Personal Territory Notes — Cordaata (Antwerp, Belgium) — Corrected Company
New Rep · Zero-to-Pipeline Playbook

Your Cordaata Territory

Cordaata is a 2–10 person cyber-risk-quantification startup out of Antwerp, founded in 2025 — you're not walking into an established brand with a logo wall. What you do have: a real product mechanism, and the biggest regulatory tailwind cybersecurity vendors have seen in years landing right now, in your own backyard.

0NIS2-Registered Entities in Belgium
0ISACA Belgium Members to Reach
0Max NIS2 Fine, Essential Entities
0Belgian Cyber Conferences, Sep–Nov 2026
Role
New Business Development Rep
Company
Cordaata (cordaata.com)
HQ
Antwerp, Belgium — founded 2025
Current Pipeline
0 accounts — Day 1
01

What You're Actually Selling

Cordaata: "Know what matters. Protect what counts." — a cyber-risk-quantification (CRQ) platform that turns technical security posture into financial and board-level language. Founded 2025, headquartered in Antwerp, Belgium, currently 2–10 employees, carrying a "Software Made in Europe" certification. No leadership names, funding round, or named customer are publicly listed anywhere — treat this as a true early-stage startup, not an established vendor with a logo wall to lean on.

The MechanismThe FORRI Framework

  • Cordaata ingests data across every business process, system, data asset, service, and dependency in an organization — not a generic template applied to everyone the same way.
  • Each entity gets a FORRI impact profile — Financial, Operational, Reputational, Regulatory, IP & Data — then relevant risk scenarios are identified specifically for how that system is actually used, not from a generic library.
  • Scenarios run through a quantification engine calibrated against published, sector-specific incident data, producing Annualized Loss Expectancy (ALE) at the scenario, system, and organization-wide level, plus control-maturity scoring.

The Four PillarsWhat You Have to Sell

  • Risk Visibility — enterprise-wide risk landscape, modeled on how the business actually operates.
  • Cyber Risk Quantification — ALE, breach-cost breakdowns, threat-actor detail, per scenario.
  • Regulatory Compliance — mapping risk posture to compliance obligations.
  • Board Reporting — translating all of the above into language a board or executive team can act on.

The Real InsightYou're Selling to Personal Liability, Not Just Risk

  • Cordaata's own site names its buyers directly: CISOs, security leaders, executive teams, and virtual CISOs/consultants.
  • Its own blog content leans hard into board-facing framing — titles like "Cyber Risk in Financial Terms: A CFO Dashboard Guide for CISOs" and "The Strategic CISO: From Gatekeeper to Business Growth Enabler." That tells you the pitch: help a CISO stop being the person who says no, and start being the person the board trusts with numbers.
  • As you'll see in tab 03, a new EU law just made board members personally liable for exactly this — which is the single biggest reason to buy a tool like this right now, not "someday."

Handle With CareYou Have No Case Studies Yet — Lean on the Mechanism

  • No named customers, no funding announcement, no press coverage of any kind was found for Cordaata. That's normal for a 2–10 person, 2025-founded company — but it means you cannot open with "here's who trusts us."
  • Real, named competitors in the cyber-risk-quantification space — Kovrr, Axio, Citalid, DeNexus, Safe Security, RiskLens, FortifyData, and France's C-Risk — are all better-funded and more established. Your honest differentiators are the "Made in Europe" data-sovereignty angle and being small enough to move fast for an early customer. Don't pretend the competitive gap isn't there.
02

Is This Organization a Good Fit?

Score any prospect on these five things. An org with zero of these is a waste of your first 90 days.

Regulatory Exposure

Is it in scope for NIS2 or DORA — 50+ staff and €10M+ revenue, in an expanded list of sectors, or an EU financial-sector firm?

Existing Security Role

Does it already have a CISO, security lead, or retained vCISO — someone whose job gets easier with a quantification tool, not someone starting from zero?

