Cyber Security
We help you secure what the business cannot do without, and document it afterwards. Without theatre, and without making the work so awkward that somebody finds a way around it.
Contact usSecurity that holds up in practice
Defence has to be built by people who understand attack
An attack rarely unfolds the way the risk matrix suggests. It starts with a valid credential, an overlooked integration, or a supplier with more access than anyone remembered. We therefore assess the environment the way an attacker would: what can be reached, what it can be used for, and where it hurts.
Controls that make work awkward get bypassed, and a bypassed control is worse than none, because it provides false assurance. We choose the controls that hold up day to day and rank them by effect: access control, segmentation, logging, and a response capability rehearsed before it is needed.
NIS2 and ISO 27001 essentially describe good practice. Documentation should be a by-product of things being in order, not a parallel production of paper. We build the substance first and let compliance follow from it. That is both cheaper and more truthful.
Where the field is moving
Attackers log in, they do not break in
Most successful attacks today begin with a valid access: a phished password, a stolen session, an MFA prompt approved out of fatigue. The perimeter is no longer the network. It is the account, and it travels home with the employee, to the hotel and into the phone.
The defence follows. Phishing-resistant methods such as passkeys replace codes that can be fished. Conditional access judges not only who, but from where, on which device and in what context. And legacy protocols that cannot be protected are closed rather than exempted.
The least glamorous work still yields the most: knowing who has access to what, revoking it the day employment ends, and administrative rights that are few, personal and logged. It is not advanced. It is simply done or not done.
Ransomware has become a business with customer service
Modern extortion does not encrypt first. It steals first, at leisure, and negotiates afterwards with documentation of what was taken. Backup saves the operation but not the confidentiality, which is why an incident today is as much a leadership and communications task as a technical one.
What gets hit is decided by segmentation and permissions long before the attack. A flat network with broad access turns a single phished account into a catastrophe. A segmented environment with narrow permissions turns it into an incident that can be contained and closed.
The response must be rehearsed while it is free. Who decides to shut systems down, who speaks to authorities, customers and press, and where does the plan live when the file share is down. A plan never exercised is an assumption about how it will go, and assumptions perform poorly at three in the morning.
NIS2 has moved from deadline to supervision
NIS2 is in force as national law and supervisory practice is taking shape. That changes the tone: from when must we be ready to what can we show today. Management must approve the risk work and can be held personally accountable, and that detail has moved security from the IT budget to the board agenda.
The supply chain is included, and it shows. Large customers push questionnaires and requirements downwards, and smaller companies discover that their security posture has become a sales condition. Documented order is becoming a competitive parameter, not just a cost.
Our approach is unchanged by the rules taking up more space: build the substance properly and let documentation be a by-product. A rehearsed response, logs that are actually read and access that is governed will pass both an inspection and an attack. Paper alone passes only the first.
Four steps, from starting point to operations
Security is not settled in a policy, but on the day something goes wrong. We build what you have to be able to stand behind.

Niels Reinau
Niels founded iCEO after a career spent at IBM, at eBay, and running platforms at DanDomain and Zitcom, two of the largest hosting companies in Denmark. Zitcom is today team.blue Denmark, and DanDomain is one of the brands it still trades under. He works alongside consultants who have been in this industry for twenty-five years. You get that experience directly, not a partner at the pitch and a graduate on the work.