Governance · Risk · Compliance
Resilience begins at the roots

Resilience that is anchored and rooted in your organisation.

Blom Risk Advisory helps organisations that depend on critical and operational technology get a grip on NIS2 compliance, OT security and risk management. Independent, practical and future-proof.

“A resilient organisation stays standing because even the risks in its deepest layers are known and controlled, precisely where they are hardest to find.”

The brand idea behind Blom Risk Advisory

Services

From legal obligation to manageable resilience

Three connected services that move you from “having to comply” to “being in control”. The centre of gravity is operational technology; the IT environment is part of every engagement, because the two cannot be secured separately.


Core values

What Blom Risk Advisory stands for

Rooted

Regional and personal. Speaking from practice, close to the organisation.

Resilient

Advice that holds up when it matters. Thoroughly grounded and future-proof.

Sharp on risk

The threat sits below the surface, in the operational foundation where the view of risk is not always obvious or complete.

Independent

Clear, honest judgements, with no entanglement with vendors, software or certification bodies. The client comes first.


Approach

CAISSON\u2122: the four-phase model for NIS2 compliance

A pragmatic, risk-driven approach that helps organisations meet NIS2 from the perspective of business continuity.

CAISSON stands for Compliance Assured In Scope, System, Organisation and Norm. Scope is the assessment of applicability across five legal frameworks. System is the OT design at zone and conduit level. Organisation is ownership and the governance cycle. Norm is the mapping to IEC 62443 and Cbw article 21.

The methodCAISSON: from statute to zoneFour phases in context, an assessment framework across five acts, and what each phase delivers.View the method
Phase 101

The Scan

NIS2 readiness & impact assessment. Critical processes tested against the NIS2 requirements and gaps identified.

Result: an impact and gap matrix.

Phase 202

The Blueprint

Strategic blueprint & implementation roadmap. Gaps are prioritised by risk, impact and implementation effort.

Result: a NIS2 master plan approved by your organisation.

Phase 303

The Implementation

End-to-end implementation & OT security. Organisational and technical measures, with a focus on IT/OT integration.

Result: demonstrably in control.

Phase 404

Ongoing management

Continuous resilience & supply-chain governance. Plan-Do-Check-Act, periodic audits and supply-chain monitoring.

Result: cybersecurity embedded in operations.

Assessment framework

In the Scan, testing covers not only NIS2 but also the relevant Dutch legal framework: the Cyber Security Act (Cbw), the General Data Protection Regulation (GDPR/AVG) and the Critical Entities Resilience Act (Wwke). Where applicable, the Open Government Act (Woo) and the Archives Act are also included. The Archives Act 2026 replaces it on 1 January 2027.

Casper A. Blom, oprichter van Blom Risk Advisory
Casper A. Blom Founder & advisor · Blom Risk Advisory

The founder

Casper Blom: 25 years at the intersection of OT and security

Blom Risk Advisory is built on more than 25 years of experience at the intersection of engineering and information technology, 15 of them abroad at large multinationals with complex technical environments and corporate-cultural challenges. As a co-developer of the thinking around the convergence of cybersecurity and operational technology (OT), Casper Blom helped shape a discipline that now sits at the heart of NIS2.

At several international operators he built and led OT security teams, carried significant budget responsibility and contributed to the then-new IEC 62443 standard. He co-authored control framework standards for OT security and consistently turned strategic vision into executable programmes, from the drawing board to remote, unmanned operations.

He pairs that depth with what clients value most: explaining complex matters simply, switching effortlessly between the boardroom and delivery teams, and bringing people along and making them stronger. Independent, approachable and accountable for the direction he sets.

  • 25+ years OT/IT security · 15 years international
  • Contributor to IEC 62443 and the original NIS directive
  • US DoD-trained OT Security Specialist
  • Educated at Delft University of Technology

About: the brand idea

The beech: a deeply rooted and resilient system

A green crown, branches and ground line as the visible, resilient organisation and a controlled perimeter. Red roots and a red trunk that break through the ground line, signalling potentially invisible danger.

Exactly the thesis of a GRC practice focused on operational technology (OT): the threat is not visible above the surface, but out of sight in the roots: in the foundation and the physical infrastructure below the ground line.

GRC in one image

Governance is the structure, shown as trunk and branching.

Risk is the red core.

Compliance and resilience are the enduring green form that proves it is under control.

The ground line is the scope: the boundary between what is visible and what lies beneath, and therefore the first question in every engagement.


Contact

Ready for NIS2 and a resilient OT environment?

Schedule a no-obligation introduction. Your situation is discussed, along with where the biggest gains are.

info@blomriskadvisory.nl
Send a message