The standard of rigor does not change.

How we work

Seven steps, from defining the perimeter to measuring progress.

  1. 01

    Understand

    We begin with the business: how the organization creates value, where it operates, what it must protect, and which regulatory, operational, and threat-related pressures shape the mandate.

  2. 02

    Gather evidence

    We combine stakeholder interviews, document review, data analysis, and alignment sessions to establish a reliable evidence base rather than work from impressions.

  3. 03

    Assess

    We evaluate the current posture against the standards, obligations, business requirements, and threat scenarios relevant to the organization.

  4. 04

    Prioritize

    We rank gaps by risk, business impact, urgency, and feasibility. This directs leadership attention and investment toward the changes that will materially improve the risk profile.

  5. 05

    Define the roadmap

    We translate priorities into a roadmap with accountable owners, timelines, dependencies, resource requirements, and decision points. Accountability is designed in from the outset.

  6. 06

    Lead execution

    We establish workstreams, governance, checkpoints, and executive reporting. We remain close to delivery, coordinating specialist implementation where required, until the change is embedded.

  7. 07

    Measure and adapt

    We track progress and outcomes, making risks and delays visible. The plan evolves as the organization, its priorities, and the threat landscape change.

NIS2: a dedicated approach

From regulatory obligation to lasting governance capability.

NIS2 is not a checklist exercise. It requires clear accountability, evidence-based risk management, and the ability to sustain security measures over time.

Our approach establishes the governance structures, responsibilities, evidence, and remediation program required to support compliance readiness. Executive summaries and heatmaps are designed for management decisions, while the underlying evidence remains traceable for assurance and audit purposes.

  1. 01

    Security committee design

    We establish a decision-making forum with defined membership, responsibilities, authority, and cadence.

  2. 02

    Information gathering

    We conduct stakeholder interviews, review relevant documentation, and map systems, services, processes, and dependencies across the agreed perimeter.

  3. 03

    Gap analysis

    We assess the current posture against applicable NIS2 obligations and supporting national requirements, documenting evidence and material gaps.

  4. 04

    Roadmap development

    We prioritize actions by risk and business impact, assigning owners, dependencies, decision points, and realistic timelines.

  5. 05

    Remediation planning

    We structure remediation into manageable workstreams and make resource requirements, delivery constraints, and cross-functional dependencies explicit.

  6. 06

    Implementation support

    We establish governance, delivery checkpoints, and executive reporting, coordinating implementation while keeping accountability visible.

  7. 07

    Executive reporting and heatmaps

    We provide decision-ready reporting for management and the board, supported by traceable evidence and clear escalation of risks and delays.

  8. 08

    Board and executive training

    We prepare leadership for its governance duties, including accountability, risk oversight, incident reporting, and the decisions required to sustain readiness.