Skip to content
Cyvalent
Back to resources

What You Should Actually Expect from Cyvalent 360 Cyber Services

Published

For many mid-market organisations, the first cybersecurity governance gap is not another policy—it is the capacity to keep the programme running. There may be no CISO, while the IT manager already covers infrastructure, support, suppliers and incidents. In Luxembourg, the pressure may come from management-body duties under the Act of 5 May 2026, DORA obligations for an in-scope financial entity supervised by the CSSF or CAA, customer expectations around ISO/IEC 27001, or an audit request for evidence that has never been maintained in one place 2 3 4 6 5.

Cyvalent 360 Cyber Services is built for that operating gap. It provides practitioner capacity to design, run, and maintain a cybersecurity governance programme, including CISOaaS where the organisation needs security leadership before it can justify or hire a full-time internal role. CISOaaS can support, structure and run the security-governance programme, but it does not transfer the management body's statutory duties to approve and oversee the measures—or its accountability under Article 13—to an external practitioner 3 5.

Software, services, or both — what the missing capacity points to

Your situationBest starting pointWhy
No internal owner with the capacity and experience to run security governanceCyvalent 360 Cyber ServicesPractitioner capacity to design, run, and maintain the programme
Internal security function, but weak compliance trackingCyvalent RGXBetter compliance tracking and cross-framework evidence reuse
Need both operating capacity and better toolingBoth, side by side360 Cyber Services runs the programme; Cyvalent RGX provides the workbench

Who Cyvalent 360 Cyber Services Is For

The service is designed for mid-market organisations that need hands-on operating capacity, not only recommendations. Common signs include: no dedicated security function; a management body that needs a documented record of its decisions and oversight; customer evidence requests that are becoming harder to answer; or duties under Luxembourg's Act of 5 May 2026 or DORA, as supervised by the relevant Luxembourg authority 2 3 4 5.

Which regime applies depends on the entity and activity. Article 1(8) of the Luxembourg NIS2 Act avoids duplicating equivalent sector-specific EU duties. DORA-covered financial entities should therefore confirm the applicable requirements and reporting route with the CSSF or CAA 2 3 4.

Cyvalent 360 Cyber Services puts an experienced cybersecurity practitioner into that operating role, providing recurring operating capacity: risk reviews, evidence maintenance, management reporting, incident-readiness work, supplier-risk follow-up, and audit/supervisory response preparation. The work is not limited to producing a report; it includes running the compliance calendar, coordinating risk decisions, and keeping the programme moving.

What the Service Covers

Cyvalent 360 Cyber Services is structured across twelve service modules. An engagement can begin with a focused set of modules and expand as the programme matures.

  • CISOaaS (virtual CISO) — Strategic security leadership, management-body reporting, risk strategy and coordination with the relevant Luxembourg authority. Luxembourg context: Article 13 of the Act of 5 May 2026 covers management-body approval, oversight, responsibility and training; DORA Article 5 applies to governance for in-scope financial entities supervised in Luxembourg by the CSSF or CAA 2 3 4 5.
  • Risk-management programme — Operating the cybersecurity risk register and treatment plan in line with the applicable requirements: Article 12 of Luxembourg's Act of 5 May 2026, DORA's ICT risk-management framework for in-scope financial entities, and ISO/IEC 27001 where the organisation has adopted that standard 2 3 6 5.
  • Compliance programme management — Compliance calendar, evidence collection, control-status tracking, and audit readiness for the frameworks the organisation is subject to.
  • Incident-response readiness — Escalation paths, playbooks, exercises and evidence needed to support reporting under Article 14 of Luxembourg's Act of 5 May 2026. For DORA entities, this also covers incident management and reporting under DORA Articles 17–23 and the related technical standards, through the CSSF or CAA as applicable 2 3 4 5.
  • Supply-chain security — Third-party risk assessments, concentration-risk reviews, contractual controls and supplier oversight. For DORA entities, this includes Article 28 and the applicable technical standards; CSSF-supervised entities should also consider Circular CSSF 25/882 2 4.
  • Security awareness and training — Regular training for management-body members and staff. Article 13(2) of Luxembourg's Act of 5 May 2026 expressly addresses both groups 3 5.
  • Policy and procedure library — Drafting and maintaining the policies, procedures, and governance records the management body approves and auditors review.
  • Technology risk assessments — Targeted reviews of systems, architectures, vendors, or changes where the governance programme identifies a material risk.
  • Board and management reporting — Preparing concise reporting for management-body decisions and oversight, including the governance duties under Article 13 of Luxembourg's Act of 5 May 2026 and DORA Article 5 where applicable 2 3 4 5.
  • Regulatory response support — Preparing evidence and response material for the relevant Luxembourg authority: the ILR for most sectors under the Luxembourg NIS2 Act; the CSSF for the sectors and supervised activities specified in Article 3 of that Act; and the CSSF or CAA for their respective DORA-supervised entities 3 4 5.
  • Vendor and partner management — Putting security requirements into RFPs and contracts, onboarding providers, scheduling reviews and tracking remediation through to closure.
  • Business continuity and resilience — Business-continuity, backup, recovery and crisis-management support aligned with Article 12(2) of Luxembourg's Act of 5 May 2026 and DORA Articles 11–12 where applicable 2 3 5.

