Service 02 · Govern

Governance, risk & compliance

Point Break Security helps organizations understand their cyber risks, meet their regulatory obligations and prove it to auditors, customers and regulators. We implement ISO/IEC 27001, support compliance with the Swiss nDSG, the GDPR, NIS2, DORA and FINMA requirements, and build risk management that works in practice.

What's included

What we deliver in governance, risk & compliance.

Cyber-risk assessment and quantification

Identify, assess and prioritize risks to the systems and data that matter most, expressed in terms leadership can act on.

ISO/IEC 27001 implementation

Scoping, risk treatment, Statement of Applicability, policies and controls, through to certification readiness.

Data protection under the nDSG and GDPR

Records of processing, data protection impact assessments, technical and organizational measures and breach procedures.

NIS2, DORA and FINMA

Applicability checks, gap analyses and remediation roadmaps for sector-specific and cross-border requirements.

Third-party and supply-chain risk

Vendor tiering, security assessments and contractual security requirements.

Audit readiness

Internal audits, evidence preparation and mock audits before certification or regulatory review.

When to engage us

Typical situations

  • You are preparing for ISO/IEC 27001 certification or a customer security audit.
  • New regulation applies to you, or you are unsure whether it does.
  • Customers and partners send you security questionnaires you struggle to answer.
  • An incident or audit finding exposed gaps in your controls.

What you receive

Deliverables

  • Overview of the regulations and standards that apply to you
  • Gap analysis with a prioritized remediation plan
  • Risk register and risk treatment plan
  • Policies, procedures and Statement of Applicability
  • Audit-ready evidence mapped to each requirement

How it works

A clear engagement, from scope to results.

  1. 01

    Scope

    Which obligations apply, to which entities, systems and data.

  2. 02

    Analyze

    Gap analysis against the relevant standards and regulations.

  3. 03

    Implement

    Controls, policies and evidence, built with your teams.

  4. 04

    Assure

    Internal audit, readiness review and continuous improvement.

FAQ

Questions about governance, risk & compliance.

Does NIS2 apply to Swiss companies?

NIS2 is an EU directive, so it does not apply in Switzerland directly. It can still affect Swiss organizations that operate in the EU, have EU subsidiaries or supply services to entities within its scope. We help you determine whether and how it applies to you.

Does DORA apply to Swiss companies?

DORA applies to financial entities in the EU and to the ICT third-party providers that serve them. Swiss financial institutions with EU operations, and Swiss providers serving EU financial entities, can be affected directly or through contractual requirements from their EU clients.

What is the revised Swiss data protection act (nDSG)?

The revised Federal Act on Data Protection (nDSG, also revFADP) has been in force since 1 September 2023. It strengthens transparency, requires many organizations to keep records of processing activities and obliges them to report data security breaches likely to result in a high risk to the Federal Data Protection and Information Commissioner (FDPIC).

Do you perform the ISO 27001 certification audit?

No. Certification audits are performed by accredited certification bodies. We prepare you for them, through implementation, internal audit and a readiness review, so that you go into the audit with confidence.

Related services

Often combined with

Let's talk about governance, risk & compliance.

A confidential first conversation with the people who would do the work.

Contact us