We are consultants first. Year after year of assessments and audits, every engagement ended the same way: a deliverable the client could not maintain. The register lived in a spreadsheet, the evidence lived in a mailbox, and eighteen months later the next auditor started from zero.
We built SynapseRM to close that gap on our own engagements. It derives requirements from the framework the client is actually audited against, produces scored risks our analysts review rather than retype, and keeps the trail intact between audits. It worked well enough on our own work that clients started asking for access to it directly. That is the whole story: there was no product roadmap, there was a problem we kept hitting.
This matters for one reason. When you tell us your scoring scale is unusual, or your regulator asks for something odd, we have probably had the same argument on our own engagements.
Every module in SynapseRM reflects how an assessment actually runs. The people who design the platform are the people who use it on client engagements the following week.
Scales, frameworks, fields and workflows are configured to the methodology you are audited against, not to a scoring model we prefer.
Everything we deliver is built to survive an audit: named owners, dated decisions, traceable changes.
Brussels-based, delivering across three regions. We are honest about how this works: we are a Brussels team, not a global firm with offices in every capital. In practice:
NIS2 essential and important entities, DORA-scoped financial entities, and organisations building an ISO 27001 programme, from critical-infrastructure operators to SMEs. On-site delivery across the Benelux and France; remote elsewhere in the EU. Working languages: English and French.
NESA / UAE Information Assurance supported alongside ISO 27001 and NIST, which most regional programmes map back to. Delivery is remote, with on-site phases for assessments and workshops.
Banks, telecoms and regulated operators building their first structured risk and third-party practice. French-language delivery covers the Maghreb and francophone West Africa; English elsewhere.
Where NIS2, DORA and ISO 27001 actually put your register.
What continuous supplier oversight looks like in practice.
Asset criticality with your own level definitions.
In a 45-minute working session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.