Skip to main content
ICITC Continuum
Services

A structured path from risk to resilience.

Four complementary areas of expertise covering your entire security programme — from initial diagnostic to continuous improvement.

01

Cyber Risk

The business problem

Most organisations invest in security without a clear, prioritised view of their actual risk exposure. The result is budget spread across secondary issues while the scenarios that could genuinely hurt the business go untreated.

Why it matters

Boards, insurers and customers no longer ask 'are you secure?' — they ask 'do you understand your risks, and how are you treating them?'. Without a structured risk map built on a recognised method, it becomes impossible to justify priorities, budgets or trade-offs to the people who ultimately own the decision.

Our approach

  1. 1Scope the assessment across business lines, critical assets, information systems and third-party dependencies.
  2. 2Identify and qualify risk sources, feared events and threat scenarios relevant to your sector.
  3. 3Assess likelihood and severity for each scenario to build a prioritised risk map.
  4. 4Define a realistic risk treatment plan aligned with your budget and operational constraints.

Methodology

  • EBIOS Risk Manager method (ANSSI / Club EBIOS)
  • NIST Cybersecurity Framework to structure control areas
  • MITRE ATT&CK mapping to model realistic threat scenarios

Deliverables

  • Prioritised cyber risk map
  • Threat analysis report with feared-event scenarios
  • Risk treatment plan with quick wins and structural workstreams
  • 12–24 month security roadmap

Typical timeline

4 to 8 weeks depending on scope

Starting investment

From €3,500

02

Cyber Compliance

The business problem

NIS2, ISO 27001, customer and sector requirements: compliance obligations keep multiplying, and are often treated as administrative overhead rather than a genuine security lever. Many organisations end up with policies that look good on paper but bear little resemblance to actual practice.

Why it matters

Compliance on paper only creates a double risk: regulatory exposure if audited, and — more importantly — a false sense of security that leaves real risks untreated. Done properly, compliance work becomes a security programme that actually protects the business, not just a binder on a shelf.

Our approach

  1. 1Analyse applicable requirements (NIS2, ISO 27001, contractual and sector-specific obligations).
  2. 2Assess gaps between current practice and the target framework through a structured diagnostic.
  3. 3Prioritise actions by security impact and implementation complexity.
  4. 4Support the rollout of the policies, procedures and evidence needed for compliance.

Methodology

  • ISO/IEC 27001 (Information Security Management System)
  • NIS2 Directive and national transposition frameworks
  • NIST Cybersecurity Framework and IEC 62443 for industrial environments

Deliverables

  • Documented gap analysis
  • Security policies and procedures tailored to your context
  • Prioritised compliance roadmap
  • Audit or certification readiness file

Typical timeline

8 to 16 weeks depending on the framework and scope

Starting investment

From €5,000

03

IT/OT Security

The business problem

Industrial environments combine legacy systems, continuous-availability requirements and remote access multiplied by integrators and maintenance vendors. Traditional IT security approaches, designed around data confidentiality, translate poorly to a world where production downtime and personnel safety are the dominant risks.

Why it matters

An incident in an OT environment is never just an IT incident: it can halt a production line, damage equipment or endanger operators. IT/OT convergence, driven by Industry 4.0, keeps expanding the attack surface faster than security controls tend to follow.

Our approach

  1. 1Map assets, networks and data flows across IT and OT environments.
  2. 2Assess risks specific to industrial settings: availability, safety, legacy systems, vendor access.
  3. 3Design a security architecture and segmentation model that respects production constraints.
  4. 4Prioritise measures by their impact on both safety and operational continuity.

Methodology

  • IEC 62443 (security for industrial automation and control systems)
  • NIST Cybersecurity Framework adapted to OT environments
  • Purdue Model for IT/OT architecture segmentation

Deliverables

  • IT/OT asset and data-flow map
  • Risk and vulnerability assessment of industrial environments
  • Architecture and network segmentation recommendations
  • Prioritised action plan compatible with production constraints

Typical timeline

6 to 12 weeks depending on the number of sites

Starting investment

From €6,000

04

Cyber Resilience

The business problem

The question is no longer whether an organisation will face a cyber incident, but when — and whether it will be ready. Many organisations discover their organisational gaps (decision-making, communication, continuity) during the incident itself, at the worst possible time.

Why it matters

A well-anticipated incident is resolved in hours; an unprepared one turns into a multi-week crisis, with far heavier operational, financial and reputational consequences. Resilience is built before the crisis, not during it.

Our approach

  1. 1Assess the organisation's detection, response and continuity maturity.
  2. 2Design or strengthen incident response, crisis management and business continuity plans.
  3. 3Test these plans through realistic crisis exercises (tabletop, technical simulation).
  4. 4Capture lessons learned to continuously improve the overall posture.

Methodology

  • NIST SP 800-61 (computer security incident handling)
  • ISO/IEC 22301 for business continuity management
  • MITRE ATT&CK framework and sector-specific lessons learned

Deliverables

  • Incident response and crisis management plan
  • Crisis exercise scenario and after-action report
  • Business continuity and recovery plan
  • Lessons-learned report with improvement recommendations

Typical timeline

3 to 6 weeks for an exercise; 8 to 12 weeks for a full programme

Starting investment

From €3,500

Let's discuss your security priority.

Every organisation starts from a different context. Let's talk about yours to identify the most useful priority.