Board Anxiety

Is leadership newly aware they're personally liable for cyber-risk oversight under NIS2 Article 20 or DORA?

EU-Sovereignty Preference

Does it care about data residency or "Made in Europe" software — public-sector-adjacent, critical infrastructure, or simply GDPR-cautious?

Reachable Buyer

Can you name an actual security leader, or a vCISO/consultancy serving them, within two LinkedIn connections?

Buyer Category 1 — DirectThe In-House CISO or Security Leader

  • Who: a named CISO or "Head of Information Security" at a mid-market company (roughly 50–2,000 employees) newly in scope for NIS2.
  • What a "yes" looks like: a security leader who already reports informally on risk but has no consistent, defensible financial number to give the board.

Buyer Category 2 — ChannelvCISO Consultancies & MSSPs

  • Who: firms selling fractional CISO services to multiple SME/mid-market clients — Cordaata names "virtual CISOs and consultants" as a target audience directly on its own site.
  • Why this matters more for a 2-person startup: one signed vCISO partner can put the platform in front of a dozen end-clients at once — the fastest path to volume without a large sales team.

Buyer Category 3 — ChannelNIS2/DORA Compliance Consultancies

  • Who: firms running formal NIS2/DORA gap assessments for clients (Big 4 practices, boutique GRC consultancies) who need a quantification engine to plug into their own engagements rather than build one.
  • What a "yes" looks like: a consultancy currently delivering gap assessments with spreadsheets, open to white-labeling or reselling a purpose-built tool.

Buyer Category 4 — EmergingCyber Insurance Brokers & Underwriters

  • Who: brokers and underwriters increasingly asking commercial clients for quantified risk data before binding or renewing cyber policies.
  • Why it fits: ALE output is exactly the kind of number an underwriter can use — a genuinely underexplored channel worth testing, not yet confirmed as an active Cordaata motion.
03

Your Product's Strength vs. Their Structural Weakness

Every good pitch is one strength curing one weakness. Here's the exact pairing to build every conversation around — everything else in this playbook is just logistics for getting this sentence in front of the right person.

Product StrengthBespoke, Board-Credible Numbers

  • Cordaata's FORRI engine doesn't score an organization against a generic template — it models risk on how that specific business actually operates: its real systems, dependencies, and revenue-generating processes.
  • The output is a single financial figure — Annualized Loss Expectancy — calibrated against published, sector-specific incident data. That's the strength: it converts a technical, defensive function into a number the board already knows how to act on, because it's denominated in money, not risk-matrix colors.

Customer WeaknessA Deadline Cleared, Not a Practice Built

  • Most NIS2-scoped mid-market organizations hit Belgium's April 18, 2026 verification deadline with a one-off consultant gap assessment or a static checklist — a compliance snapshot, not a living, continuously updated risk narrative.
  • Their real vulnerability isn't a missing control — it's that when a board member, auditor, or cyber-insurance underwriter asks "prove you're managing this," most of them have a folder that says they did something once, and no number they can defend today.

Secondary WeaknessThe CISO's Own Credibility Gap

  • This is personal, not just organizational: Cordaata's own content — "The Strategic CISO: From Gatekeeper to Business Growth Enabler" — is built around the fact that most security leaders are seen internally as a cost center that says no, not a strategic voice the board trusts.
  • That's a real, separate self-interest lever from the compliance one: the same tool that fixes the board's exposure also fixes the CISO's own standing in the room. Sell to both motives at once.

The Thesis, One LineSay This, Almost Verbatim

  • "You didn't fail to comply — you complied with a snapshot. Cordaata turns that snapshot into a living number your board can actually defend every quarter, calibrated to how your business specifically runs, not a generic template."
  • This single sentence is the diagnostic question and the pitch at once — it works as a cold-open line, a follow-up after a conference conversation, and the frame for a discovery call.
04

The RACE Plan — Reach, Act, Convert, Engage

Built around the reality of a 2-person, pre-case-study startup: small, bounded first asks, not enterprise-wide commitments — proof comes from one real number, not a sales deck.

