The Verhulsdonck Method

The Verhulsdonck Method™ is a diagnostic and validation approach used in QWASP's assurance and governance work. It exists to answer one question first: does this organisation actually work the way its policy says it does, and where is the gap?

Why not just another checklist audit

Conventional compliance checklists confirm that a document or control exists. They are often insufficient on their own: presence is not the same as effectiveness. The Verhulsdonck Method starts from a different question: does a control actually work, in practice, under real conditions, and treats compliance-completeness as secondary to demonstrable risk reduction.

HUMINT-first

The method always starts from conversations, observation and the factual operational reality of an organisation, never from a pre-filled questionnaire or a fixed set of controls. Interviews with key functions (management, security, IT operations) generate the first signals; technical validation is then scoped to follow up on what those conversations actually surfaced, not a generic checklist.

Three phases

Phase 1

Insight & analysis

Interviews, document review and a high-level technical quickscan produce a commercially relevant risk picture: top risks, critical gaps, and a first maturity indication. Deliberately not a full validation: a starting point, not an end point.

Phase 2

Technical validation

Findings from Phase 1 are confirmed, quantified and deepened: technical review, incident-response testing, backup/recovery validation, supply-chain risk review, and an explicit test against NIS2 requirements. Every finding carries an evidence reference.

Phase 3

Implementation roadmap

Findings become a prioritised, owned improvement plan, with quick wins (achievable within roughly 30 days) separated from structural, longer-term measures and their dependencies.

Reference frameworks

How it is anchored

ISO/IEC 27001 as an existing control baseline, CISSP domains as a structuring framework, and the NIS2 directive (EU 2022/2555) as the regulatory test, without duplicating what a valid certification already confirms.

Digital validation via Mosaic

Where useful, later-stage validation and awareness work is supported digitally through Mosaic, QWASP's Moodle-based execution environment (part of the Qwasp Education line). Mosaic supports the method. It does not replace the HUMINT-based interview rounds, and it is not itself audit evidence toward a supervisory authority.

Implementation mechanics, interview scripts and internal templates are confidential and not published here.