COMPANY & SERVICES OVERVIEW

Regulatory clarity for complex institutions.

An independent Luxembourg advisory boutique — Fractional CISO, DPO and regulatory compliance for the financial sector.

Warm marble and glass interior of a Luxembourg institution
Junglinster · LuxembourgEst. 2017

WHO WE ARE

01

Fractional Leadership

Formally designated DPO and outsourced CISO roles — senior regulatory presence at a fraction of a full-time hire, reporting directly to your Executive Committee and Board.

02

Regulatory Depth

GDPR, CSSF circulars and DORA read as one continuous framework. Gap assessments, remediation roadmaps and regulatory correspondence prepared to institutional standard.

03

Sector Focus

Deep familiarity with regulated financial entities — banks and branches, payment and electronic money institutions, and virtual asset service providers (VASPs) navigating Luxembourg's compliance, risk and IT expectations.

PRACTICE AREAS

Eight disciplines,
one advisor.

"Compliance is not a certificate on the wall. It is a posture — sustained, documented, and worthy of examination."
Mirko Teroni · Managing Partner

25+ years across IT Governance, Security and Compliance. Lecturer, University of Luxembourg — Master's in IT Security.

MANAGING PARTNER

Mirko Teroni.

Twenty-five years across IT Governance, Data Privacy, Information Security and Regulatory Compliance — advising banks, branches and their Head Offices through ISO 27001 and PCI-DSS certification. Lecturer at the University of Luxembourg on the Master's in IT Security, and PECB Certified Trainer. Holds CISM, CRISC, and ISO 27001 Lead Implementer, Lead Auditor and Master credentials.

DIGITAL ASSETS

Crypto providers and VASP compliance.

We advise virtual asset service providers, crypto-asset firms and their banking counterparties on the full regulatory perimeter — VASP registration and MiCA authorisation, AML/CFT for on-chain activity, custody and key management, GDPR on blockchain data, and DORA-grade ICT resilience. The same Fractional CISO and DPO model applies, adapted to the operating reality of a digital-asset business.

01

Licensing & registration support

Preparation of VASP registration and MiCA/CASP authorisation files — governance arrangements, internal control framework, ICT and security policies, and responses to regulator questions during the review.

02

AML/CFT for virtual assets

Travel Rule implementation, blockchain analytics and wallet screening controls, transaction monitoring calibration for on-chain flows, and source-of-funds/source-of-wealth evidencing for crypto-derived assets.

03

Custody & key management

Review of hot, warm and cold wallet architecture, HSM and MPC key ceremonies, segregation of client assets, signing policies, and recovery and business continuity testing for key material.

04

Data protection for on-chain data

GDPR analysis of blockchain and wallet data, DPIAs for analytics and screening tooling, retention and erasure positions on immutable ledgers, and transfer assessments for offshore exchange and custody partners.

05

ICT risk, DORA & resilience

DORA readiness for crypto-asset firms — ICT third-party registers for exchanges, custodians and node providers, incident classification and reporting, penetration testing and smart-contract review coordination.

06

Bank-side crypto exposure

Advising banks and PSPs onboarding VASP clients or launching digital-asset offerings: risk appetite, counterparty due diligence on exchanges, and control expectations aligned with CSSF and EBA guidance.

Engagements range from a targeted licensing or Travel Rule review to an ongoing Fractional CISO or DPO mandate for a regulated digital-asset entity.

WHY THE ADVISORY GROUP

Credentials that stand scrutiny.

25+

Years of practice

08

Regulated disciplines

Certifications

CISM · CRISC · ISO 27001 Lead Implementer, Lead Auditor & Master · PECB Certified Trainer

Track record

Guided financial institutions through ISO 27001 and PCI-DSS certification. Hands-on experience advising crypto-asset service providers (VASPs) on GDPR, AML/CFT-adjacent controls and information security. Academic grounding at the University of Luxembourg.

ENGAGEMENT MODEL

A single point
of contact.

REQUEST A CONSULTATION

Reserve a confidential
introductory call.

Share a topic and two preferred windows. The Managing Partner will confirm a slot within one business day.

Availability

Submissions are treated in strict confidence. No data is stored on this site.

Let's discuss your
compliance posture.