V&V Group
About us

Two brothers, one trade.

We are Slava and Victor Lashkov, the founders of V&V Group. On this page you can read who we are, what we do, what we have done so far and where our knowledge comes from. That way you know exactly who you are talking to.

Who we are

Young, curious and both working in security.

We share one trade and complement each other. Slava looks at it from daily practice as a security officer, Victor from his studies and the professional literature. Together we see both how things should be done and how they actually go.

Slava Lashkov

Co-founder

In my day job, I work as a security officer. There I see how a security policy holds up when it really has to work: during an incident, an audit or when a colleague receives a suspicious email.

I bring that hands-on experience to every V&V assignment, and I make sure that what we write down together can actually be carried out.

Victor Lashkov

Co-founder

Since September 2026 I have been studying Cyber Safety & Security part-time at NHL Stenden in Leeuwarden. I put what I learn there straight into my work.

I focus on how security fits the way your business works, so it becomes part of how you operate rather than a separate pile of paperwork.

Location
Blikfaart 20, 8801 XC Franeker
Region
Mainly active in and around Leeuwarden
Legal form
V&V Group V.O.F. (general partnership)
Chamber of Commerce (KVK)
97585750
Focus
Information security for Dutch SMEs
LinkedIn
V&V Group on LinkedIn
What we do

One trade: information security.

We help small and medium-sized businesses that are dealing with ISO 27001, NIS2 or GDPR for the first time, usually because a customer asks for it. We turn the requirements into what you actually need to do, and in what order.

An open question

The easiest way to start. Send us an email or a message on LinkedIn and we'll think along with you. Your first question is free, with no obligation.

ISO 27001 gap analysis

Using a questionnaire and a workbook covering all 93 controls in Annex A, we map out where you stand. You get a report showing what is already in place, what is missing and what needs attention first.

Setting up an ISMS

We guide you through setting up an information security management system: scope, policy, risk assessment and the controls that go with it. The certificate itself is issued by an accredited certification body, not by us.

NIS2 and GDPR

We work out whether the Dutch Cybersecurity Act applies to you, or what your customers will ask of you if it applies to them. For GDPR, we review how you work and the agreements you have, such as data processing agreements.

Ongoing support

Security is never finished. With a standing arrangement your approach stays up to date and you always know who to call when something comes up.

What we have done

We've only just started. This is what we've done so far.

V&V Group is a young company. We won't pretend to have years of experience or a long client list. This is what we can show.

Our own business

Our own ISMS under ISO 27001

We are working towards ISO 27001 certification ourselves. Our scope, security policy, risk methodology and overview of controls are in progress, and we have already put our own documentation through a critical internal mock audit. What we advise you, we apply to ourselves first.

Method

Our own ISO 27001 gap analysis

We built our own gap analysis method: an intake questionnaire, a workbook covering all 93 controls in Annex A and a standard report template. That way every analysis is complete and comparable.

On this website

The NIS2 check

This website has a short check that lets you see for yourself whether the Dutch Cybersecurity Act is likely to apply to you. It runs entirely in your own browser: your answers are not stored or sent anywhere.

Take the NIS2 check

Our sources

What our advice is based on.

There is a lot of half-information about security out there. That is why we work from the original standards and legislation and from the official regulators. If we say something is required, we can show you where it says so.

Standards

  • NEN-EN-ISO/IEC 27001:2023The official Dutch edition of the ISO 27001 standard. We work from a licensed copy obtained from NEN.

Legislation

Government and regulators

Literature and education

  • Professional literatureWe read a lot of literature on information security, including the Dutch books Handboek ISO 27001 ISMS, Handboek ISO 27001 Controls and Handboek NEN 7510 by Cees van der Wens, and ISO 27001 Tussen de regels by Nico Basten.
  • Cyber Safety & Security, NHL StendenThe part-time programme Victor is following, for which he also reads textbooks such as Basiskennis informatiebeveiliging op basis van ISO27001 en ISO27002 by Hans Baars, Jule Hintzbergen, Kees Hintzbergen and André Smulders.
  • PracticeWhat Slava sees every day as a security officer.

The text of ISO standards is protected by copyright. That is why we don't quote it, but explain in our own words what is required. If you want to read the standard yourself, you can buy it from NEN.

Want to get to know us? Just ask a question.

Whether it's about ISO 27001, NIS2, GDPR or something you can't quite figure out: no question is too small, and the first one is free with no obligation.

Our privacy statement explains what we do with your message.

info@vv-group.nl
Email us
Message on LinkedIn