Continuous Risk Assessment
Not an annual audit, but a quarterly-updated view of risk that reflects the threat landscape observed by our CTI: who is targeting your sector, which techniques, which assets they're hitting.
Consulting firms produce slides. Fortgale produces runbooks and detections. Our advisory is anchored to our SOC, MDR and proprietary CTI: every recommendation translates into an applicable procedure and updates when the threat landscape changes — not when the contract expires.
The Fortgale strategic workshop with the Board includes a compromise simulation: you see an attacker move, we discuss together what the defense outpost detects, what the Board decides, when the national CERT notification is triggered. This is a condensed version.
Fortgale Cybersecurity Advisory is the strategic layer of the defense outpost. It defines posture, translates regulatory obligations into a roadmap, prepares for the worst plausible scenario — and then measures results every quarter.
The standard Advisory engagement combines risk governance, applied compliance and operational readiness. Each capability is modular based on the customer profile.
Not an annual audit, but a quarterly-updated view of risk that reflects the threat landscape observed by our CTI: who is targeting your sector, which techniques, which assets they're hitting.
Gap analysis, remediation roadmap, board-ready documentation. We support national CERT notification within 24 hours and the 72-hour documentation required by NIS2, plus all DORA requirements for the financial sector.
Incident simulations built on the TTPs of the most probable adversary against your sector: LockBit 4.0 against manufacturing, Scattered Spider against insurance, Cl0p against finance. Not generic scenarios.
Board reporting in risk language, not technology language. Four reports per year with posture metrics, incidents handled, remediation roadmap, residual exposure. Ready to present in audit committee.
Suppliers are the modern primary attack surface. We build a vendor evaluation and monitoring process for critical suppliers, consistent with NIS2 (supply chain) and DORA (third-party ICT risk).
A senior reference acting as virtual CISO or advisor alongside an existing CISO. Unlike an independent vCISO, our advisor is connected to Fortgale's SOC, MDR and CTI: direct visibility on customer incidents and metrics.
Posture is not a state, it's a process. Our model combines assessment, roadmap, execution, and review in a quarterly cycle.
Analysis of existing cyber posture: governance, processes, controls, assets, regulatory exposure. Mapping against relevant frameworks (NIS2, DORA, ISO 27001, NIST CSF) and identification of critical gaps.
Profile of the most probable threat actors for your sector and size, based on Fortgale CTI: who has already targeted you, who is targeting your peers, which campaigns are active.
12-24 month roadmap with priorities based on real risk, not regulatory checklists. Each intervention has owner, KPI, deadline, and estimated budget. Ready for the Board.
We work alongside the internal team during implementation: runbook review, tabletop on real adversaries to validate readiness, support for NIS2/DORA compliance, vendor governance.
Quarterly review of posture: what changed in the threat landscape, which remediations are complete, which new risks emerge. Posture is not a state, it's a process.
A new CISO needs an objective view of the inherited posture, realistic prioritisation, and a partner working alongside them without internal politics. Fortgale Advisory provides the framework, the metrics, and the European context to set up the first 100 days.
Essential entities (energy, healthcare, transport, banking, strategic manufacturing) face heavy obligations and tight timelines. Our Advisory translates NIS2 articles into an implementable, audit-demonstrable roadmap.
The Digital Operational Resilience Act requires ICT risk management frameworks, scenario testing, critical vendor governance. Fortgale supports the DORA journey with direct experience on actors targeting European finance (Cl0p, FIN7).
Mid-to-large manufacturing companies that do not have a full-time internal CISO but are still active targets (LockBit, Akira, BlackCat). The Fortgale vCISO model provides senior coverage at predictable cost.
One meeting, one NDA, one initial risk briefing. You'll receive an objective view of your posture and a concrete roadmap proposal within 72 hours of the meeting.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.