STRIDE threat modelling, code-level vulnerability assessment, and review of your existing security design. We find what automated scanners miss.
Nordic Sec Group is a Swedish security & compliance consultancy. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and ISO/IEC 42001:2023 for AI — treating compliance as real engineering, not policy PDFs.
Six practices, one team. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and ISO/IEC 42001:2023 certification — building the evidence and secure-by-design practice that stands up to a real auditor, not a policy template.
STRIDE threat modelling, code-level vulnerability assessment, and review of your existing security design. We find what automated scanners miss.
System design assessment, trust-boundary and infrastructure review, reliability analysis. Honest evaluation of technical debt and security risk.
Readiness assessment, control design, and an automated evidence pipeline that carries you through the Type II observation window and the auditor's fieldwork.
End-to-end ISMS build against the 2022 Annex A controls — risk register, policies, and Statement of Applicability — through Stage 1 and Stage 2 certification.
Bake security into how your team ships: threat modelling, SAST/DAST and dependency gates in CI, secure code review, and supply-chain controls that satisfy your framework.
An AI management system built to the 42001 clauses and Annex A controls — AI policy, risk and impact assessment, and data and model governance — designed to extend your existing ISMS, through Stage 1 and Stage 2 certification.
Every engagement follows the same rhythm: understand what's being defended, reproduce findings before reporting them, deliver something engineers can act on, and close the loop.
We start with what you're actually defending — assets, adversaries, tolerances. The engagement is shaped to your risk, not a template.
Every finding is exploitable, reproducible, and validated before it reaches you. No speculative CVEs, no cosmetic noise.
Reports ship with proof-of-concept, reproduction steps, and concrete remediation — plus an exec summary that doesn't hide the detail.
Findings aren't closed until the fix is verified against the original proof of concept. Free re-test within 60 days of delivery.
Security audit, architecture review, or threat model with a set scope, timeline, and deliverable. Clear price, no surprises.
We join your team — building the ISMS, running the control programme, and mentoring engineers on secure practice. Monthly retainer, flexible scope.
On-demand access for architecture decisions, incident response guidance, and review of critical changes. Lightweight and high-signal.
Led the end-to-end security and compliance programme for a startup beginning with no formal security posture. Designed the control framework, authored the policies, built the automated evidence pipeline, and walked the team through Stage 1 and Stage 2 ISO audits and the SOC 2 Type II observation window — reaching both certifications inside nine months, with zero major non-conformities.
20+ years building and securing software systems. A deep engineering background — systems programming, distributed systems, and infrastructure — now focused on security audits and compliance engineering across fintech, SaaS, Web3, and enterprise.
CISSP certified. Led a company from no formal security posture to SOC 2 Type II and ISO 27001:2022 in nine months. Fluent in the 2022 Annex A controls, ISO/IEC 42001:2023 for AI management systems, GDPR, and NIST frameworks — and able to read the code the controls are meant to protect.
Based in Sweden. Working with clients across Europe — remote-first, timezone-flexible.
Security audit, SOC 2 / ISO 27001 readiness, or an ISO 42001 AI management system — we're ready when you are. Most engagements start with a 30-minute scoping call.