Cyber Risk & Governance
Risk register development, governance framework design, appetite statements, control owner assignment, and board-level reporting structures.
Regulated organisations and procurement-critical environments need governance evidence that holds up under real scrutiny — not advisory memos. DandaCyber delivers structured, auditable documentation and assurance work, directly from a senior practitioner, on a fixed-fee basis.
About DandaCyber
DandaCyber is a founder-led cyber assurance and governance support practice based in Tallinn, Estonia. We exist specifically to serve organisations that operate in regulated, procurement-intensive, or compliance-critical environments — where the quality of your security governance documentation directly affects your commercial and operational standing.
We are not a managed security service provider. We do not sell technology or hold vendor partnerships. What we provide is independent, practitioner-grade assurance, documentation, and governance support — delivered with personal accountability at every stage.
You engage with the founder. The same person scopes, delivers, and presents every engagement. No junior handoffs.
No reseller arrangements, no technology affiliations. Every recommendation is based solely on your context and requirements.
All deliverables are designed to withstand scrutiny — from internal audit to regulatory inspection to procurement evaluation.
Capabilities Statement
A structured overview of DandaCyber's practitioner capabilities — suitable for inclusion in supplier qualification processes, procurement responses, and due diligence packs.
Risk register development, governance framework design, appetite statements, control owner assignment, and board-level reporting structures.
Pre-audit readiness assessment, evidence pack construction, control gap analysis, and structured remediation planning against major frameworks.
Policy suites, procedure libraries, ISMS documentation, data classification frameworks, and procurement-ready security governance packs.
Third-party risk tiering, supplier questionnaire design, subcontractor assurance evidence, and supply chain governance support for organisations with complex vendor relationships.
Retained fractional CISO function — board attendance, incident response readiness, regulatory engagement, and ongoing cyber leadership without full-time overhead.
Process design, tooling-agnostic programme architecture, SLA frameworks, remediation governance, and reporting to senior stakeholders.
Who We Support
DandaCyber is positioned specifically for clients where cyber governance is a baseline commercial and regulatory requirement — not an optional enhancement.
Financial institutions, healthcare providers, utilities, and critical infrastructure operators navigating NIS2, DORA, or sector-specific mandatory frameworks. We produce the structured evidence regulators expect.
Organisations that must demonstrate a documented assurance posture to customers, partners, or as a condition of winning and retaining contracts — whether responding to private sector vendor questionnaires or public sector tender cyber scoring criteria. We produce evidence packs built for real scrutiny.
Small and mid-sized companies operating in regulated sectors who need enterprise-grade governance documentation without the overhead of a large internal security function.
Engagement Outcomes
A selection of anonymised engagement outcomes. Client names and identifying details are withheld by default — full references available under NDA upon request.
A globally operating financial services organisation subject to multiple overlapping regulatory frameworks across several jurisdictions required a single, coherent control environment. Working as part of a managed services delivery team, we produced a consolidated controls mapping matrix that satisfied each framework's requirements without duplicating control ownership — reducing audit overhead and providing a single source of truth for regulators across jurisdictions.
A regulated organisation with no existing information security management system required a complete ISO 27001 implementation. We conducted the initial gap analysis, led policy and standard creation, supported the internal audit programme, constructed the evidence pack, and managed the approval process through to certification. The organisation achieved certification at first audit attempt.
An organisation with a complex supplier base and procurement obligations required a structured approach to third-party risk. We designed a risk-based supplier tiering model, developed the assurance questionnaire suite, produced subcontractor assurance evidence templates, and documented the governance framework — enabling the organisation to demonstrate supply chain oversight to both customers and contracting authorities.
All engagements described above are anonymised. Named references, sector-specific case detail, and practitioner credentials are available under NDA. Request a capability discussion →
Service Offers
Structured, outcome-defined engagements. Each service produces real documentation, real assessments, and real evidence — not slide decks or advisory memos.