DIAGNOSTIC OPEN → RISK-SNAPSHOT PILOT → SIGNED FIRST CONTRACT → REFERENCEABLE EXPANSION 01 REACH Ask the one-line diagnostic question 02 ACT Offer a free, scoped risk-snapshot on 1 system 03 CONVERT Snapshot becomes a paid first contract 04 ENGAGE Expand org-wide; win your first case study YOU ARE HERE
You have zero deals and zero case studies today — this loop is designed to produce your first referenceable customer, not to land a large enterprise contract out of the gate.

01 · ReachOpen With the Diagnostic, Not the Product

  • Objective: get the one-line thesis (tab 03) in front of a named CISO, vCISO, or consultancy — via the real doors mapped in tab 06 (ISACA Belgium, ICTLAB, the Belgian conferences this fall).
  • Do this: ask whether their post-deadline compliance work produced an actual number their board saw, or just a checklist. Let their answer tell you which weakness (organizational or personal) to lean on next.
  • Avoid: opening with a feature list or the FORRI acronym — nobody outside your own team cares about the mechanism before they care about the pain it fixes.

02 · ActTurn the Open Into a Bounded Pilot

  • Objective: a small, free, or low-cost ask — not a full-platform commitment a 2-person startup can't yet support at scale anyway.
  • Do this: offer to run one real business-critical system or process through the FORRI model and hand back a genuine ALE number within an agreed timeframe — proof by demonstration, not by deck.
  • Success metric: a scoped snapshot accepted, with a named system and a delivery date.

03 · ConvertTurn the Snapshot Into a Signed Contract

  • Objective: one paid engagement — your first, so treat the commercial terms as flexible in service of getting it signed.
  • Do this: when you deliver the snapshot, frame the next step explicitly around the weakness it exposed — "here's the one number your board saw; here's what a live, quarterly version of this looks like."
  • Success metric: a signed contract, ideally with an explicit or implied right to reference them once results land.

04 · EngageTurn One Customer Into Your First Case Study

  • Objective: convert your very first deal into the proof point every future "Reach" conversation currently lacks.
  • Do this: expand from the pilot system to org-wide coverage; ask directly for a reference or testimonial once there's a real result; if the first win came through a vCISO or consultancy, ask them to formalize the relationship into a repeatable channel rather than a one-off referral.
  • Success metric: a named, referenceable customer you can cite in the very outreach scripts in tab 08 — closing the loop this playbook opened with "you have no case studies yet."
05

The Regulatory Wave — Why Now, Specifically

This is the single most important thing to understand about your market: you're not selling into a hypothetical "someday we should quantify risk" conversation. Two EU laws just made this a legal, board-level, personally-liable obligation — and one deadline has already passed.

NIS2 DirectiveBoard Members Are Now Personally on the Hook

  • Scope: any organization with 50+ employees and €10M+ revenue across an expanded sector list — no longer just tech, now including manufacturing, food, waste management, energy, transport, water, health, digital infrastructure, and public administration.
  • Board liability: Article 20 makes management bodies personally accountable for approving and overseeing cyber-risk-management measures — failure can mean fines and even temporary bans from management roles. Article 23 imposes a strict 24-72-30 hour incident-reporting timeline.
  • Fines: up to €10M or 2% of global turnover for "essential entities."
  • Belgium specifically: the national verification deadline was April 18, 2026 — 18 months after the law took effect — by which essential entities had to show a recognized compliance pathway. That date has already passed as of this playbook. Belgium has registered roughly 1,500 essential entities and 2,500 important entities — a real, named, ~4,000-organization addressable market in Cordaata's own home country.

DORAAlready Live for EU Financial Services

  • The Digital Operational Resilience Act has been in force since January 2025 for EU banks, insurers, and fintechs — meaning financial-sector prospects aren't waiting for a future deadline, they're already supposed to be compliant now.
  • DORA and NIS2 overlap heavily on risk-management-framework and board-reporting requirements — a single Cordaata pitch can often address both at once for a financial-sector prospect.

