Implementing
risk management across your organization

Consolidate your entire risk management process into a single, unified platform aligned with a Risk-Based Approach. Ready to begin?

  • Step 1: Choose the product that fits your needs.
  • Step 2: Leverage expert consultancy or follow our structured implementation roadmap.

Implement RIG DORA & NIS2 in your organization

Regardless of which product you choose, you can implement the RED INTO GREEN system on your own or use our implementation service.

If you choose to implement the system yourself, you’ll receive support in the form of regular training sessions, user guides, and meetings with a support specialist who will address any questions you may have and provide instructions on how to use the tool.
If you choose the RIG system implementation service, a consultant will guide you through the implementation project and, at the end, train your team on how to use the RIG system.

Preparing your organization for a DORA or NIS2 compliance audit using the RIG tool takes 3 to 6 months. It depends mainly on the availability of information within the organization, rather than on the method of tool implementation.

Expert-led industry implementation

The implementation with a consultant is led by someone with experience in risk management who has previously worked with clients in the financial sector. Once you gain access to the system—just as with a self-guided implementation—you’ll receive instructions for the tool and can access recordings of the entire training series on RIG and risk management.

You are not required to spend time working with the consultant. Instead, you will be asked to provide information about supporting assets, processes, and security measures necessary to begin working in the application. The consultant will perform most of the steps for you and then train your team.

Introductory training

The consultant conducts an introductory training for the Client’s team – so that all project participants understand its purpose, the scope of work, and the initial involvement; in particular, it will include a discussion of the scope of the DORA or NIS2 regulations in the context of the project being carried out.

Audit

As part of the audit, the consultant will identify information needs, clarify ambiguities, interview the designated team members, review the documentation, correspondence or supplier interviews made available. At the appropriate stages of the project, the consultant will ensure consultation with the client on the final conclusions and recommendations, and will take into account the suggestions provided by the client.

In cooperation with the client, the consultant will prepare recommendations for the risk treatment plan regarding possible mitigations of the most significant identified risks.

The deliverable of the audit will be recommendations.

List of post-audit recommendations for the organization

List of post-audit recommendations for the organization in connection with the implementation of DORA or NIS2 (e.g. which requirements the organization must still fulfil, which recurring obligations should be carried out in accordance with DORA or NIS2, what are the recommendations regarding the necessary human resources and competencies, processes or functions within the organization).

Organization description

The consultant will gather information about your organization in the RED INTO GREEN application. They will prepare a register of suppliers in accordance with the supplier questionnaires and the ICT risk assessment, which they will carry out in the application. The consultant will coordinate the process of collecting information from suppliers.

The deliverables of this stage will be the following information sources prepared in the application:

Map of processes and assets

The consultant maps the organization’s processes using the available sources of information about them within the organization. These may be: the record of processing activities, the website, or lists of supporting IT assets (infrastructure, systems, tools).

The consultant assigns supporting assets and products/services (delivered to the organization’s clients/stakeholders) to individual processes, indicating their mutual criticality.

List with security control categories

The consultant conducts an interview with IT and identifies the security controls and vulnerabilities of the supporting assets they manage. If you have a vulnerability management tool, e.g. Tenable, the consultant will integrate the tools, which will help to accelerate and add detail to this stage of the implementation.

RED INTO GREEN usage training

The consultant provides training on risk management automation in the RIG DORA application. They generate risk assessment results and, together with the team, prepare risk treatment plans. They also support the preparation of a presentation for the management board.

Self-guided subscription implementation

Self-implementation is managed by a designated member of your organization, who receives dedicated technical support throughout the duration of the software subscription. Upon gaining system access, this individual receives comprehensive onboarding instructions, two hours of initial consultation with a support specialist, and full access to our complete risk management training library.

As part of your subscription, you can participate in newly developed training sessions while maintaining access to all archived sessions. Our training program guides you through the entire risk management lifecycle—from defining your organization within the system to conducting assessments and ongoing management.

Logging into the application

Gain access to the application and assign permissions to authorized users.

Application Training

Receive seven hours of expert consultation and begin a series of recorded training sessions on the RIG tool.

Registry of processes

Collect information regarding organizational processes and complete the standardized process registry.

Mapping

Link threats, supporting assets, vulnerabilities, and safeguards. Integrate these data points with information on processes, products, and services.

Risk assessment

Execute automated risk assessments within the platform.

Risk management planning

Generate comprehensive risk management reports and strategic action plans.

Action plan implementation

Assign specific tasks arising from risk management plans to the relevant team members.

Supplier surveys

Distribute surveys to suppliers directly through the system.

Updating supplier contracts

Issue amendments to supplier contracts.

Maintaining records

Build a centralized document repository and maintain detailed records of supplier contracts. Manage the incident assessment log, evaluate events, and prepare serious incident reports for the supervisory authority.

Reporting

Develop a work plan for the defined period (annual or semi-annual), prepare final reports, and present findings to the management board.

Talk to us
Product

RIG DORA

Product

RIG NIS

Compliance roadmaps for DORA and NIS2

RIG DORA

Learn how to maintain compliance with DORA. The process involves risk analysis, an incident register, and a register of ICT supplier information.

RIG NIS

Learn how to implement NIS2 compliance. The process involves risk analysis, an incident register, and a registry of supply chain vendor information.

Regulatory compliance based on the RED INTO GREEN methodology

The risk assessment methodology, representing the Asset-Based Approach (the approach recommended by the EU) forms the foundation of the RIG risk analysis system.

Get a register of information requirements done!