Platform · Consulting · Advisory

Products & Services

From a purpose-built EU compliance SaaS platform to hands-on consulting, Tools of Tech delivers enterprise-grade cybersecurity and AI governance capabilities to organisations across Europe.

Building Management · Defense & Government

α²Buildings

Sovereign, on-premise building management for defense and government estates. KNX, BACnet, Modbus and DALI-2 — one console, no cloud dependency, air-gap capable.

Full overview
01

On-premise & air-gap capable

Fully self-contained deployment — no external telemetry, no cloud dependency, signed offline update path.

02

Vendor-neutral protocol support

KNX, BACnet, Modbus and DALI-2 on the same console. Existing plant stays; new hardware extends it.

03

IEC 62443 & NIS2 aligned

KNX Data Secure and KNX IP Secure end-to-end, RBAC, MFA, full audit trail and SIEM export.

04

Resilient by design

Decentralised KNX field logic keeps every room running even if the head-end or network segment goes dark.

05

Energy & EED reporting

Per-building metering, demand-controlled HVAC, and EED-ready consumption reports for ELECTRA-funded upgrades.

06

Local delivery & support

Delivered with certified KNX integration partners. Engineering and support in English and Greek.

AgileAEGIS logo

Powered by AgileAEGIS

AgileAegis Ltd, The Hague

From barracks block to island outpost — one sovereign platform.

Barracks, headquarters, hangars, military hospitals, remote island installations and public ministry buildings — all on the same console, inside your perimeter.

Platform Product

CyberResilience360

One platform. Three EU frameworks. Audit-grade evidence. Unified compliance for the NIS2 Directive, Commission Implementing Regulation 2024/2690, and DORA — in a single multi-tenant SaaS built for European enterprises and critical entities.

Launch Platform
3EU Frameworks
300+Mapped Controls
100Art. 21 Cyber Risks
27Member States

NIS2 Directive (2022/2555)

41 control objectives · 107 atomic controls

CIR 2024/2690

Digital infrastructure & ICT service management

DORA (EU 2022/2554)

155 controls · scope-aware applicability tagging

Art. 21 Risk Register

100-entry pre-seeded risk library · residual scoring

Incident Reporting

24h early warning · 72h notification · 1-month final report

Evidence & Audit Vault

Sign-off-ready documentation · tamper-evident audit trail

Supply Chain Risk

Supplier questionnaires · ICT third-party register (DORA)

Compliance Analytics

Real-time dashboards · risk heat maps · gap analysis

How It Works

01

Onboard

Classify your sector and entity type with the guided onboarding wizard. Financial-sector tenants run the DORA scope wizard.

02

Assess

Run unified assessments across NIS2, CIR, and DORA — each scoped automatically to your applicability profile.

03

Remediate

Generate and manage remediation tasks with priority-based workflows, due dates, owners, and Gantt-style project planning.

04

Report

Produce print-ready, sign-off-ready audit-grade reports with Article 21 measure coverage and audit-readiness scoring.

See also: Critical Entity Resilience (CER) Advisory — extend your NIS2 compliance programme to cover all-hazards physical and organisational resilience.

Consulting Service

Cybersecurity Maturity Assessments

Understanding where you stand is the first step to building genuine cyber resilience. Our structured maturity assessments benchmark your organisation against leading frameworks and deliver a clear, actionable picture of your security posture.

Delivered by certified practitioners with deep EU regulatory expertise, our assessments go beyond checkbox compliance to identify structural vulnerabilities, governance gaps, and supply chain exposures.

Request an Assessment
Foundation01

Gap analysis against NIS2 / ISO 27001 / NIST CSF

Deliverable: Executive summary + prioritised remediation roadmap

Advanced02

Deep-dive technical & governance assessment across all domains

Deliverable: Full maturity scorecard · risk register · board-ready report

Continuous03

Ongoing quarterly assessments with trend tracking

Deliverable: Maturity progression reports · regulatory readiness dashboard

Frameworks & Standards Covered

NIS2 DirectiveISO/IEC 27001:2022NIST CSF 2.0CIS Controls v8.1DORACIR 2024/2690ENISA GuidelinesEU Cyber Resilience Act

See also: Critical Entity Resilience (CER) Advisory — all-hazards resilience assessment integrated with your NIS2 posture.

