Area of service04 / 05

Governance & decisions.

You receive a decision paper that clearly separates options, evidence and open questions.

The situation

What did you know, and what did you do about it?

Recognising risks is not enough for the executive board. What matters is what was subsequently decided, initiated and actually implemented.

Requirements and decisions must turn into concrete measures within the company. Obligations, identified risks, decisions, measures and implementation are brought together and made demonstrable. Governance in this sense does not mean writing more policies, but making visible who actually decides, and on what basis.

This creates a traceable record: What was known? How was it assessed? What was decided? Who was responsible? What was implemented?

Insight → decision → responsibility → evidence.

What pleXcreen delivers to leadership

  1. 01

    A decision paper

    Options, evidence and open questions clearly separated, with a reasoned recommendation.

  2. 02

    Clear responsibility

    Who decides and initiates what, recorded at the time of the decision.

  3. 03

    Robust evidence

    What was known, how it was assessed and what was done about it. Legal assessment is provided by specialised lawyers.

The moment before the decision.

Empty boardroom at dusk: two stacks of paper on the table, one in warm lamplight, one in cool shadow, a fountain pen between them.Fictitious example
evidencedFoundations with source, time and test status.
openAssumptions nobody has yet tested remain visible.
decisionWho decides, on what basis, and what deliberately remains open.
  1. 1evidenced Foundations with source, time and test status.
  2. 2open Assumptions nobody has yet tested remain visible.
  3. 3decision Who decides, on what basis, and what deliberately remains open.
Illustrative scene. A good decision paper separates what is evidenced from what is open before anyone signs.
Technical detail · optional · fictitious sampleWhat a decision paper looks like.

A fictitious sample: three options, their evidence and one question that deliberately remains open.

Fictitious exampleDecision paper · no client data

Remote maintenance: restrict, replace or leave as is?

ARecommended

Restrict access

Reachability: evidenced

A reasoned decision despite open exploitability: low effort, reduces the attack surface immediately.

  1. BReplace the service

    Cost: estimated

    Sensible, but cost and time are not yet evidenced.

  2. CLeave unchanged

    Exploitability: open

    Assumes there is no vulnerability. That is untested.

Open question

Whether the running version is actually affected is not yet clarified. The recommendation applies until then.

Decided by: management · Paper: pleXcreen

Method, scope and limits

01

What is examined

Within the agreed scope we look at how technical and operational reality becomes a management decision in your organisation: the assignment of responsibilities, the handling of known risks, the quality of evidence provided to supervisors, auditors and the board, and the question of whether relevant findings reach leadership at all.

Where regulatory requirements apply, from NIS2, the critical-infrastructure context or sector-specific rules, we map existing findings to those requirements. We assess what is evidenced and what remains open; we do not confirm compliance that the available observations do not support.

02

What you receive

You receive a management interpretation that separates three things: what is observed and supported, what is derived from it and what remains unknown. On that basis a prioritised plan of measures is developed, with a clear assignment of decision, responsibility and time horizon.

Where wanted, the evidence is structured so that it stands up to third parties, board, supervisors, auditors, insurers or contractual partners. Additional legal validation through partners is possible and agreed separately.

03

How the collaboration begins

It starts with a free initial conversation about your situation, the question at hand and responsibilities. It contains no assessment. Only once objective and scope are agreed does the commissioned work begin, often as a Schlaglicht that provides the outside view, or directly as a deepening of the governance perspective where technical findings already exist.

04

Who this is for

Executive management and boards that need an independent second view of their own decision basis; risk management and compliance functions that must turn technical findings into demonstrable steering; CISOs who want their findings to carry weight at leadership level.

What this service is not

  • Not legal advice and not a certificate of compliance; legal validation, where wanted, is provided separately through partners.
  • No confirmation of security or completeness: what is assessed is what has been observed and supported within the agreed scope.
  • Not a replacement for internal leadership responsibility, decisions remain yours.

Frequently asked questions

Does the management interpretation replace an audit?
No. It is an independent interpretation of the available findings for leadership decisions. It can prepare or complement an audit, but does not replace one and is not a certificate of compliance.
How are NIS2 or critical-infrastructure requirements handled?
Existing findings are mapped to the relevant requirements. We show what is evidenced and what remains open. Whether and how formal evidence is provided to an authority is agreed within the mandate.
Do you need access to internal systems?
Not, as a rule, for interpreting technical findings. Examining the leadership and decision architecture requires conversations and documents, the extent of which is agreed in advance.

Next step

Arrange an initial conversation.

Free of charge, with no assessment. Getting in touch triggers neither an engagement nor any technical testing. Scope and depth are agreed only afterwards.