Business Security and Resilience

Achieve compliance and build sustainable security and resilience.

Pass audits faster and evidence compliance with advisory playbooks tuned to your risks.

Xiphos d.o.o. helps small and medium-sized organisations build practical cybersecurity, continuity and compliance programs that work in real life, not only on paper.

25+ years experience 1000+ trainings delivered ISO 27001, ISO 22301, NIS2, DORA, GDPR

Security that survives audits and incidents.

We design systems, policies and training that keep your security program resilient. You stay ready for auditors, regulators and real incidents.

{{ metrics.keyDomains.display }} Key domains

Cybersecurity, continuity, risk and compliance, supplier oversight.

{{ metrics.serviceTiers.display }} Service tiers

Advisory, implementation projects and tailored training packages.

What Xiphos does

We combine hands-on consulting, structured training and practical tools so your teams get clear structure, make faster decisions and reduce operational friction while meeting regulatory expectations and building real security and resilience.

ISO 27001 information security

Implementation and consulting for information security management systems, from initial gap assessment to full certification, surveillance audits and continuous improvement.

  • Gap analysis and implementation roadmap
  • Risk assessment and treatment
  • Policies, controls and documentation
  • Preparation for certification audits
Read more

Blended on-site and remote support keeps momentum steady, with templates and coaching your teams can reuse.

Learn more

ISO 42001 AI governance

AI governance aligned with ISO 42001 so your AI use cases remain transparent, accountable and controlled.

  • AI system scoping and risk assessment
  • Policies and controls for responsible AI
  • Model lifecycle and supplier oversight
  • Readiness for audits and certifications
Read more

We map controls to your architecture, close gaps with pragmatic guardrails and prep evidence for auditors.

Learn more

ISO 22301 business continuity

Structured business continuity management that protects your critical services, people and assets from disruption, aligned with ISO 22301.

  • Business impact analysis
  • Continuity and recovery strategies
  • Exercises and scenario workshops
  • Support for certification
Read more

Continuity runbooks and playbooks are designed with your teams, making testing faster and lessons learned reusable.

Learn more

Regulatory compliance: NIS2, DORA, GDPR

Practical interpretation and implementation of regulatory requirements, so that compliance supports your business instead of slowing it down.

  • NIS2 readiness and implementation
  • DORA compliance for financial entities
  • GDPR assessments and DPIA
  • Third party and ICT supplier oversight
Read more

We align controls to critical services, set measurable milestones and brief leadership in plain language.

Learn more

Advisory and fractional CISO

Fractional CISO and ICT risk management advisory for organisations that need senior guidance without building a large internal team.

  • Security and risk strategy
  • Governance and reporting
  • Incident and crisis advisory
  • Coaching for internal teams
Read more

Engagements blend board-level updates with hands-on support so internal teams gain confidence quickly.

Learn more

Audits, health checks and training

Independent reviews of security, continuity and compliance with clear findings your teams can implement, plus targeted training that builds confidence.

  • ISMS internal audits and pre-certification checks
  • Business continuity and resilience assessments
  • Risk management and supplier reviews
  • Tailored training, workshops and exercises
Read more

Reports prioritise quick wins and structural fixes with owners, timelines and evidence you can track.

Learn more

Trusted by teams that need to move fast

Proof points without the marketing noise.

Engagements span regulated industries, critical infrastructure, fintech scale-ups and public sector programmes.

Financial services Energy & utilities Telecom & cloud Public sector Health & pharma Technology scale-ups
Delivery

1,000+ workshops and exercises delivered with average 4.9/5 participant rating.

Audit-ready

ISO 27001 and 22301 implementations that pass certification on first attempt.

Regulatory

NIS2, DORA and GDPR programmes aligned to business priorities, not paperwork.

Trusted by teams with high stakes

Practical programs for financial services, technology, critical infrastructure and regulated suppliers that need audit-ready outcomes without slowing delivery.

“Xiphos translated regulations into clear steps we could execute with our teams.”

COO, digital banking provider

“Workshops were hands-on and immediately improved our incident readiness.”

Head of Operations, SaaS platform

“Auditors appreciated the pragmatic evidence and traceability of controls.”

Risk Lead, infrastructure operator

Ready to talk

Whether you are facing a new regulation, planning for certification or recovering from an incident, a focused conversation can clarify your options.

Book a free introductory consulting session

A 60-minute online session focused on your current situation, key risks and practical next steps.

Book your session