Why "Made in Europe" Is a Real HookNot Just a Badge

  • NIS2's push for supply-chain and third-party risk management, combined with general EU data-sovereignty sentiment, makes a genuinely EU-headquartered, EU-hosted vendor a real point of difference against US-based CRQ platforms like Kovrr, Axio, or RiskLens for data-residency-sensitive buyers.
  • This is most persuasive with public-sector-adjacent organizations, critical-infrastructure operators, and any prospect that's already nervous about US CLOUD Act exposure.

The Honest CaveatA Deadline Already Passed Cuts Both Ways

  • Because Belgium's April 2026 verification deadline has passed, some prospects will already have picked a compliance pathway — possibly a spreadsheet, a consultant, or a competitor. "First to market" isn't guaranteed; "still looking for something better" is a real and common state after a rushed first pass at a new regulation. Lead discovery calls by asking what they used to hit the deadline, not by assuming they have nothing.
06

How to Actually Find Them

For a 2-person startup with no case studies, the fastest path to a pipeline is real associations and channel partners in your own home market — not cold-calling a purchased list.

JoinISACA Belgium Chapter

  • 850+ members from 450+ organizations — the largest Belgian association for governance, risk, and compliance professionals. Runs Belgium's Cyber Security Awards (with a dedicated CISO Award) and regular networking events.
  • This is the single highest-density room of exactly the people Cordaata sells to, in Cordaata's own city.

WatchThe Centre for Cyber Security Belgium (CCB)

  • Belgium's national NIS2 regulator (ccb.belgium.be) publishes the actual registered-entity counts, deadlines, and enforcement updates directly — the authoritative source for exactly how urgent this is at any given moment.

Show UpNamed, Dated Events

  • Belgium alone runs 8 cybersecurity conferences between mid-September and mid-November 2026, including Cybersec Europe and BruCON.
  • The Benelux Cyber Summit (Amsterdam, recurring) is a cross-border option if Netherlands prospects are also in scope.
  • Belgium's Cyber Security Coalition is a second major association worth joining alongside ISACA Belgium.

Partner WithNamed NIS2/vCISO Consultancies

  • ICTLAB (Brussels) — works with Belgian SMEs and scale-ups on NIS2, GDPR, and ISO 27001; publishes its own public NIS2 readiness checklist.
  • EY Belgium — runs formal NIS2 compliance assessments and implementation support for larger clients.
  • In the Netherlands: NIS2 Safe (Logicle B.V.), ISO2700x, and New Paradigm Security (vCISO services) all run NIS2 gap-assessment and vCISO practices that could plug Cordaata in as their quantification layer.

Search SmartLinkedIn

  • Title-search: CISO, Head of Information Security, IT Risk Manager, Chief Risk Officer at Belgian/Benelux companies with 50–2,000 employees in NIS2-expanded sectors (manufacturing, food, energy, transport, health).
  • Separately search virtual CISO, fractional CISO, NIS2 consultant to find channel-partner candidates directly.

ContentRepurpose the Existing Blog

  • Cordaata already has real, on-message blog content — "Tiered Risk Analysis," "Security Metrics & Governance," "Proactive Security Capacity Planning" — built for exactly this buyer. Share it directly into ISACA Belgium and Cyber Security Coalition channels rather than writing new material from scratch.
07

Your Real Starter Pipeline

Honest framing: no public source names specific NIS2-scoped companies actively shopping for a CRQ tool, so this dossier won't invent a list of named target companies the way a more mature account's public record might support. What's actually real and actionable is the set of doors below — work these first, and named end-customer leads will come out the other side of them.

