A senior-led GRC advisory
built on real-world experience.
Boutique by design, senior by default — built for organisations where trust, resilience and regulatory confidence are non-negotiable. Discover Our Services call_made

Who we are

NOVUMCYBER is a boutique Governance, Risk and Compliance firm specialising in cybersecurity, privacy, IT assurance and AI governance. From our base in Cyprus, we help regulated and growth-stage organisations across the EU and other regulated jurisdictions turn a tangle of overlapping regulations into one clear, defensible posture.

We believe security, privacy and trustworthy AI are not just compliance requirements but business enablers that drive resilience, trust and long-term growth.

Our founder

NOVUMCYBER is led by founder Constantinos Koumides — a Governance, Risk and Compliance professional with more than 15 years across Big 4 advisory, banking security leadership and technology-sector compliance. He has held the most senior information-security seat inside regulated EU banks — reporting to the board risk committee — led cyber, privacy and SOC 2 assurance engagements at a Big 4 firm, and built ISO 27001-certified programmes from the ground up. Today he serves clients as a fractional CISO (vCISO) and Data Protection Officer (vDPO), guiding them through ISO 27001, ISO 42001, SOC 2, GDPR, DORA, NIS2 and the EU AI Act.

He holds an MSc in Information Security from Royal Holloway, University of London, and completed the Oxford Artificial Intelligence Programme at Saïd Business School. His certifications include CISA, CIPP/E, ISO 27001 Lead Implementer and ISO 27032 Lead Cybersecurity Manager, and he serves as President of ISACA Cyprus.

Who we serve

Our primary focus is on organisations operating in regulated and high-accountability environments, including:

Financial services: Startup and scaling regulated firms such as banks, electronic money institutions, fintech companies, forex firms, insurers, investment firms, and crypto businesses.

Technology providers: Organisations delivering infrastructure, platforms, software, and services to regulated industries, including IT providers, CRM platforms, and payroll solutions.

Operators of essential & important services: organisations in other regulated sectors with obligations under EU and national rules.

While our expertise is deeply rooted in regulated sectors, our services apply horizontally across industries where risk, governance, and compliance are business-critical.

How we work

One governance model, one risk register and one control framework — mapped across DORA, NIS2, GDPR, the EU AI Act, ISO 27001, ISO 42001, SOC 2 and NIST, so a single control can answer to several obligations at once. Less duplication, and a posture that scales as new obligations arrive.

Let’s Talk About Your
Digital Risk Challenges

Facing a new regulatory obligation, preparing for an audit, or in need of a senior advisor who has held the seat? Tell us where you stand, and we’ll come back to you, plainly, on scope and approach — and, once we understand the detail, a fair fee estimate.

CONTACT DETAILS

Email:        contact@novumcyber.com
Phone:      +357 94 003336
Address:   Nicosia, Cyprus


A senior-led GRC advisory
built on real-world experience.
Boutique by design, senior by default — built for organisations where trust, resilience and regulatory confidence are non-negotiable. Discover Our Services call_made

Who we are

NOVUMCYBER is a boutique Governance, Risk and Compliance firm specialising in cybersecurity, privacy, IT assurance and AI governance. From our base in Cyprus, we help regulated and growth-stage organisations across the EU and other regulated jurisdictions turn a tangle of overlapping regulations into one clear, defensible posture.

We believe security, privacy and trustworthy AI are not just compliance requirements but business enablers that drive resilience, trust and long-term growth.

Our founder

NOVUMCYBER is led by founder Constantinos Koumides — a Governance, Risk and Compliance professional with more than 15 years across Big 4 advisory, banking security leadership and technology-sector compliance. He has held the most senior information-security seat inside regulated EU banks — reporting to the board risk committee — led cyber, privacy and SOC 2 assurance engagements at a Big 4 firm, and built ISO 27001-certified programmes from the ground up. Today he serves clients as a fractional CISO (vCISO) and Data Protection Officer (vDPO), guiding them through ISO 27001, ISO 42001, SOC 2, GDPR, DORA, NIS2 and the EU AI Act.

He holds an MSc in Information Security from Royal Holloway, University of London, and completed the Oxford Artificial Intelligence Programme at Saïd Business School. His certifications include CISA, CIPP/E, ISO 27001 Lead Implementer and ISO 27032 Lead Cybersecurity Manager, and he serves as President of ISACA Cyprus.

Who we serve

Our primary focus is on organisations operating in regulated and high-accountability environments, including:

Financial services: Startup and scaling regulated firms such as banks, electronic money institutions, fintech companies, forex firms, insurers, investment firms, and crypto businesses.

Technology providers: Organisations delivering infrastructure, platforms, software, and services to regulated industries, including IT providers, CRM platforms, and payroll solutions.

Operators of essential & important services: organisations in other regulated sectors with obligations under EU and national rules.

While our expertise is deeply rooted in regulated sectors, our services apply horizontally across industries where risk, governance, and compliance are business-critical.

How we work

One governance model, one risk register and one control framework — mapped across DORA, NIS2, GDPR, the EU AI Act, ISO 27001, ISO 42001, SOC 2 and NIST, so a single control can answer to several obligations at once. Less duplication, and a posture that scales as new obligations arrive.

Let’s Talk About Your
Digital Risk Challenges

Facing a new regulatory obligation, preparing for an audit, or in need of a senior advisor who has held the seat? Tell us where you stand, and we’ll come back to you, plainly, on scope and approach — and, once we understand the detail, a fair fee estimate.

CONTACT DETAILS

Email:        contact@novumcyber.com
Phone:      +357 94 003336
Address:   Nicosia, Cyprus