Estonia-Based  ·  EU Registered · Reg. 17531084  ·  Founder-Led

Cyber Assurance
and Governance
Support

Regulated organisations and procurement-critical environments need governance evidence that holds up under real scrutiny — not advisory memos. DandaCyber delivers structured, auditable documentation and assurance work, directly from a senior practitioner, on a fixed-fee basis.

CISSP & CISM Certified ISO 27001 & ISO 42001 PECB Certified Trainer EU Data Residency
Frameworks & standards supported:
ISO 27001 ISO 42001 NIST CSF 2.0 DORA CIS Controls v8 SWIFT Cyber Essentials

About DandaCyber

Independent. Practitioner-Led.
Procurement-Ready.

DandaCyber is a founder-led cyber assurance and governance support practice based in Tallinn, Estonia. We exist specifically to serve organisations that operate in regulated, procurement-intensive, or compliance-critical environments — where the quality of your security governance documentation directly affects your commercial and operational standing.

We are not a managed security service provider. We do not sell technology or hold vendor partnerships. What we provide is independent, practitioner-grade assurance, documentation, and governance support — delivered with personal accountability at every stage.

Direct Practitioner Delivery

You engage with the founder. The same person scopes, delivers, and presents every engagement. No junior handoffs.

Vendor-Independent by Principle

No reseller arrangements, no technology affiliations. Every recommendation is based solely on your context and requirements.

Auditable, Defensible Outputs

All deliverables are designed to withstand scrutiny — from internal audit to regulatory inspection to procurement evaluation.

Capabilities Statement

Core Competency Areas

A structured overview of DandaCyber's practitioner capabilities — suitable for inclusion in supplier qualification processes, procurement responses, and due diligence packs.

This capabilities statement provides a procurement-ready summary of competency areas. For outcome-defined service descriptions with specific deliverables, see Service Offers below.

Cyber Risk & Governance

Risk register development, governance framework design, appetite statements, control owner assignment, and board-level reporting structures.

Audit & Assurance

Pre-audit readiness assessment, evidence pack construction, control gap analysis, and structured remediation planning against major frameworks.

Security Documentation

Policy suites, procedure libraries, ISMS documentation, data classification frameworks, and procurement-ready security governance packs.

Supply Chain Assurance

Third-party risk tiering, supplier questionnaire design, subcontractor assurance evidence, and supply chain governance support for organisations with complex vendor relationships.

Board & Audit Committee Reporting Support

Retained fractional CISO function — board attendance, incident response readiness, regulatory engagement, and ongoing cyber leadership without full-time overhead.

Vulnerability Management

Process design, tooling-agnostic programme architecture, SLA frameworks, remediation governance, and reporting to senior stakeholders.

Who We Support

Built for Environments Where Assurance is Non-Negotiable

DandaCyber is positioned specifically for clients where cyber governance is a baseline commercial and regulatory requirement — not an optional enhancement.

Regulated Organisations

Financial institutions, healthcare providers, utilities, and critical infrastructure operators navigating NIS2, DORA, or sector-specific mandatory frameworks. We produce the structured evidence regulators expect.

  • NIS2 readiness
  • DORA compliance
  • Regulatory evidence

Supply Chain, Procurement & Bid Environments

Organisations that must demonstrate a documented assurance posture to customers, partners, or as a condition of winning and retaining contracts — whether responding to private sector vendor questionnaires or public sector tender cyber scoring criteria. We produce evidence packs built for real scrutiny.

  • Vendor assurance packs
  • Tender cyber scoring
  • Questionnaire responses
  • Evidence compilation

SMEs in Regulated Sectors

Small and mid-sized companies operating in regulated sectors who need enterprise-grade governance documentation without the overhead of a large internal security function.

  • Right-sized governance
  • ISO readiness
  • NIST maturity

Engagement Outcomes

Work That Has Been Delivered

A selection of anonymised engagement outcomes. Client names and identifying details are withheld by default — full references available under NDA upon request.

Global Regulated Financial Services

Multi-Framework Controls Consolidation

A globally operating financial services organisation subject to multiple overlapping regulatory frameworks across several jurisdictions required a single, coherent control environment. Working as part of a managed services delivery team, we produced a consolidated controls mapping matrix that satisfied each framework's requirements without duplicating control ownership — reducing audit overhead and providing a single source of truth for regulators across jurisdictions.

