Scope and assess
We define the systems in scope, select the right benchmark, and run the initial assessment. Where no suitable standard exists, we build a benchmark based on best practices and fit to your environment.
Baseline Based helps regulated entities assess secure configuration baselines, identify hardening gaps, and guide remediation based on industry standards and real-world constraints.
Practical support across DORA and NIS2
We help regulated entities assess secure configurations against relevant benchmarks, validate the findings, design baselines and turn the result into a remediation path the technical team can actually execute.
We define the systems in scope, select the right benchmark, and run the initial assessment. Where no suitable standard exists, we build a benchmark based on best practices and fit to your environment.
We review the findings with the working team, resolve false positives and false negatives, and agree which items belong in the baseline, which need remediation, and which require documented exceptions.
We guide remediation, help structure the action plan, and build the evidence needed to support review or audit. Where ongoing assurance is required, we can also help implement continuous monitoring and reporting.
Assess the baseline. Fix the gaps. Keep it defensible.
Regulated entities are under growing pressure to show that hardening is not handled ad hoc. Under frameworks such as DORA and NIS2, the challenge is not only to assess the current state, but to maintain an auditable baseline over time.
That is why Baseline Based focuses on benchmark-based assessment, remediation guidance, documented exceptions, and monitoring where ongoing assurance is required. The goal is not more paperwork. It is a security baseline that can be maintained, explained, and defended.
Baseline Based combines baseline-based hardening, remediation support, and regulated-sector experience across banking, insurance, and compliance-heavy technology environments.
Founder, controls & compliance
Former founder with experience building compliance-heavy products and the ISMS, risk, and security structures behind them. Now focused on controls and compliance, with an interest in evidence, and practical implementation in regulated environments.
Founder, secure configuration & hardening
Background in the Dutch banking and insurance sector, with hands-on experience in CIS standard implementation, remediation guidance, exception handling, and audit evidence across enterprise environments. Focuses on the technical implementation layer: what is configured, what is missing, and what needs to change.
If you need a clearer view of your configuration, stronger hardening, or support turning findings into remediation and evidence, Baseline Based can help.
Let's talk