Tredit Support portal Get in touch

Home / Services / IT Governance

IT governance and compliance

Governed, documented, audit-ready IT.

We help make sure your IT doesn’t just work, but also complies with NIS2, ISO 27001 and GDPR, and evolves along a well-thought-out IT strategy.

At a glance

  • NIS2 readinessunder Hungary’s Cybersecurity Act
  • ISO/IEC 27001information security management system
  • GDPRtechnical and organisational measures
  • vCIOIT leadership as a service

What we do

From policies to implementation, from one partner.

Most consultants stop at the paperwork. With us, the same team that writes the policies also implements the technical measures, so what’s on paper matches reality.

NIS2 and cybersecurity compliance

We assess whether you’re in scope, classify your systems, carry out a gap analysis, draw up an action plan and prepare your company for the mandatory cybersecurity audit.

  • Scope assessment
  • Security classification
  • Audit preparation

Risk assessment and policies

Risk assessment and the policies you need, tailored to how your company actually works, with no boilerplate.

  • IT security policy
  • Access, backup and device policies
  • Business continuity plan (BCP/DRP)

ISO/IEC 27001

Support in building an information security management system (ISMS) according to the 2022 version of the standard, and preparation for the certification audit.

  • Building the ISMS
  • Implementing controls
  • Certification readiness

GDPR and data protection

The IT side of data protection compliance: access control, logging, encryption and a process for handling personal data breaches.

  • Technical and organisational measures
  • Access management and logging
  • Incident handling process

IT strategy and vCIO

A virtual CIO who represents IT at management level without a full-time hire: budget, roadmap, vendors and reporting.

  • IT budget and development roadmap
  • Vendor and contract management
  • Decision support for management

NIS2 in brief

Cybersecurity is now a legal obligation.

The law

In Hungary, the NIS2 Directive is transposed by Act LXIX of 2024 on the Cybersecurity of Hungary. Companies are supervised by the Supervisory Authority for Regulated Activities (SZTFH).

Who is in scope?

Medium-sized and large companies in specific sectors, such as energy, transport, healthcare, digital infrastructure and certain areas of manufacturing, including motor vehicle manufacturing.

Audit

Organisations in scope must undergo a cybersecurity audit. For organisations operating before 2025, the first audit deadline was 30 June 2026, and compliance must be maintained on an ongoing basis.

As a supplier

Companies covered by NIS2 expect security measures from their suppliers too, so smaller companies can be affected indirectly.

Technologies

What we work with.

Legislation

  • NIS2 Directive
  • Act LXIX of 2024 (Hungary)
  • GDPR

Standards

  • ISO/IEC 27001:2022
  • ISO/IEC 27002

Documents

  • IT security policy
  • Risk assessment
  • BCP/DRP
  • Action plan

Process

How we get you to compliance.

Current state

Scope, existing systems, policies and practices.

Gap analysis

Risk assessment and comparison against the requirements.

Action plan

Priorities, owners, deadlines and costs.

Implementation

Policies, plus technical measures delivered by our own team.

Audit and follow-up

Audit preparation, then regular reviews.

FAQ

Questions our clients often ask.

Is our company in scope for NIS2?

It depends on your sector and company size. We start with a scope assessment. Even if you’re not directly in scope, you may receive security requirements from your clients as a supplier.

What’s the difference between NIS2 and ISO 27001?

NIS2 is a legal obligation for organisations in scope, while ISO 27001 is a voluntary international standard. Many requirements overlap, so a well-built ISMS is a strong foundation for NIS2 compliance.

Do you carry out the cybersecurity audit?

No. The mandatory audit is performed by an independent auditor registered with SZTFH. We help with preparation and with closing any gaps.

What is a vCIO?

A virtual CIO: an experienced professional who handles IT leadership tasks within an agreed time budget, without a full-time hire.

Related services

Network & Perimeter Security

Firewalls, remote access, LAN/WAN

Microsoft Cloud

Microsoft 365, Entra ID, Intune, Azure

Server Operations

Windows Server, Hyper-V, VMware, Linux

Contact

Let’s talk about your IT.

Call us, or send us a short note about how many employees and which systems need support. We’ll assess your current setup and prepare a tailored proposal.

Registered office
2340 Kiskunlacháza, Dobó István utca 23.Tax number: 24076735-2-13
Support
Support portalFor contracted clients