
Building resilience on a solid foundation of risk management
From building and implementing governance to conducting hollistic and in depth risk assessments and everything in between. Risk expertise that strengthens your business and descision making, not just your paperwork.
IT, OT, Operational Risk & Resilience
Information Security
Supply Chain & Third Party Risk
Governance, Risk, Compliance & Audit

Services
IT, OT and Operational Risk & Resilience
How well do you really understand your Information Technology (IT), Operational Technology (OT) and Operational Risk (ORM) exposure? On paper, systems and processes often appear well protected. In practice, they are usually more vulnerable than thought.
We map that gap. From in-depth risk assessments and risk methodology to industrial control systems and business continuity, built on years of assessing entire value streams, production environments and warehouses across Europe. The result is not a report, but decisions you can act on, with governance, security and resilience designed in from the start.
Information Security
Information is one of your most valuable assets and one of the easiest to lose. Strong information security isn't a tool you buy: it's a capability you build into how your organization works.
We help you build and embed an Information Security Management System that fits your organization, from policies and procedures to security by design, data privacy in line with GDPR and awareness training. Practical, proportionate and aligned with ISO 27001, NIST CSF and IEC 62443, so security becomes something people actually follow instead of something they work around.
Supply Chain & Third Party Risk
Your risk exposure doesn't stop at your own walls. It extends to every vendor, supplier and partner with access to your systems, data or premises. Whether that's a cloud provider for a financial institution or an OT supplier for an industrial operator, third-party risk is one of the most overlooked attack surfaces.
From procurement and vendor due diligence to third-party risk assessments and ongoing monitoring across your supply chain, we help you see where your real exposure lies and manage it before it becomes an incident. Built on years of assessing vendors, partners and data-sharing arrangements across European supply chains, and aligned with requirements such as DORA.
Governance, Risk, Compliance & Audit
Governance isn't a paperwork exercise. It's how resilient organizations know what to do, and how to do it, when it matters. We help you build the governance structures, policies, procedures and control frameworks that keep risk manageable. From risk appetite and reporting to embedded ways of working: governance that fits how your organization actually runs, instead of a binder on a shelf.
And we test whether it holds. Through internal audits, control testing and maturity assessments, we show you where your governance stands today and what it takes to strengthen it, before a regulator or certification body does. With the CER directive, NIS2 and DORA reshaping compliance obligations across Europe, that readiness is no longer optional.

ABOUT
I am Ferry Verspuij, born and raised in The Hague, in the Netherlands and founder of Ferspuij Business Consultancy.
For over 12 years I've worked at the intersection of operational risk, information security and IT/OT risk, at international and domestic organizations across financial services, real estate, retail, logistics and manufacturing.
I hold the CISM, CRISC and CDPSE certifications, and previously led information security and risk teams at Nike and Aegon, including internal audit work and OT and ICS risk assessments across European supply chains and manufacturing facilities.
In 2025 I went independent, because I wanted to help organizations and the people to gain insights and get in control of their risks. I believe risk management works best when it's practical and tailored to the organization: when it creates insights that matter and helps you achieve your objectives.

From risk assessments on processes, applications and systems to entire entities and factories and from building risk assessment methodologies at a bank to securing supply chains across EMEA, I've seen that the difference between paper resilience and real resilience is made in execution, not in reports. That's what Ferspuij Business Consultancy stands for.
All the way from actual insights that actually matter to to implementation: risk assessments (IT, OT and operational risk), information security, third-party risk and governance that fit how your organization truly runs.
I'm hands-on by nature, and what drives me is simple. I get energy from helping organizations and the people in them to make sense of risk. Not as something overwhelming, but as something you understand, own and use to make better decisions.
Let's talk about how I can help you gain insight and strengthen your risk and security posture.

Experience










CONTACT
Inquiries
For any inquiries, questions or commendations, please call: +316 47 00 49 97 or fill out the following form
Contact Us
Head Office
Amsterdam, the Netherlands
Chamber of commerce: 97668583