Multi-jurisdiction Controls mapping Regulatory frameworks
Regulated Industry — ISO 27001 Certification

ISO 27001 Implementation from Zero to Certification

A regulated organisation with no existing information security management system required a complete ISO 27001 implementation. We conducted the initial gap analysis, led policy and standard creation, supported the internal audit programme, constructed the evidence pack, and managed the approval process through to certification. The organisation achieved certification at first audit attempt.

ISO 27001 Gap analysis ISMS build First-attempt certification
Supply Chain & Procurement Environment

Third-Party Risk and Supplier Assurance Programme

An organisation with a complex supplier base and procurement obligations required a structured approach to third-party risk. We designed a risk-based supplier tiering model, developed the assurance questionnaire suite, produced subcontractor assurance evidence templates, and documented the governance framework — enabling the organisation to demonstrate supply chain oversight to both customers and contracting authorities.

Third-party risk Supplier tiering Assurance questionnaires Supply chain governance

All engagements described above are anonymised. Named references, sector-specific case detail, and practitioner credentials are available under NDA. Request a capability discussion →

Service Offers

What We Deliver

Structured, outcome-defined engagements. Each service produces real documentation, real assessments, and real evidence — not slide decks or advisory memos.

Audit Readiness & Evidence Support

High Demand

Pre-audit assessment of your current control environment against the target framework. We identify evidence gaps, build the evidence pack, and prepare your team for auditor interaction — so nothing comes as a surprise.

  • Control gap analysis against target standard
  • Evidence pack construction and formatting
  • Remediation roadmap with prioritised actions
  • Auditor-ready documentation set

Security Documentation Packages

Structured policy and procedure libraries tailored to your organisation's size, sector, and regulatory obligations. Produced in formats suitable for board adoption, audit submission, and procurement responses.

  • ISMS policy suite (core and supporting policies)
  • Procedures, work instructions, and registers
  • Data classification and handling framework
  • Bespoke or template-based, fully tailored

Supply Chain & Vendor Assurance Support

For organisations that must demonstrate supply chain security to customers, partners, or as part of a procurement process — and for those that need to assess and govern their own vendor base. We produce structured assurance documentation that meets customer requirements and supports ongoing vendor oversight.

  • Supplier security assurance packs
  • Third-party risk tiering and assessment design
  • Vendor oversight framework documentation
  • Customer security questionnaire response support

Monthly Governance & Board Reporting Retainers

Retained

Ongoing fractional CISO and governance support on a monthly retainer basis. Suitable for organisations that need a credible, senior security voice without the cost or overhead of a full-time hire.

  • Monthly governance and risk review sessions
  • Board and audit committee attendance
  • Incident response readiness and oversight
  • Regulatory engagement and correspondence support

Vulnerability Management Process Design

Design and documentation of a structured, tooling-agnostic vulnerability management programme — including triage criteria, SLA frameworks, remediation governance, exception handling, and senior reporting.

  • VM policy and procedure documentation
  • Risk-based triage and prioritisation framework
  • SLA and exception governance structure
  • Reporting metrics and executive dashboard design

Customer Security Questionnaire & Supplier Assurance Support

Response preparation for incoming security questionnaires from customers, partners, and contracting authorities — and design of outbound supplier assurance programmes to satisfy your own governance obligations.

  • Security questionnaire response drafting
  • Evidence library construction for reuse
  • Supplier questionnaire design and scoring
  • Assurance programme governance documentation

ISO 27001 / ISO 42001 & NIST Readiness Support

Structured readiness and gap assessment against ISO 27001 (information security), ISO 42001 (AI management systems), and NIST CSF maturity tiers — producing auditable evidence packs and actionable remediation plans.

  • ISO 27001 / ISO 42001 gap and readiness report
  • NIST CSF current-state maturity assessment
  • Target-state roadmap with control mapping
  • Certification-pathway support documentation

Founder & Credentials

Senior Practitioner Background. Personal Accountability.

