How the engagement runs. Shown, not asserted.
These are reference scenarios: recognizable industry archetypes walked through the real engagement model, with the real deliverable set. TruSecure does not present invented clients, quotes or results — when engagements complete and permission is granted, named case studies appear here, including TruSecure's own Romania/DNSC experience as a first-party reference.
A regional energy utility, newly in NIS2 scope
An electricity distribution operator — several hundred staff, generation subsidiary, grid operations, a SCADA estate built over two decades.
- Discovery
Applicability is determined entity by entity: grid operations lands as an Annex I essential entity; the generation subsidiary is tested against the size thresholds separately. The country assessment maps what the member state transposition actually demands — registration deadlines, sectoral supervisor, incident windows.
- AI-run mapping
Existing ISO 27001 work is crosswalked rather than discarded: a control evidenced once covers its NIS2, ISO and utility-regulation counterparts. The gap list enumerates what Annex I criticality actually adds — supply-chain security, business continuity with grid-specific dependencies.
- Human review and decisions
Working sessions place the SCADA estate at the top of the risk register with named ownership; the remediation backlog is sequenced around maintenance windows, not calendar quarters.
- What is running at the end
A board pack the executives can defend, an incident reporting pack naming who calls the CSIRT in which window, evidence flowing from the tools the utility already runs, and a registration-ready applicability record per entity.
A payment institution facing DORA's deadline
An EU-licensed payment institution — a few hundred staff, card processing, a mobile app, two dozen critical ICT providers.
- Discovery
DORA obligations are mapped against the NIS2 overlap so nothing is complied with twice. The maturity baseline shows where ICT risk management is strong (operations) and thin (third-party).
- AI-run mapping
The register of information — ICT providers, services, dependencies, concentration — is assembled from procurement and contract data the institution already holds. Contract clauses are mapped to what DORA requires them to say; gaps are enumerated clause by clause.
- Human review and decisions
Concentration risk in the two overlapping cloud providers is surfaced and owned; the resilience-testing strategy is sequenced against the regulatory timetable.
- What is running at the end
A living register of information instead of a spreadsheet, ICT risk tied to the incident-reporting workflow, third-party evidence collected as providers certify, and a board view of DORA readiness that updates with the data.
A device manufacturer whose product became software
A medical-device maker adding connected software and AI-based features to a regulated hardware line.
- Discovery
The AI features are classified against the EU AI Act risk tiers; the quality-management world (ISO 13485, MDR processes) is mapped as the governance backbone it already is.
- AI-run mapping
Existing QMS controls are crosswalked to ISO 27001 and the EU AI Act obligations for the roles the manufacturer actually holds — much of the machinery exists; the gap list shows precisely which parts do not. Technical documentation obligations are tied to the engineering artifacts that satisfy them.
- Human review and decisions
The team decides accountability split between product, quality and IT for the AI features — the decision the regulator will ask about first.
- What is running at the end
One control model serving the QMS and the security programme, AI-classification records with their evidence, a certification-preparation trail for the notified-body conversation, and a policy set modernized to name the AI boundary explicitly.
Different industries, same arc: applicability determined by fact, the tedious 80% automated and reviewed, the decisions taken by the people accountable for them, and a running system at the end.
Book a Resilience Sprint