Risk Services

Risk management, privacy and supplier security as an integral part of governance. Berigo helps boards and executives understand, prioritise and manage risk, grounded in ISO 27001, the GDPR and NIS2.

Risk cannot be eliminated, but it can be understood, prioritised and managed. Berigo's risk services help organisations treat risk as an integral part of governance rather than a side project. We work at the intersection of risk management, privacy and supplier security, grounded in frameworks such as ISO 27001, the GDPR and NIS2.

Our starting point is simple: sound risk decisions require a sound basis for decision-making. Executives and boards should know which risks the organisation actually faces, what is acceptable, and where effort delivers the greatest effect. Documentation should support those decisions, not conceal weaknesses.

Our risk services

Risk management

We establish and improve methodology for risk assessment, risk acceptance and follow-up of measures, and integrate it into the organisation's management system. The result is a risk picture that can be used to prioritise, not merely to document.

Privacy and DPO as a service

For organisations required to appoint a data protection officer under the GDPR, or that want a professional privacy function without hiring in-house, Berigo provides an independent DPO in line with GDPR Articles 37 to 39. The service includes a gap analysis, a record of processing activities, support in the event of data breaches, and regular reporting to management and the board.

Supplier security

An increasing share of risk sits outside your own organisation. We help you map and assess critical suppliers, set the right security requirements in contracts, and follow up third-party risk over time, in line with the supply chain security requirements of NIS2.

What we deliver

  • Risk assessment and risk acceptance methodology, adapted to the organisation's size and maturity
  • Risk assessments with a prioritised list of measures
  • An independent data protection officer (DPO) and ongoing GDPR advisory
  • Mapping of processing activities, data processing agreements and third-party risk
  • Assessment and follow-up of critical suppliers, including security requirements in contracts
  • Regular reporting to management and the board on the risk picture, deviations and recommended measures

Who it is for

These services are particularly relevant for organisations within the scope of NIS2 or the GDPR, and for those without a dedicated risk or privacy function, or that want independent reinforcement of the one they have. We work with executive teams, boards and specialist functions, and tailor delivery to each organisation's situation.

How an engagement starts

An engagement typically begins with an initial conversation about your situation and needs, followed by a gap analysis against the relevant requirements. The outcome is a prioritised list of measures with a risk and maturity assessment, forming the basis for the way forward, either as a defined project or as an ongoing service with regular reporting.

Proven Executive Outcomes

M&A

Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.

NIS2

Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.

Is your Board ready for NIS2?

Download the 2026 Executive Checklist for Cyber Liability.

Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.