Pre-audit assessment of your current control environment against the target framework. We identify evidence gaps, build the evidence pack, and prepare your team for auditor interaction — so nothing comes as a surprise.
Structured policy and procedure libraries tailored to your organisation's size, sector, and regulatory obligations. Produced in formats suitable for board adoption, audit submission, and procurement responses.
For organisations that must demonstrate supply chain security to customers, partners, or as part of a procurement process — and for those that need to assess and govern their own vendor base. We produce structured assurance documentation that meets customer requirements and supports ongoing vendor oversight.
Ongoing fractional CISO and governance support on a monthly retainer basis. Suitable for organisations that need a credible, senior security voice without the cost or overhead of a full-time hire.
Design and documentation of a structured, tooling-agnostic vulnerability management programme — including triage criteria, SLA frameworks, remediation governance, exception handling, and senior reporting.
Response preparation for incoming security questionnaires from customers, partners, and contracting authorities — and design of outbound supplier assurance programmes to satisfy your own governance obligations.
Structured readiness and gap assessment against ISO 27001 (information security), ISO 42001 (AI management systems), and NIST CSF maturity tiers — producing auditable evidence packs and actionable remediation plans.
Founder & Credentials
DandaCyber is built on the experience of a senior practitioner with a career background spanning the insurance sector and complex ERP environments. ERP deployments in regulated environments demand rigorous access control, data classification, and audit trail governance — the same disciplines at the core of every DandaCyber engagement. That grounding in heavily regulated, documentation-intensive environments directly shapes how we approach every piece of work.
When you engage DandaCyber, you engage the founder directly. There is no delegation, no account management layer, and no handoff after contract signature. Every deliverable carries personal professional accountability.
EU Presence & Positioning
DandaCyber is based in Tallinn, Estonia — a deliberate choice, not an incidental one. Estonia is internationally recognised as the EU's most advanced digital governance jurisdiction, and operating within it provides our clients with substantive practical advantages.
Operating under GDPR, NIS2, DORA, and eIDAS by default — the same frameworks your organisation is likely navigating.
All client data, documentation, and engagement records remain within EU jurisdiction. No third-country exposure. No data sovereignty risk.
Estonia's e-governance model — home to NATO's CCDCOE — means digital trust and auditability are embedded in the operating environment DandaCyber was built in.
Active experience supporting clients across EU member states. Remote-first, with structured on-site capability where required by the engagement.
Why DandaCyber
DandaCyber is not structured like a consultancy practice. It is structured for clients who need a trusted, independent advisor rather than a vendor relationship.
We will execute a mutual NDA before you share anything sensitive — no pressure, no commitment required. Confidentiality is the starting point, not a concession made after negotiation.
Many clients operate under multiple overlapping frameworks simultaneously. We map controls across frameworks — ISO 27001, DORA, NIST, SWIFT — so you build once and satisfy many, without duplicating effort.
Engagements are scoped around defined deliverables with fixed or milestone-based pricing. You know exactly what you will receive, when, and at what cost — before any work begins. No open-ended billing.
Operating from within the EU means we understand the practical nuance of multi-jurisdictional regulatory environments. We are not advising from outside looking in — we operate in the same regulatory space as our clients.
Our deliverables are built for audit rooms, procurement portals, and board packs — not internal presentations. Every output is structured to hold up under direct examination by auditors, regulators, and contracting authorities.
We hold no reseller agreements, technology partnerships, or referral arrangements. When we recommend a control approach or tooling category, it is based solely on your requirements — not on what earns us a commission.
Get in Touch
All genuine enquiries receive a response within one business day. If you have a regulatory deadline, procurement window, or audit timeline in mind, please mention it — we will prioritise accordingly.
Initial capability discussions are complimentary and conducted without obligation. All engagements are fixed-fee — scope and cost are confirmed in writing before any work begins. We determine whether we are the right fit before proposing anything.