Cyvalent RGX and Cyvalent 360 Cyber Services

Cyvalent RGX is the platform. Cyvalent 360 Cyber Services is the practitioner capacity. The two offerings are complementary.

Cyvalent RGX helps teams map regulatory obligations to control frameworks, track compliance posture and identify opportunities to reuse evidence across frameworks. Cyvalent 360 Cyber Services provides the human work of interpreting the organisation's situation, preparing decisions, running the programme, and maintaining the records and reporting needed for accountable management-body oversight.

Some organisations need the platform first because they already have a security or GRC function and need better structure. Others need services first because they do not yet have the operating capacity to run the programme. Many use both: the practitioner runs the governance programme while Cyvalent RGX provides the compliance workbench.

The Buyer's Decision

The core decision is not "software or services?" It is "what is the missing capacity?"

  • If you need an experienced cybersecurity practitioner to design and run your security governance programme, Cyvalent 360 Cyber Services is the starting point.
  • If you have an internal security function that needs better compliance tracking and cross-framework evidence management, Cyvalent RGX is the starting point.
  • If you need both operating capacity and better tooling, the two offerings work side by side: Cyvalent 360 Cyber Services runs the governance programme while Cyvalent RGX provides the structured platform for posture tracking and evidence reuse.

A useful first conversation covers what you have, what the gap is, and what sequencing makes sense: services first, platform first, or both together.

In short

  • Cyvalent 360 Cyber Services fills an operating-capacity gap, not just an advice gap: it puts an experienced cybersecurity practitioner into the role — including CISOaaS — to design, run, and maintain the governance programme, without replacing the management body’s legal duties to approve and oversee.
  • The service is structured across twelve modules; an engagement can begin with a focused set of modules and expand as the programme matures.
  • The buyer's real question is not “software or services?” but “what is the missing capacity?” — Cyvalent 360 Cyber Services and Cyvalent RGX are complementary and can run side by side.

Not sure what capacity you are missing?

Cyvalent helps mid-market organisations decide what to run in-house and what to hand over — through founder-led 360 Cyber Services / CISOaaS and the Cyvalent RGX cyber GRC platform.

Frequently asked questions

What is Cyvalent 360 Cyber Services?

Cyvalent 360 Cyber Services is practitioner capacity to design, run, and maintain a cybersecurity governance programme — including CISOaaS (a virtual CISO) where an organisation needs security leadership before it can justify or hire a full-time internal role. The work is not limited to producing a report: it includes running the compliance calendar, maintaining the evidence base, preparing management reporting, coordinating risk decisions, and keeping the programme moving.

Who is Cyvalent 360 Cyber Services for?

It is built for mid-market organisations that need hands-on operating capacity, not only advice. Typical signs include no dedicated security function, growing customer evidence requests, or duties under Luxembourg's Act of 5 May 2026 or DORA that require repeatable decisions and documented evidence. The relevant regime and supervisor depend on the entity and activity.

What does Cyvalent 360 Cyber Services cover?

