Measure my level
Services Method GRC Suite About Contact
Security consultancy · EU · NIS2 · DORA · ISO 27001

Your company already has a security level.
Do you know what it is?

Every system, process and decision you run is already secured — to some degree. Corum makes that level visible, measures it, and helps you raise it to where regulators and customers expect it.

For companies from startups to enterprises across the EU.

SECURITY LEVEL
?
Unmeasured — like at most companies.
Move across the scale to try it
Certified expertise
CISSPCISSP-ISSAPCCSPCISMCISA CRISCCGEITISO 27001 LA/LIISO 27005 NIS2 Lead ImplementerDORA Lead ManagerSABSASANS
Our view

Security isn't something you buy and bolt on. It's a property your business already has — like quality or safety. The problem: nobody can see it — and nobody names it.

Invisible things get no budget, no owner and no board attention. So we start by making yours visible.

Standards & regulations

Once we name it, we can measure it. One measured level — and every framework becomes easier.

ISO 27001, NIS2, DORA and GDPR all demand the same thing underneath: that you know, manage and can prove your security level. Once the level is measured, each framework stops being a separate project and becomes a mapping exercise.

Faster certification

You start from a measured gap map, not a blank page — the audit verifies evidence instead of digging for it.

One system, many frameworks

A control implemented once counts across standards; one improvement raises your coverage in several frameworks at the same time.

Audit-ready, continuously

Levels, gaps and evidence live in the GRC tool all year — so a new regulation is an update, not a shock.

ISO/IEC 27001ISO/IEC 27005ISO 22301ISO/IEC 27017/18 NIS2DORAGDPREU AI ActISO/IEC 42001 NIST CSF 2.0SOC 2TISAX
What we do

Four services. One goal: a security level you can see and steer.

Start here

Security Level Assessment

3 weeks · fixed price

We measure your current security level (1–5) across your key domains, map the gaps against NIS2, DORA and ISO 27001, and give your management a one-page answer to “where do we stand?”. No jargon.

Compliance & Certification

ISO 27001 · NIS2 · DORA · GDPR

From zero to the ISO 27001 certificate, NIS2 and DORA readiness, GDPR. We build the system with your people — so it survives the audit, and the year after it.

vCISO — security leadership as a service

Monthly retainer

Senior security leadership for a fraction of a full-time hire. We run your security agenda, report to the board in business language, and track your level quarter by quarter.

Security Culture Programme

Diagnose · intervene · measure

Training alone doesn't change behaviour. We first diagnose why secure behaviour isn't happening — skills, environment or motivation — then target exactly that, and measure the change.

How we work

We make security visible — then manageable.

01

Reveal

We name everything in your business that already has a security level: systems, processes, suppliers, decisions.

02

Measure

Each domain gets a level from 1 to 5 against an explicit threat model. No guesswork, no fear-selling.

03

Govern

Gaps become a plan with owners, budgets and deadlines your board actually understands.

04

Improve

Levels are tracked continuously in the GRC tool — progress becomes visible, not assumed.

The bonus

GRC Suite — the tool we work with. Yours, free.

A self-hosted governance, risk & compliance platform built for EU-regulated companies. We use it at every client — and you can download it and run it yourself. Your data never leaves your servers.

v2.14Self-hostedEN · SK · DE · FR · NL
  • 18 built-in frameworks — ISO 27001, NIS2, DORA, GDPR, EU AI Act and more
  • Risk register with Monte Carlo simulation and KRI dashboards
  • NIS2 & DORA incident reporting with deadlines built in
  • Business continuity, GDPR and AI-governance modules
  • Interface in EN · SK · DE · FR · NL
  • Self-hosted — your data stays with you

Free download · runs on your own server · optional deployment & support by Corum

Who we are

Boutique expertise from the heart of Europe.

Corum is a security consultancy based in Slovakia and the Czech Republic, working with companies across the EU. Every engagement is led by senior, certified experts — no junior staffing, no outsourcing.

Corum s.r.o.

Tatranská 3109/4
010 08 Žilina
Slovensko

IČO 53343328 · VAT SK2121346040

Corum CZ s.r.o.

Kačírkova 3041/11
746 01 Opava
Česká republika

IČO 17099684 · VAT CZ17099684

Contact

Find out your security level.

A 30-minute call is enough to tell you whether — and how — we can help. No obligations.

Book a consultation