NIS2 and ISO 27001 — without panic, with a clear plan
I help management understand what actually needs to be done, where to start, and what to show a client, auditor or regulator. Practical, not theoretical — from self-check to a working system.
When cybersecurity becomes a management responsibility
Practical support for organisations that need more than technical controls: responsibilities, decisions, documentation and evidence for clients, auditors or management.
Decision clarity
What must be decided, who owns the risk and what can be shown to clients, auditors or regulators?
Evidence for clients
When clients ask for NIS2, ISO 27001 or security control evidence, organisations need structured proof, not vague assurances.
ISO 27001 direction
Understand whether ISO 27001 is needed now, what the scope might be and what resources would be required.
A working system
Documentation, risk management, suppliers, incidents and management reviews need to work in day-to-day operations.
Documents are necessary. Governance creates readiness.
The gap is rarely only missing documentation. The real issue is often unclear cyber governance: decisions, responsibilities, evidence and operational reality are not connected.
Unclear ownership
Who makes decisions about risk, incidents, suppliers, access and continuity?
Weak evidence readiness
Documents may exist, but the organisation cannot clearly show how cyber risk is governed.
NIS2 or ISO seen too narrowly
A regulatory or certification issue becomes an IT task, while the real need is a management system.
Start with a short readiness self-check
The assessment helps identify whether responsibilities, evidence, incident escalation, supplier risk and management decisions are clear enough for NIS2-related expectations or client security questionnaires.
5 questions, under 2 minutes, with an instant result showing which readiness stage you are in. If you want a deeper picture, you can continue to the full assessment.
NIS2 readiness, evidence and ISO 27001 implementation support
The scope is selected based on the organisation’s situation: from initial NIS2 readiness assessment to full ISO 27001 implementation support before certification audits. If you are still unsure whether you need NIS2 or ISO 27001, start with a short explanation — then it is clear what to ask for.
NIS2 readiness assessment
Assessment of responsibilities, documentation, incident governance, supplier risk, business continuity, management involvement and evidence readiness.
Governance documents and evidence
Practical support with NIS2-related documents, responsibilities, risk management logic, incident escalation and supplier risk governance.
ISO 27001 consulting and implementation
Support with ISO/IEC 27001 business case, ISMS structure, documentation, responsibilities, risk management and readiness for certification audits.
Supplier questionnaires
Support in preparing a clear structure of answers and evidence when clients request NIS2, ISO 27001 or cybersecurity control information.
Three practical paths
Not every organisation needs a full implementation project immediately. The right first step is to choose the path based on business need, maturity and available internal resources.
Business Case & Roadmap
A management decision document: realistic scope, priorities, implementation options, 3-year cost logic and potential business value.
Methodological supervision
Your internal team leads the project, while I provide direction, reviews and feedback on risk assessment, SoA, policies and audit readiness.
Full certification readiness support
ISO 27001 implementation support from ISMS scope, risk assessment and SoA to readiness for Stage 1 and Stage 2 certification audits.
I help organisations practically prepare for ISO/IEC 27001:2022 certification audits: ISMS structure, risk management, documentation, responsibilities, evidence and management readiness. Not sure whether you need ISO 27001 or NIS2? Comparison here →
Your people already use AI. The question is whether you govern it.
ChatGPT, Copilot and other tools are already running inside your organisation — often without rules or visibility. When a client or regulator asks how you manage AI risk, words won't be enough. You'll need to show it. ISO/IEC 42001 is the first international AI management standard — the same evidence logic as ISO 27001, now applied to artificial intelligence.
AI governance gap analysis
Where your organisation stands today: which AI tools are in use, what data moves through them, and what's missing against the standard.
Building the AI management system
Policies, controls, accountability and risk management for AI use — practical, without bureaucracy, sized for SMEs.
Certification readiness
I prepare your AI management system so you pass the audit with something to show — a working system, not paperwork on a shelf.
In 2 minutes, check whether your organisation governs AI use — or just hopes it's fine.
From situation assessment to a clear implementation path
The process is focused on management clarity, practical decisions and usable evidence — not documentation for its own sake.
Cybersecurity governance support for management
My work helps management treat cybersecurity as a question of governance, accountability and business continuity.
Practice
- Ongoing NIS2 compliance implementation projects in the manufacturing sector
- Security assessment of an IT services company against an aviation sector client's 28-question security questionnaire — gap analysis, plan and implementation instructions
- Delivered cyber resilience training for a tourism sector company
- Cyber resilience training for a non-profit organisation (pro bono)
Darius Jasiulionis
ISO 27001:2022 Lead Implementer providing consulting support on NIS2 readiness, cybersecurity governance, ISO 27001 implementation and certification audit readiness.
- ISO 27001:2022 Lead Implementer
- ISO/IEC 42001 (AI management system) Lead Implementer
- 600+ hours of cybersecurity training
- NKSC (National Cyber Security Centre) cybersecurity qualification
- Services provided by UAB StarPrus
Need to assess NIS2 or ISO 27001 readiness?
If you are still considering — start with a quick 2-minute check to see where you stand. If you already know the situation – send me an email, and I will suggest a rational first step.
Cyber governance · NIS2 readiness assessment · ISO 27001 consulting · ISO 27001 implementation · documentation · client evidence