We turn regulatory complexity into clarity, compliance into business advantage, and risk into continuous resilience.
NOVUM CYBER is a boutique Governance, Risk and Compliance advisory working at the intersection of cybersecurity, privacy and AI governance — helping regulated and growth-stage organisations meet their obligations while strengthening governance and reducing risk.
We make security, privacy and AI obligations legible — a clear picture of where you stand, what's required, and what to do next.
We translate the regulatory load — DORA, NIS2, GDPR, the EU AI Act, ISO standards and the CRA — into a practical, audit-ready posture.
We stay close — typically as your fractional CISO or DPO — embedding capability that becomes lasting resilience.
Delivered individually or together — because the regulations driving them increasingly converge.
Strategy, ISO 27001, DORA/NIS2, incident readiness, and CISO as a Service (vCISO).
GDPR, ISO 27701, DPIAs, breach management, and DPO as a Service (vDPO).
Independent IT audit, controls reviews, third-party risk and SOC 2 readiness.
ISO 42001 and EU AI Act readiness, AI risk and impact assessments, AI vendor risk.
Training across cyber, privacy, AI and compliance — capability that lasts.
Rather than treating each regulation in isolation, we build a single governance model, a single risk register and a single control framework — then map them across the standards that matter, so a single control can satisfy multiple obligations at once.
The firm is led by founder Constantinos Koumides — Big 4 advisory, security leadership in banking, and IT compliance in the technology sector, with more than 15 years in cybersecurity, risk and compliance. The person on the proposal is the person doing the work.
Facing a new regulatory obligation, preparing for an audit, or want a senior advisor who has held the seat? Tell us where you stand.