Systemic risk, translated for the board.

LSVL Cyber is the independent advisory practice of Alyssa Sevilla, CISSP — enterprise security risk management, cyber strategy and GRC for major financial institutions across the UK, EU, APAC and the Middle East.

The system, observed
DORANIS 2NIST CSFISO 27001MAS TRMCIS ControlsFAIRGDPRPCI DSSZero TrustSABSATOGAFCyber Essentials

Advisory built for regulated finance.

Three pillars, one discipline: security decisions made legible to boards, regulators and the executives accountable for them.

  • Enterprise Security Risk Management

    Board-grade visibility of the cyber risks that are actually material. Risk profiles built from business impact, threat modelling on the applications that move money, and reporting that lets a risk committee decide with confidence.

    • Risk profiles & materiality assessmentFAIR · NIST CSF
    • Executive & board cyber-risk reportingC-SUITE
    • Crown-jewels & high-value-asset identificationBIA
    • Threat modelling on critical applicationsSTRIDE · MITRE
  • Cyber Strategy & Roadmap Development

    Strategy that survives contact with the regulator and the budget cycle. Independent validation of multi-year roadmaps, maturity benchmarked against global peers, and operating models that make the strategy executable.

    • Multi-year strategy design & independent validation3-YR HORIZON
    • Maturity assessment & peer benchmarkingREGIONAL · GLOBAL
    • Target operating model designPEOPLE · PROCESS · TECH
    • Zero Trust & enterprise security architectureSABSA · TOGAF
  • Governance, Risk & Compliance

    Compliance treated as an operating discipline, not paperwork. Readiness for DORA and NIS 2, harmonisation across UK, EU and APAC regimes, and certification programmes led end to end.

    • DORA readiness & enhanced risk managementDORA
    • Regulatory harmonisation across regimesNIS 2 · MAS TRM
    • Certification programme leadershipISO 27001:2022
    • Policies, standards & control frameworksCIS · PCI DSS

A ledger of mandates.

Nine years of advisory across the institutions where cyber risk is systemic: market infrastructure, sovereign capital, exchanges, banks and the platforms they depend on.

Client confidentiality is absolute — engagements are listed by sector.

Selected engagements by sector, mandate and region
SectorMandateRegion
Systemically important European FMIRepeatable assessment methodology for mission-critical applications under DORA’s enhanced risk-management mandate; executive reporting translating systemic cyber risk for C-suite and senior management.UK · EU
Sovereign wealth fundZero Trust architecture blueprint and a refreshed enterprise security architecture, embedding Zero Trust principles in support of a new business model.Singapore
One of Singapore’s largest financial institutionsIndependent review and validation of a three-year cyber defence roadmap and strategy, with maturity benchmarking against regional and global peers.APAC
National ICT ministrySector-level cyber strategy and framework — vulnerability, threat, incident and crisis management — aligned to leading international standards.Middle East
Financial subsidiary of a German automotive groupCrown-jewels and high-value-asset identification across the region: the framework, the executive engagement and the prioritised asset register.APAC
Satellite communications operatorISO 27001:2022 re-certification leadership for critical platforms, with harmonisation of UK, EU and national cybersecurity mandates.UK · US

From assessment to the boardroom.

The same arc on every mandate — evidence first, materiality second, and a story the board can act on at the end of it.

  1. Assess

    Maturity, threat exposure and control reality — benchmarked against regional and global peers, not against vendor marketing.

  2. Prioritise

    Business impact analysis with the executives who own the assets. Materiality decides the order of work; investment follows the crown jewels.

  3. Chart

    A roadmap the board can fund and the CISO can deliver — sequenced, costed in effort, and mapped to the regulatory horizon.

  4. Report

    Systemic risk translated into business language: board papers, committee reporting and the ongoing counsel that keeps direction.

LSVL CYBER · LONDON · SECURITY RISK ADVISORY · EST. MMXXVI ·AS

CISSP 2023–2029LondonUK · EU · APAC · ME

Alyssa Sevilla, CISSP

LSVL Cyber is the independent practice of Alyssa Sevilla — nine years of international security advisory across London, Brussels, Singapore and the Middle East, most of it inside the world’s most regulated industry.

Her career spans Big Four financial-services consulting, global telecommunications and satellite operators, and Europe’s market infrastructure — advising sovereign wealth funds, stock exchanges, banks and asset managers on the risks that reach the board.

Working frameworksDORA · NIS 2 · NIST CSF · ISO 27001 · CIS Controls · FAIR · GDPR · PCI DSS · MAS TRM · TOGAF · SABSA · Zero Trust

Begin the conversation.

For advisory enquiries, board briefings or engagement availability — a direct line to the principal, without a gatekeeper.

contact@lsvlcyber.com