Consulting · CER Directive (EU) 2022/2557

Resilience beyond cybersecurity.

All-hazards resilience advisory for the entities that keep society running — aligned to the EU Critical Entities Resilience Directive and integrated with your NIS2 obligations.

Assess your CER exposure

The challenge

Europe's resilience agenda no longer stops at cybersecurity. Where NIS2 protects the digital layer, the Critical Entities Resilience (CER) Directive governs the physical and organisational resilience of critical entities against an all-hazards spectrum — natural disasters, sabotage, insider threats and hybrid attacks. Across the EU, national competent authorities designate critical entities in eleven sectors; once designated, an entity must complete an all-hazards risk assessment, maintain a resilience plan, appoint a liaison to the authority, apply personnel background checks, and notify significant incidents within 24 hours. Most organisations are well advanced on the cyber side and materially unprepared for the physical and organisational half. We close that gap — and make CER and NIS2 run as a single programme, not two.

Who this is for

Operators of essential services across energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space and food — and the public authorities that supervise them, in any EU Member State.

Why Tools of Tech

Deep expertise in the EU directives and their national transpositions; the only advisory pairing CER physical and organisational resilience with a NIS2/CIR/DORA compliance platform, so identification, assessment and evidence live in one place; EU-sovereign, Athens-based, ECSO Full Member.

Our CER services

Designation & scoping readiness

A public-data-driven screening of whether your organisation is likely to be designated a critical entity, with a documented likelihood assessment and evidence trail.

All-hazards risk assessment

The CER-mandated assessment of natural, man-made, hybrid, insider and sabotage risks, delivered to the post-designation deadline and reusable across your existing risk framework.

See also: Maturity Assessments

Resilience plan development

Prevention and disaster-risk reduction, physical protection, response and crisis management, recovery and business continuity, personnel security and staff awareness, documented as an audit-ready plan.

Personnel security & background-check framework

Lawful, GDPR-aligned vetting for sensitive, remote and control-system roles, including external service-provider staff.

Incident notification & liaison setup

The 24-hour notification runbook, significance thresholds, and the single point of contact with the competent authority.

Integrated CER + NIS2 programme

One control set, shared evidence, no duplication, because a CER-designated entity is automatically in NIS2 scope.

Manage via CyberResilience360

Resilience maturity monitoring

Ongoing measurement and reporting through our CyberResilience360 platform, extended to CER resilience controls.

CyberResilience360 platform

Board & management enablement

Executive briefings and the management-accountability documentation the regime now demands.

Advisory Service

AI Governance Services

As the EU AI Act reshapes the regulatory landscape, organisations need more than compliance checklists — they need a governance architecture that embeds responsibility, transparency, and accountability into every AI system they build or procure.

Speak to an Expert

EU AI Act Readiness

Classification of AI systems by risk tier, conformity assessment preparation, and documentation for high-risk systems under Regulation (EU) 2024/1689.

AI Risk Management

Structured risk identification, bias auditing, explainability frameworks, and human-oversight protocols aligned to ISO/IEC 42001.

Data Governance & Ethics

Data lineage mapping, GDPR-aligned data governance policies, and ethical AI principles embedded into procurement and deployment workflows.

Public Sector AI Strategy

Advisory for government bodies on responsible AI adoption, algorithmic transparency, and citizen-facing AI service design.

Regulation (EU) 2024/1689

EU AI Act — Now in Force

The world's first comprehensive AI regulation entered into force in August 2024. High-risk AI systems face mandatory conformity assessments, technical documentation, and human oversight requirements. Tools of Tech helps you classify your AI systems, prepare conformity documentation, and build the governance structures required for full compliance.

Ready to strengthen your cyber resilience?

Whether you need the CyberResilience360 platform, a maturity assessment, or AI governance advisory — our team is ready to help.