It is structured across twelve service modules, including CISOaaS, a risk-management programme, compliance programme management, incident-response readiness, supply-chain security, security awareness and training, a policy and procedure library, technology risk assessments, board and management reporting, regulatory response support, vendor and partner management, and business continuity and resilience. Not every engagement uses all twelve at once; an engagement can begin with a focused set of modules and expand as the programme matures.

Does Cyvalent 360 Cyber Services include a virtual CISO (CISOaaS)?

Yes. CISOaaS is one of the twelve modules and covers strategic security leadership, board reporting, risk strategy, and regulatory-response coordination — provided where an organisation needs security leadership before it can justify or hire a full-time internal role. It supports, structures and runs the programme but does not replace or transfer the management body’s statutory duties or accountability under Article 13.

What is the difference between Cyvalent 360 Cyber Services and Cyvalent RGX?

Cyvalent RGX is the platform: it helps teams map regulatory obligations to control frameworks, track compliance posture and identify opportunities to reuse evidence across frameworks. Cyvalent 360 Cyber Services is the practitioner capacity: the human work of interpreting the organisation’s situation, preparing decisions, running the programme, and maintaining the records and reporting needed for accountable management-body oversight. The two offerings are complementary.

Should we start with the platform or the services?

It depends on the missing capacity. If you need an experienced cybersecurity practitioner to design and run your security governance programme, Cyvalent 360 Cyber Services is the starting point. If you have an internal security function that needs better compliance tracking and cross-framework evidence management, Cyvalent RGX is the starting point. If you need both, the two work side by side — the practitioner runs the governance programme while Cyvalent RGX provides the compliance workbench.

Sources & References

Last checked:

EU legislation

  1. [1] European Parliament & Council. Directive (EU) 2022/2555 (NIS2) — Art. 20 (management-body approval, oversight, training), Art. 21 (cybersecurity risk-management measures), Art. 23 (incident reporting), Annexes I-II (sectors). EU background source; for Luxembourg's transposition and current supervisory guidance, see [3] and [5]. Status/date: in force; adopted 14 Dec 2022. Source: EUR-Lex. https://eur-lex.europa.eu/eli/dir/2022/2555/oj

  2. [2] European Parliament & Council. Regulation (EU) 2022/2554 (DORA) — Art. 5 (governance/management body), Arts. 11-12 (business continuity), Arts. 17-23 (incident management), Art. 28 (third-party ICT risk), Art. 64 (applies 17 Jan 2025). Status/date: applicable from 17 Jan 2025. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg/2022/2554/oj

Luxembourg legislation and supervisory guidance

  1. [3] Luxembourg. Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (Mémorial A No 225, published 6 May 2026) — Luxembourg transposition of Directive (EU) 2022/2555; in force since 10 May 2026. Source: Legilux. https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a225/jo

  2. [4] Luxembourg DORA implementation and supervision. Law of 1 July 2024 (Mémorial A No 271); CSSF, ICT and cyber risk – for DORA entities; CSSF Circular 25/882 on ICT third-party services; and CAA Circular Letter 25/1 on DORA. DORA and the national implementing law have applied since 17 January 2025; the CSSF and CAA supervise their respective entities. Sources: Legilux, CSSF, Circular 25/882, CAA Circular 25/1. https://legilux.public.lu/eli/etat/leg/loi/2024/07/01/a271/jo and https://www.cssf.lu/en/ict-and-cyber-risk-for-dora-entities/ and https://www.cssf.lu/en/Document/circular-cssf-25-882/ and https://www.caa.lu/uploads/documents/files/LC25-01_FR.pdf

  3. [5] Institut Luxembourgeois de Régulation. The NIS 2 Act; Security measures and supervision under NIS2; and Incident notification — current Luxembourg supervisory guidance and further reading. Sources: ILR. https://www.ilr.lu/en/sectors/niss/nis-2/ and https://www.ilr.lu/en/sectors/niss/nis-2/security-measures-and-supervision-under-nis2/ and https://www.ilr.lu/en/sectors/niss/incident-notification/

Other sources

  1. [6] International Organization for Standardization. ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements, including Amendment 1:2024 where applicable. Status/date: published 2022 (Amd 1:2024). Source: ISO. https://www.iso.org/standard/27001

Related reading