Skip to main content
CASE STUDIES

How the engagement runs. Shown, not asserted.

These are reference scenarios: recognizable industry archetypes walked through the real engagement model, with the real deliverable set. TruSecure does not present invented clients, quotes or results — when engagements complete and permission is granted, named case studies appear here, including TruSecure's own Romania/DNSC experience as a first-party reference.

A regional energy utility, newly in NIS2 scope

An electricity distribution operator — several hundred staff, generation subsidiary, grid operations, a SCADA estate built over two decades.

  1. Discovery

    Applicability is determined entity by entity: grid operations lands as an Annex I essential entity; the generation subsidiary is tested against the size thresholds separately. The country assessment maps what the member state transposition actually demands — registration deadlines, sectoral supervisor, incident windows.

  2. AI-run mapping

    Existing ISO 27001 work is crosswalked rather than discarded: a control evidenced once covers its NIS2, ISO and utility-regulation counterparts. The gap list enumerates what Annex I criticality actually adds — supply-chain security, business continuity with grid-specific dependencies.

  3. Human review and decisions

    Working sessions place the SCADA estate at the top of the risk register with named ownership; the remediation backlog is sequenced around maintenance windows, not calendar quarters.

  4. What is running at the end

    A board pack the executives can defend, an incident reporting pack naming who calls the CSIRT in which window, evidence flowing from the tools the utility already runs, and a registration-ready applicability record per entity.

A payment institution facing DORA's deadline

An EU-licensed payment institution — a few hundred staff, card processing, a mobile app, two dozen critical ICT providers.

  1. Discovery

    DORA obligations are mapped against the NIS2 overlap so nothing is complied with twice. The maturity baseline shows where ICT risk management is strong (operations) and thin (third-party).

  2. AI-run mapping

    The register of information — ICT providers, services, dependencies, concentration — is assembled from procurement and contract data the institution already holds. Contract clauses are mapped to what DORA requires them to say; gaps are enumerated clause by clause.

  3. Human review and decisions

    Concentration risk in the two overlapping cloud providers is surfaced and owned; the resilience-testing strategy is sequenced against the regulatory timetable.

  4. What is running at the end

    A living register of information instead of a spreadsheet, ICT risk tied to the incident-reporting workflow, third-party evidence collected as providers certify, and a board view of DORA readiness that updates with the data.

A device manufacturer whose product became software

A medical-device maker adding connected software and AI-based features to a regulated hardware line.

  1. Discovery

    The AI features are classified against the EU AI Act risk tiers; the quality-management world (ISO 13485, MDR processes) is mapped as the governance backbone it already is.

  2. AI-run mapping

    Existing QMS controls are crosswalked to ISO 27001 and the EU AI Act obligations for the roles the manufacturer actually holds — much of the machinery exists; the gap list shows precisely which parts do not. Technical documentation obligations are tied to the engineering artifacts that satisfy them.

  3. Human review and decisions

    The team decides accountability split between product, quality and IT for the AI features — the decision the regulator will ask about first.

  4. What is running at the end

    One control model serving the QMS and the security programme, AI-classification records with their evidence, a certification-preparation trail for the notified-body conversation, and a policy set modernized to name the AI boundary explicitly.

Different industries, same arc: applicability determined by fact, the tedious 80% automated and reviewed, the decisions taken by the people accountable for them, and a running system at the end.

Book a Resilience Sprint