STRIDE threat modelling, code-level vulnerability assessment, and review of your existing security design. We find what automated scanners miss.
Nordic Sec is a Swedish security & compliance consultancy. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and EU Cyber Resilience Act certification — treating compliance as real engineering, not policy PDFs.
Six practices, one team. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and EU Cyber Resilience Act certification — building the evidence and secure-by-design practice that stands up to a real auditor, not a policy template.
STRIDE threat modelling, code-level vulnerability assessment, and review of your existing security design. We find what automated scanners miss.
System design assessment, trust-boundary and infrastructure review, reliability analysis. Honest evaluation of technical debt and security risk.
Readiness assessment, control design, and an automated evidence pipeline that carries you through the Type II observation window and the auditor's fieldwork.
End-to-end ISMS build against the 2022 Annex A controls — risk register, policies, and Statement of Applicability — through Stage 1 and Stage 2 certification.
EU CRA readiness for products with digital elements: security-by-design, SBOM, coordinated vulnerability handling, and conformity documentation ahead of the 2027 deadline.
Bake security into how your team ships: threat modelling, SAST/DAST and dependency gates in CI, secure code review, and supply-chain controls that satisfy your framework.
Every engagement follows the same rhythm: understand what's being defended, reproduce findings before reporting them, deliver something engineers can act on, and close the loop.
We start with what you're actually defending — assets, adversaries, tolerances. The engagement is shaped to your risk, not a template.
Every finding is exploitable, reproducible, and validated before it reaches you. No speculative CVEs, no cosmetic noise.
Reports ship with proof-of-concept, reproduction steps, and concrete remediation — plus an exec summary that doesn't hide the detail.
Findings aren't closed until the fix is verified against the original proof of concept. Free re-test within 60 days of delivery.
Security audit, architecture review, or threat model with a set scope, timeline, and deliverable. Clear price, no surprises.
We join your team — building the ISMS, running the control programme, and mentoring engineers on secure practice. Monthly retainer, flexible scope.
On-demand access for architecture decisions, incident response guidance, and review of critical changes. Lightweight and high-signal.
Led the end-to-end security and compliance programme for a startup beginning with no formal security posture. Designed the control framework, authored the policies, built the automated evidence pipeline, and walked the team through Stage 1 and Stage 2 ISO audits and the SOC 2 Type II observation window — reaching both certifications inside nine months, with zero major non-conformities.
20+ years building and securing software systems. A deep engineering background — systems programming, distributed systems, and infrastructure — now focused on security audits and compliance engineering across fintech, SaaS, Web3, and enterprise.
CISSP certified. Led a company from no formal security posture to SOC 2 Type II and ISO 27001:2022 in nine months. Fluent in the 2022 Annex A controls, the EU Cyber Resilience Act, GDPR, and NIST frameworks — and able to read the code the controls are meant to protect.
Based in Sweden. Working with clients across Europe — remote-first, timezone-flexible.
Security audit, SOC 2 / ISO 27001 readiness, or CRA compliance — we're ready when you are. Most engagements start with a 30-minute scoping call.