★ 4.8/5.0 Google Reviews · for organisations of 50–250 employees
Compliance that survives an inspection.
A certificate doesn't discharge your duty of care — and the regulator is entitled to inspect your systems on site. I put in place the technology that gets you through that moment, and I run that same stack myself.
Not just my claim — the regulator's
The Dutch Cyber Security Act (Cyberbeveiligingswet) enters into force on 15 August 2026. The Rijksinspectie Digitale Infrastructuur (RDI) — the Dutch regulator responsible for enforcement — has been explicit about what that means in practice. Below are the RDI's own statements in the original Dutch, alongside an English translation.
“Nee, het voldoen aan een eigen normenkader betekent niet dat een organisatie aan de zorgplicht voldoet.”
Translation: “No, meeting a self-defined normative framework does not mean an organisation meets its duty of care.”
— RDI (Dutch regulator), translated from Dutch
“Ook mogen we ter plekke uw systemen inkijken.”
Translation: “We are also permitted to inspect your systems on site.”
— RDI (Dutch regulator), translated from Dutch
Three ways I deliver
Implementation, governance and training. Which one you need depends on how far along you already are.
Implementation
Actually putting the measures in place: access management, encryption, backup and recovery, monitoring. Working technology, not a folder of policy documents.
Learn more →Governance
Oversight of suppliers, contracts and demonstrability. So that during an inspection you can show that it works, not just that it's documented.
Learn more →Training
Bringing boards and organisations up to speed on what's expected of them. The Cyber Security Act places the responsibility explicitly with the board, including a duty to train.
Learn more →Judge me by my work
My clients work under confidentiality, so you won't find logos here. What you will find: platforms running in production, code you can read, and a security analysis that's publicly verifiable. Check it yourself and judge.
View the projects →Technology & trust
Ready to get your compliance in order?
A short 30-minute call. No obligations, no sales pitch. Just an honest look at where you stand and where I can help.
Book a call →