DandaCyber is built on the experience of a senior practitioner with a career background spanning the insurance sector and complex ERP environments. ERP deployments in regulated environments demand rigorous access control, data classification, and audit trail governance — the same disciplines at the core of every DandaCyber engagement. That grounding in heavily regulated, documentation-intensive environments directly shapes how we approach every piece of work.

When you engage DandaCyber, you engage the founder directly. There is no delegation, no account management layer, and no handoff after contract signature. Every deliverable carries personal professional accountability.

Founder, DandaCyber Tallinn, Estonia · EU
CISSP Certified Information Systems Security Professional — (ISC)²
CISM Certified Information Security Manager — ISACA
ISO 27001 Lead Implementer Information Security Management Systems
ISO 42001 Lead Implementer Artificial Intelligence Management Systems
Certified Operational Resilience Professional Operational resilience & continuity assurance
Certified Payment Security Practitioner Payment systems security & compliance
Full name and registration details available under NDA or upon formal engagement request.

EU Presence & Positioning

Registered and Operating Within the EU

DandaCyber is based in Tallinn, Estonia — a deliberate choice, not an incidental one. Estonia is internationally recognised as the EU's most advanced digital governance jurisdiction, and operating within it provides our clients with substantive practical advantages.

Full EU Regulatory Jurisdiction

Operating under GDPR, NIS2, DORA, and eIDAS by default — the same frameworks your organisation is likely navigating.

EU Data Residency — No Ambiguity

All client data, documentation, and engagement records remain within EU jurisdiction. No third-country exposure. No data sovereignty risk.

Digital Governance Pioneer

Estonia's e-governance model — home to NATO's CCDCOE — means digital trust and auditability are embedded in the operating environment DandaCyber was built in.

Pan-European Reach

Active experience supporting clients across EU member states. Remote-first, with structured on-site capability where required by the engagement.

Republic of Estonia EU Member State  ·  NATO Ally  ·  CCDCOE Host
#1 EU Digital Economy Index
NATO CCDCOE Host Nation
EU Full regulatory jurisdiction

Why DandaCyber

A Different Kind of Engagement

DandaCyber is not structured like a consultancy practice. It is structured for clients who need a trusted, independent advisor rather than a vendor relationship.

NDA Before Any Disclosure

We will execute a mutual NDA before you share anything sensitive — no pressure, no commitment required. Confidentiality is the starting point, not a concession made after negotiation.

Cross-Framework Control Mapping

Many clients operate under multiple overlapping frameworks simultaneously. We map controls across frameworks — ISO 27001, DORA, NIST, SWIFT — so you build once and satisfy many, without duplicating effort.

Fixed-Fee Certainty

Engagements are scoped around defined deliverables with fixed or milestone-based pricing. You know exactly what you will receive, when, and at what cost — before any work begins. No open-ended billing.

EU-Anchored and Jurisdiction-Aware

Operating from within the EU means we understand the practical nuance of multi-jurisdictional regulatory environments. We are not advising from outside looking in — we operate in the same regulatory space as our clients.

Evidence That Withstands Scrutiny

Our deliverables are built for audit rooms, procurement portals, and board packs — not internal presentations. Every output is structured to hold up under direct examination by auditors, regulators, and contracting authorities.

No Vendor Agenda — Ever

We hold no reseller agreements, technology partnerships, or referral arrangements. When we recommend a control approach or tooling category, it is based solely on your requirements — not on what earns us a commission.

All capability discussions can be conducted under mutual NDA. No commitment required before disclosure. Request one on the form below — we will execute promptly.
Request a Discussion

Get in Touch

Request a Capability Discussion

All genuine enquiries receive a response within one business day. If you have a regulatory deadline, procurement window, or audit timeline in mind, please mention it — we will prioritise accordingly.

Initial capability discussions are complimentary and conducted without obligation. All engagements are fixed-fee — scope and cost are confirmed in writing before any work begins. We determine whether we are the right fit before proposing anything.

EU data residency — all enquiry data stays within the EU
Fixed-fee engagements — scope and cost confirmed in writing before any work begins
First response typically same business day
Mutual NDA available on request — tick the box on the form or email us directly

By submitting this form you consent to DandaCyber OÜ processing the information you provide solely for the purpose of responding to your enquiry. Data is processed under GDPR and retained within EU jurisdiction. See our Privacy Policy.