Your risk framework should survive an incident, not only an audit.
Independent risk and resilience advisory for regulated institutions and critical operators. Zurich.
Zurich, since 2023. Europe and the Middle East.
Who we work with
By obligation
- FINMA supervised banks and asset managers
- Firms in scope of DORA
- Energy and utilities under NIS2 and CER
- Multi-site manufacturers
- Consumer goods groups
What we have delivered
0 capability areas, from operational risk to third-party risk and business continuity
Multi-year relationships in Swiss and Liechtenstein private banking.
The obligation differs by sector. The underlying work does not. Sectors
Your risk taxonomy did not come from your organisation. It came from a vendor’s data model.
We are platform independent, not a reseller.
Most of this work comes down to your minimum viable company: the smallest version still delivering its core purpose in a disruption.
Selected engagements
Swiss private banking and asset management group
Financial services
Liechtenstein-headquartered private banking and asset management group
Financial services
Major Swiss cantonal bank
Financial services
Questions we get asked
- How detailed should a business impact analysis be?
- What should a risk taxonomy look like when it is not only about IT?
- How do you build one control library that answers several regulations at once?
- Should a business impact analysis be scoped at business service or business process level?

