Whalper Resilience turns your existing controls, backups and third-party relationships into a defensible evidence pack for DORA, NIS2 and ISO 27001 — the kind boards, auditors, regulators and customers actually ask for.
Boards, auditors, regulators and enterprise customers no longer accept a policy binder as evidence of resilience. They want to see it demonstrated — and most security teams are too stretched to build that proof themselves.
DORA, NIS2, the Cyber Resilience Act, the Cyber Solidarity Act and the EU's 2026 AI & Cybersecurity Action Plan now overlap — each expecting evidence of resilience, not just written policy.
Independent 2026 benchmarking found the large majority of organisations treat cybersecurity as a top priority, yet more than half run with one or fewer dedicated security staff.
Security and compliance leads report audit preparation as their single biggest challenge, often losing a full day a week to manual evidence gathering that a focused sprint can replace.
Every deliverable is built to be handed straight to your board, your auditor or your biggest customer's security questionnaire.
A single, plain-English view of critical services, current risk posture and open actions — built for a 10-minute board update.
Your critical business services traced through to the systems, data and third parties they actually depend on.
Recovery targets tested against reality, with documented ransomware recovery testing evidence — not assumed, verified.
Your critical suppliers and vendors assessed for concentration risk, contractual coverage and resilience posture.
Every control mapped and cross-referenced to DORA, NIS2 and ISO 27001 clauses, ready to hand to an assessor or auditor.
Updated risk register entries plus a short list of control-owner actions — so the pack drives real remediation, not just a report.
Designed to fit inside a busy security team's week — most of the heavy lifting happens off your desk.
A short call to confirm which framework(s) matter most right now, what evidence already exists, and what's driving the deadline.
A focused working session to map critical services, dependencies, recovery targets, controls and key third parties.
Your board dashboard, auditor evidence pack, risk register updates and control-owner actions, delivered and walked through live.
Founder, Whalper Resilience
CISSP-certified security leader with a practitioner background as Field CISO and Account CISO for Vodafone, Sky and BT. Published author on AI & cybersecurity, GTIA Cybersecurity Leadership Award winner, and regular speaker at InfoSecurity Europe and Hannover Messe.
Every evidence pack is built personally — drawing on years spent advising Tier-1 telcos and enterprise security teams on resilience, ransomware recovery and risk governance, translated into language boards and auditors already trust.
Bylines in The Hacker News, Bleeping Computer and a SANS Institute whitepaper on resilience and recovery, plus hands-on experience closing multi-million-pound security investment cases with Tier-1 telco boards.
A single, clearly-scoped engagement — no subscriptions, no lengthy procurement process.
Yes. Most customer security questionnaires and board risk reports already expect the same evidence these frameworks require. Building it now means you're ready before the obligation lands, not scrambling after.
No. The evidence pack is designed to sit on top of whatever you already use — spreadsheets, Notion, or a GRC platform — and turn it into something board- and auditor-ready.
Subu Rao leads every engagement personally. This isn't handed off to a junior analyst or a template generator.
Nothing formal. Existing policies, a supplier list and any past incident or recovery test notes are useful, but the workshop is designed to work even if none of that is organised yet.
The first sprint is scoped to one critical business service or unit so it stays fast and sharp. Additional units or an ongoing retainer can follow once you've seen the first pack.
30 minutes, no obligation. We'll confirm which framework matters most right now and whether a sprint is the right fit.
Already booked your call? Complete the pre-work questionnaire so we can go straight into the detail.