Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.
Risk Services
Risk management, privacy and supplier security as an integral part of governance. Berigo helps boards and executives understand, prioritise and manage risk, grounded in ISO 27001, the GDPR and NIS2.
Risk cannot be eliminated, but it can be understood, prioritised and managed. Berigo's risk services help organisations treat risk as an integral part of governance rather than a side project. We work at the intersection of risk management, privacy and supplier security, grounded in frameworks such as ISO 27001, the GDPR and NIS2.
Our starting point is simple: sound risk decisions require a sound basis for decision-making. Executives and boards should know which risks the organisation actually faces, what is acceptable, and where effort delivers the greatest effect. Documentation should support those decisions, not conceal weaknesses.
Our risk services
Risk management
We establish and improve methodology for risk assessment, risk acceptance and follow-up of measures, and integrate it into the organisation's management system. The result is a risk picture that can be used to prioritise, not merely to document.
Privacy and DPO as a service
For organisations required to appoint a data protection officer under the GDPR, or that want a professional privacy function without hiring in-house, Berigo provides an independent DPO in line with GDPR Articles 37 to 39. The service includes a gap analysis, a record of processing activities, support in the event of data breaches, and regular reporting to management and the board.
Supplier security
An increasing share of risk sits outside your own organisation. We help you map and assess critical suppliers, set the right security requirements in contracts, and follow up third-party risk over time, in line with the supply chain security requirements of NIS2.
What we deliver
- Risk assessment and risk acceptance methodology, adapted to the organisation's size and maturity
- Risk assessments with a prioritised list of measures
- An independent data protection officer (DPO) and ongoing GDPR advisory
- Mapping of processing activities, data processing agreements and third-party risk
- Assessment and follow-up of critical suppliers, including security requirements in contracts
- Regular reporting to management and the board on the risk picture, deviations and recommended measures
Who it is for
These services are particularly relevant for organisations within the scope of NIS2 or the GDPR, and for those without a dedicated risk or privacy function, or that want independent reinforcement of the one they have. We work with executive teams, boards and specialist functions, and tailor delivery to each organisation's situation.
How an engagement starts
An engagement typically begins with an initial conversation about your situation and needs, followed by a gap analysis against the relevant requirements. The outcome is a prioritised list of measures with a risk and maturity assessment, forming the basis for the way forward, either as a defined project or as an ongoing service with regular reporting.
In this area
DPO as a Service
Berigo offers DPO as a Service, an independent data protection officer function that meets the requirements of GDPR Articles 37 to 39, without the need to hire in-house.
Risk Management
Digital risk is business risk. Berigo helps organisations integrate digital risk into enterprise risk management, with risk assessments that support decisions and maturity development that lasts.
Supplier and Third-Party Security
Your supply chain is part of your risk picture. Berigo helps you map, assess and follow up on suppliers and data processors in line with NIS2, the GDPR and ISO 27001.
Proven Executive Outcomes
Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.
Is your Board ready for NIS2?
Download the 2026 Executive Checklist for Cyber Liability.
Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.