A customer asks for ISO 27001 or NIS2. We help you get there.
A large customer sends a security questionnaire, the Dutch Cybersecurity Act is in force, or you simply want to know where you stand. V&V Group turns ISO 27001, NIS2 and GDPR into what you actually need to do. In plain language.
Your first question is free, with no obligation. If we go on to work together, you'll get a fixed price up front.
A customer sent me an information security questionnaire. Where do I start?
Does the Dutch Cybersecurity Act apply to my business?
Do I need a data processing agreement with my IT supplier?
Sound familiar? Send us your question.
Security you understand and can maintain yourself.
Many small businesses are dealing with information security standards and laws for the first time. We turn them into what you actually need to do, and in what order.
ISO 27001
We help you set up and maintain an information security management system (ISMS), and work out with you where you stand on the 93 controls in Annex A.
We don't issue the certificate ourselves. That is done by an accredited certification body. We prepare you for that audit so you know what will be asked.
NIS2
Since 15 August 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, has been in force in the Netherlands. It is aimed mainly at medium-sized and large organisations in designated sectors.
If it doesn't apply to you directly, you will often still feel its effects through your customers, who must also assess their suppliers. We work out with you whether the law applies and what your customers are likely to ask.
GDPR
Do you process personal data? We review how you work and the agreements you have, such as data processing agreements, and explain why each one matters.
Ongoing support
Security is never finished. Stay in touch with us and your approach stays up to date, and you always know who to call when something comes up.
Step by step, at your pace.
You know your business best. We bring the security knowledge. Together we find an approach that works.
You ask a question
Send us an email or a message on LinkedIn. Your first question is free. No form, no fixed package.
We get to know you
We ask questions and go through your work, systems and risks with you.
A plan with a fixed price
We explain what we see, decide with you what comes first and agree a price up front.
The knowledge stays with you
We hand over what we know so you can carry on yourself without depending on us.
We start with ourselves
V&V Group is working towards ISO 27001 certification itself. What we advise you, we apply in our own business first.
Young and curious
We move fast, ask lots of questions about your line of work and share what we learn along the way.
Plain language
No jargon without explanation. When we use a technical term, we explain it briefly.
Want to know more about us and how we work?
We are Slava and Victor Lashkov, two brothers from Franeker who both work in information security. Read who we are, what we have done so far and which sources we base our advice on.
Got a question? Just ask.
Whether it's about ISO 27001, NIS2, GDPR or something you can't quite figure out: no question is too small, and the first one is free with no obligation.
Our privacy statement explains what we do with your message.