Blom Risk Advisory helps organisations that depend on critical and operational technology get a grip on NIS2 compliance, OT security and risk management. Independent, practical and future-proof.
“A resilient organisation stays standing because even the risks in its deepest layers are known and controlled, precisely where they are hardest to find.”
Three connected services that move you from “having to comply” to “being in control”. The centre of gravity is operational technology; the IT environment is part of every engagement, because the two cannot be secured separately.
Regional and personal. Speaking from practice, close to the organisation.
Advice that holds up when it matters. Thoroughly grounded and future-proof.
The threat sits below the surface, in the operational foundation where the view of risk is not always obvious or complete.
Clear, honest judgements, with no entanglement with vendors, software or certification bodies. The client comes first.
A pragmatic, risk-driven approach that helps organisations meet NIS2 from the perspective of business continuity.
CAISSON stands for Compliance Assured In Scope, System, Organisation and Norm. Scope is the assessment of applicability across five legal frameworks. System is the OT design at zone and conduit level. Organisation is ownership and the governance cycle. Norm is the mapping to IEC 62443 and Cbw article 21.
NIS2 readiness & impact assessment. Critical processes tested against the NIS2 requirements and gaps identified.
Result: an impact and gap matrix.
Strategic blueprint & implementation roadmap. Gaps are prioritised by risk, impact and implementation effort.
Result: a NIS2 master plan approved by your organisation.
End-to-end implementation & OT security. Organisational and technical measures, with a focus on IT/OT integration.
Result: demonstrably in control.
Continuous resilience & supply-chain governance. Plan-Do-Check-Act, periodic audits and supply-chain monitoring.
Result: cybersecurity embedded in operations.
In the Scan, testing covers not only NIS2 but also the relevant Dutch legal framework: the Cyber Security Act (Cbw), the General Data Protection Regulation (GDPR/AVG) and the Critical Entities Resilience Act (Wwke). Where applicable, the Open Government Act (Woo) and the Archives Act are also included. The Archives Act 2026 replaces it on 1 January 2027.
Blom Risk Advisory is built on more than 25 years of experience at the intersection of engineering and information technology, 15 of them abroad at large multinationals with complex technical environments and corporate-cultural challenges. As a co-developer of the thinking around the convergence of cybersecurity and operational technology (OT), Casper Blom helped shape a discipline that now sits at the heart of NIS2.
At several international operators he built and led OT security teams, carried significant budget responsibility and contributed to the then-new IEC 62443 standard. He co-authored control framework standards for OT security and consistently turned strategic vision into executable programmes, from the drawing board to remote, unmanned operations.
He pairs that depth with what clients value most: explaining complex matters simply, switching effortlessly between the boardroom and delivery teams, and bringing people along and making them stronger. Independent, approachable and accountable for the direction he sets.
A green crown, branches and ground line as the visible, resilient organisation and a controlled perimeter. Red roots and a red trunk that break through the ground line, signalling potentially invisible danger.
Exactly the thesis of a GRC practice focused on operational technology (OT): the threat is not visible above the surface, but out of sight in the roots: in the foundation and the physical infrastructure below the ground line.
Governance is the structure, shown as trunk and branching.
Risk is the red core.
Compliance and resilience are the enduring green form that proves it is under control.
The ground line is the scope: the boundary between what is visible and what lies beneath, and therefore the first question in every engagement.
Schedule a no-obligation introduction. Your situation is discussed, along with where the biggest gains are.
info@blomriskadvisory.nl