Boxfish Labs home
Boxfish Labs
  • Solutions
  • Resources
  • About
  • Labs
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • By service
      • Information Security Advisory
      • Virtual CISO
      • External DPO
      • Data Residency & Sovereignty
      • Human-centred cybersecurity awareness
      • Security Check for Vibe-Coded Apps
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Audience
      • Startups and Scaleups
      • Fintech
      • Technology suppliers
      • Educators
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • CRA applicability quiz
    • Privacy toolboxNEW
    • View all resources
    • About us
    • News
    • Social impact
    • Pilot partner program
    • Referral program
    • Contact
    • About Labs
    • Privacy toolbox

Featured

Dot-matrix letters CRA on a black grid background

Does your software or hardware product need to comply with the EU Cyber Resilience Act?

Take the test
ENDEHU
Book a Call
Challenges

What problem should we help with?

These are situations clients often bring to Boxfish Labs. Pick the closest match, or book a call if yours looks different.

Customers keep asking for security evidence

Questionnaires, privacy reviews, and supplier checks are stacking up, and you need clearer answers without building an enterprise programme overnight.

Talk this through

We are not sure which rules apply

GDPR, DORA, the EU AI Act, the Cyber Resilience Act, or customer frameworks may apply - and you need a practical read of what matters for your business.

Map your obligations

People are the weakest link right now

Phishing, weak habits, unclear reporting, or AI misuse are creating risk, and awareness training alone is not changing behaviour.

Strengthen human resilience

We need senior security or privacy leadership

You are not ready for a full-time CISO or DPO hire, but customers, investors, and leadership still expect credible ownership.

Explore external support

A product launch is coming and risk is unclear

Data flows, AI features, suppliers, access, and market expectations need a focused review before release creates avoidable problems.

Prepare your launch

AI is already in use without clear boundaries

Teams are experimenting with tools, sharing sensitive context, or building AI features, and you need governance people can actually follow.

Govern AI use

An incident or near miss raised hard questions

Something went wrong, almost went wrong, or leadership wants a clearer response path before the next pressure moment.

Improve readiness

Data residency and suppliers feel risky

Where data lives, who can access it, and which providers you depend on are becoming customer, legal, or resilience issues.

Review dependencies

You hope a security incident will not happen because you are not prepared

We build practical incident response plans: how your team spots and reports issues, who coordinates decisions, how containment works, and how to maintain operations under pressure.

Build incident readiness

You need senior expertise without hiring a full-time executive

We provide on-demand security and privacy leadership that scales with your growth, giving you access to senior guidance, audit preparation, and strategy only when you need it.

Get senior security leadership

Your sensitive data is scattered across tools and vendors

We map personal and confidential data, cloud platforms, shared drives, collaboration tools, and access patterns to give you a clear, defensible basis for security and privacy decisions.

Map where sensitive data lives

Your security and privacy responsibilities are undefined

We establish proportionate governance structures: leadership accountability, operational ownership, policy baselines, escalation routes, and clear reporting lines so everyone knows who decides what.

Clarify security ownership

You must meet GDPR and European privacy expectations

We handle data-flow mapping, records of processing, privacy notices, DPIAs, vendor risk reviews, and data subject requests, providing hands-on execution or dedicated DPO coverage.

Meet GDPR and privacy expectations

You rely on critical third parties, cloud platforms, and SaaS

We identify critical supplier, contractor, and subprocessor dependencies, evaluate third-party risks, review contracts, and build practical oversight to protect your business continuity.

Reduce supplier and cloud risk

Your team needs practical, inclusive security training

We design human-centred learning that builds confidence rather than fear, using role-based training, phishing exercises, workshops, and serious games that fit everyday working routines.

Build practical team resilience

You are adopting AI tools, cloud services, or new tech stacks

We evaluate the security, privacy, and regulatory implications of AI tools, new software architectures, and automated systems before decisions become costly or difficult to reverse.

Assess AI and new tech risk

Something else entirely

Your situation does not fit a neat label. Tell us what is creating pressure and we will help you find the right next step.

Book a discovery call

Still not sure where to start?

Tell us what is creating pressure for your team. We will help you map the right Boxfish Labs approach.

Talk to our expert
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Solutions
  • Resources
  • About
  • Labs

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs