Frameworks & regulation

Scaffolding,
not the goal.

We work fluently across the frameworks your organisation is measured against, and help you keep the actual risk in view.

Strategy, risk and compliance resting on one shared control base

Frameworks are useful. They give structure to a messy subject, a shared vocabulary, and a way to demonstrate to outsiders that you take security seriously.

A certificate proves that a system was in place on the day of the audit, not that your organisation is secure, and not that you are protecting the things that matter most. We have seen certified organisations with serious blind spots and uncertified ones in genuinely good shape.

Use the framework as scaffolding, not as the goal. Infinity Security helps you meet the standards you are held to, while keeping the actual risk in view.

What we work with

ISO 27001

The general baseline for an information security management system, and the framework most organisations are eventually asked about by customers. We help boards understand what certification does and does not tell them, and where scope decisions quietly limit its value.

NEN 7510

The Dutch standard for information security in healthcare, building on ISO 27001 with requirements specific to patient data. Relevant to care providers and to the growing number of suppliers who process health data on their behalf.

NIS2 and the Cyberbeveiligingswet

The European directive and its Dutch implementation, aimed at the resilience of essential and important entities. Notable for placing duties directly on management bodies rather than only on the organisation.

DORA

The EU regulation on digital operational resilience for the financial sector, in force since January 2025. Heavy on ICT third-party risk, testing and incident reporting, with real consequences for the contracts you hold with your providers.

NIST Cybersecurity Framework

Less a compliance obligation than a way of organising the conversation. We use it frequently to structure maturity assessments and to give boards a coherent picture across govern, identify, protect, detect, respond and recover.

BIO

Baseline Informatiebeveiliging Overheid: where public-sector obligations intersect with the security agenda, as they usually do.

GDPR / AVG

Where personal data protection intersects with the security agenda, as it usually does. The two programmes share evidence, owners and much of the same control base.

Other frameworks on request

Sector schemes, customer-imposed standards and group requirements from a parent company all shape what you must demonstrate. We work with what applies to you.

ISO 27001
NIS2 / Cbw
DORA
GDPR/AVG

One control base

Mapping, not stacking

One control base, several obligations satisfied

Most organisations sit under several of these at once and run each as its own programme, which is expensive and demoralising. We map the overlap into one set of controls and one body of evidence, so board attention goes to what is genuinely different, not the same work repeated under three names.

Let's talk.

Thirty minutes is usually enough to work out whether we can help.

Book an introduction