Independent information security advisory

Audit, advise, awaken.

We help mid-market organisations across Central and Western Europe meet their security obligations — ISO 27001, NIS2, DORA, GDPR — without losing focus on the people who actually live inside the controls.

Discuss your situation Read our services

10 yrEstablished in 2016
120+Audits delivered
7European jurisdictions served
ISO 27001Certified ourselves

What we do

Our advisory services

Four advisory practices. Each engagement is scoped individually; please get in touch to discuss your specific context.

Security risk assessment

Structured ISO 27005-aligned assessments scoped to your actual business. We produce risk registers your board can read, not artefacts for the archive.

Learn more →

NIS2 and DORA advisory

Practical translation of NIS2 and DORA obligations into a workplan your security team can actually execute, with measurable acceptance criteria.

Learn more →

“Ellipse Project delivered a NIS2 readiness review that finally produced a workplan our security team could actually execute, rather than a 200-page document destined for a shared drive.”

— Head of Information Security, European energy utility, ~3,500 employees

Selected work

Retail banking, ~4,500 employees

DORA readiness for a regional retail bank

Eighteen-month DORA readiness programme covering operational-resilience testing, incident reporting, third-party risk, and ICT supplier oversight.

All case studies →

From the Insights

All posts →

Working with Ellipse Project

Most of our engagements start with a short conversation — 45 minutes with one of our partners covering your situation, our honest view of fit, and what a structured engagement would look like. We follow up with a written proposal or, where we are not the right partner, a referral to a firm that fits better.

Get in touch