V&V Group
Information security for SMEs

A customer asks for ISO 27001 or NIS2. We help you get there.

A large customer sends a security questionnaire, the Dutch Cybersecurity Act is in force, or you simply want to know where you stand. V&V Group turns ISO 27001, NIS2 and GDPR into what you actually need to do. In plain language.

Your first question is free, with no obligation. If we go on to work together, you'll get a fixed price up front.

How most conversations start

A customer sent me an information security questionnaire. Where do I start?

Does the Dutch Cybersecurity Act apply to my business?

Do I need a data processing agreement with my IT supplier?

Sound familiar? Send us your question.

What we do

Security you understand and can maintain yourself.

Many small businesses are dealing with information security standards and laws for the first time. We turn them into what you actually need to do, and in what order.

ISO 27001

We help you set up and maintain an information security management system (ISMS), and work out with you where you stand on the 93 controls in Annex A.

We don't issue the certificate ourselves. That is done by an accredited certification body. We prepare you for that audit so you know what will be asked.

NIS2

Since 15 August 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, has been in force in the Netherlands. It is aimed mainly at medium-sized and large organisations in designated sectors.

If it doesn't apply to you directly, you will often still feel its effects through your customers, who must also assess their suppliers. We work out with you whether the law applies and what your customers are likely to ask.

Does NIS2 apply to me? Take the short check

GDPR

Do you process personal data? We review how you work and the agreements you have, such as data processing agreements, and explain why each one matters.

Ongoing support

Security is never finished. Stay in touch with us and your approach stays up to date, and you always know who to call when something comes up.

How we work

Step by step, at your pace.

You know your business best. We bring the security knowledge. Together we find an approach that works.

  1. You ask a question

    Send us an email or a message on LinkedIn. Your first question is free. No form, no fixed package.

  2. We get to know you

    We ask questions and go through your work, systems and risks with you.

  3. A plan with a fixed price

    We explain what we see, decide with you what comes first and agree a price up front.

  4. The knowledge stays with you

    We hand over what we know so you can carry on yourself without depending on us.

Why V&V

We start with ourselves

V&V Group is working towards ISO 27001 certification itself. What we advise you, we apply in our own business first.

Young and curious

We move fast, ask lots of questions about your line of work and share what we learn along the way.

Plain language

No jargon without explanation. When we use a technical term, we explain it briefly.

About us

Want to know more about us and how we work?

We are Slava and Victor Lashkov, two brothers from Franeker who both work in information security. Read who we are, what we have done so far and which sources we base our advice on.

Read more about us

Got a question? Just ask.

Whether it's about ISO 27001, NIS2, GDPR or something you can't quite figure out: no question is too small, and the first one is free with no obligation.

Our privacy statement explains what we do with your message.

info@vv-group.nl
Email us
Message on LinkedIn