Security Level Assessment
We measure your current security level (1–5) across your key domains, map the gaps against NIS2, DORA and ISO 27001, and give your management a one-page answer to “where do we stand?”. No jargon.
Every system, process and decision you run is already secured — to some degree. Corum makes that level visible, measures it, and helps you raise it to where regulators and customers expect it.
For companies from startups to enterprises across the EU.
Security isn't something you buy and bolt on. It's a property your business already has — like quality or safety. The problem: nobody can see it — and nobody names it.
Invisible things get no budget, no owner and no board attention. So we start by making yours visible.
ISO 27001, NIS2, DORA and GDPR all demand the same thing underneath: that you know, manage and can prove your security level. Once the level is measured, each framework stops being a separate project and becomes a mapping exercise.
You start from a measured gap map, not a blank page — the audit verifies evidence instead of digging for it.
A control implemented once counts across standards; one improvement raises your coverage in several frameworks at the same time.
Levels, gaps and evidence live in the GRC tool all year — so a new regulation is an update, not a shock.
We measure your current security level (1–5) across your key domains, map the gaps against NIS2, DORA and ISO 27001, and give your management a one-page answer to “where do we stand?”. No jargon.
From zero to the ISO 27001 certificate, NIS2 and DORA readiness, GDPR. We build the system with your people — so it survives the audit, and the year after it.
Senior security leadership for a fraction of a full-time hire. We run your security agenda, report to the board in business language, and track your level quarter by quarter.
Training alone doesn't change behaviour. We first diagnose why secure behaviour isn't happening — skills, environment or motivation — then target exactly that, and measure the change.
We name everything in your business that already has a security level: systems, processes, suppliers, decisions.
Each domain gets a level from 1 to 5 against an explicit threat model. No guesswork, no fear-selling.
Gaps become a plan with owners, budgets and deadlines your board actually understands.
Levels are tracked continuously in the GRC tool — progress becomes visible, not assumed.
A self-hosted governance, risk & compliance platform built for EU-regulated companies. We use it at every client — and you can download it and run it yourself. Your data never leaves your servers.
Free download · runs on your own server · optional deployment & support by Corum
Corum is a security consultancy based in Slovakia and the Czech Republic, working with companies across the EU. Every engagement is led by senior, certified experts — no junior staffing, no outsourcing.
Tatranská 3109/4
010 08 Žilina
Slovensko
IČO 53343328 · VAT SK2121346040
Kačírkova 3041/11
746 01 Opava
Česká republika
IČO 17099684 · VAT CZ17099684
A 30-minute call is enough to tell you whether — and how — we can help. No obligations.
Book a consultation