Cyber-risk assessment and quantification
Identify, assess and prioritize risks to the systems and data that matter most, expressed in terms leadership can act on.
Service 02 · Govern
Point Break Security helps organizations understand their cyber risks, meet their regulatory obligations and prove it to auditors, customers and regulators. We implement ISO/IEC 27001, support compliance with the Swiss nDSG, the GDPR, NIS2, DORA and FINMA requirements, and build risk management that works in practice.
What's included
Identify, assess and prioritize risks to the systems and data that matter most, expressed in terms leadership can act on.
Scoping, risk treatment, Statement of Applicability, policies and controls, through to certification readiness.
Records of processing, data protection impact assessments, technical and organizational measures and breach procedures.
Applicability checks, gap analyses and remediation roadmaps for sector-specific and cross-border requirements.
Vendor tiering, security assessments and contractual security requirements.
Internal audits, evidence preparation and mock audits before certification or regulatory review.
When to engage us
What you receive
How it works
Which obligations apply, to which entities, systems and data.
Gap analysis against the relevant standards and regulations.
Controls, policies and evidence, built with your teams.
Internal audit, readiness review and continuous improvement.
FAQ
NIS2 is an EU directive, so it does not apply in Switzerland directly. It can still affect Swiss organizations that operate in the EU, have EU subsidiaries or supply services to entities within its scope. We help you determine whether and how it applies to you.
DORA applies to financial entities in the EU and to the ICT third-party providers that serve them. Swiss financial institutions with EU operations, and Swiss providers serving EU financial entities, can be affected directly or through contractual requirements from their EU clients.
The revised Federal Act on Data Protection (nDSG, also revFADP) has been in force since 1 September 2023. It strengthens transparency, requires many organizations to keep records of processing activities and obliges them to report data security breaches likely to result in a high risk to the Federal Data Protection and Information Commissioner (FDPIC).
No. Certification audits are performed by accredited certification bodies. We prepare you for them, through implementation, internal audit and a readiness review, so that you go into the audit with confidence.
Related services
A confidential first conversation with the people who would do the work.