Tier 1

Contact This Week

#DoorTypeWhy It's First
1ISACA Belgium ChapterAssociation850+ GRC professionals, 450+ organizations, hosts a dedicated CISO award — highest-density room of your exact buyer, in your home city.
2ICTLAB (Brussels)Consultancy / ChannelAlready runs NIS2 readiness work for Belgian SMEs and scale-ups — a natural first channel-partner conversation.
3Belgium's Cyber Security CoalitionAssociationSecond major national association; publishes its own public NIS2 resources.
4Cybersec Europe / BruCON (Sep–Nov 2026)EventDated, imminent, and local — the fastest way to have 20 real conversations in one week.
Tier 2

Build Toward

#DoorTypeWhy It's Next
5EY Belgium (NIS2 practice)Consultancy / ChannelLarger, slower-moving than ICTLAB, but a bigger potential client volume if a partnership lands.
6NIS2 Safe (Logicle B.V.), NetherlandsConsultancy / ChannelDutch-market equivalent to ICTLAB — expands beyond Belgium into the wider Benelux.
7ISO2700x, NetherlandsConsultancy / ChannelRuns NIS2 scope and gap analysis plus vCISO services — a second Dutch channel candidate.
8New Paradigm Security, NetherlandsvCISO / ChannelA vCISO practice by design — directly matches Cordaata's named "virtual CISO" buyer category.
9Benelux Cyber SummitEventCross-border event if the Netherlands becomes part of your territory alongside Belgium.
Where Named End-Customers Come From

Once you're inside ISACA Belgium or a consultancy partnership, ask directly who in the room is still without a locked-in compliance pathway after the April 2026 deadline — that single question, asked in person at an event or a chapter meeting, will surface real, named, currently-shopping prospects faster than any desk research could from the outside.

08

First-Touch Scripts

Rehearsal scripts, not real quotes — adapt once you have a named contact.

01

In-House CISO — Cold Outreach

LinkedIn / Email

Lead with the deadline that just passed, not a generic product pitch — it's specific, current, and assumes they've already done something (even if imperfect).

YOU —Hi [Name], with Belgium's April NIS2 verification deadline behind us, I'm curious how your board conversations about cyber risk have changed since Article 20 made oversight personally your management team's liability. I'm with Cordaata — we turn security posture into an actual financial number (Annualized Loss Expectancy) boards can act on, calibrated to your specific systems rather than a generic framework. Worth 15 minutes to see whether what you used to hit the deadline is still working for you six months on?
02

vCISO / Consultancy — Channel Pitch

Call

This is a partner pitch, not an end-user pitch — the value is volume, not a single seat.

YOU —You're running NIS2 gap assessments for multiple clients right now — I'd guess a lot of that quantification work is still manual or spreadsheet-based. Cordaata is a Belgian-built risk-quantification engine that could sit underneath your assessments as the numbers layer, so your reports carry an actual calibrated ALE figure instead of a qualitative score. Open to a walkthrough to see if it fits how you deliver engagements today?
03

Association — Membership Introduction

In Person

Not a pitch at all — this is how you get into the room in the first place.

YOU —I'm new to Cordaata, a Belgian cyber-risk-quantification startup, and honestly still building out who in this room has already found a good answer to the NIS2 board-reporting requirement versus who's still patching something together. Happy to compare notes rather than pitch anything today — who else here would you point me toward?
  1. Before any call: confirm the contact's actual title and whether their organization is confirmed NIS2-scoped (size + sector) — don't assume.
  2. After first contact: send one relevant Cordaata blog post matched to their role (CFO-dashboard piece for a CISO who needs board buy-in, capacity-planning piece for an operationally stretched team).
  3. If no response in 5 business days: follow up once with a different angle — a new blog post, or an event you'll both be at — never a bare "just checking in."
09

Your First 90 Days

Sequenced around the real, dated events and named doors above.

  1. Days 1–15: Join ISACA Belgium and Belgium's Cyber Security Coalition; register for at least one of the 8 Belgian cybersecurity conferences running September–November 2026; ask Cordaata's founders directly for any warm contacts at ICTLAB or EY Belgium.
  2. Days 16–45: First outreach wave — one channel-partner conversation each with ICTLAB and one Netherlands-based vCISO firm; attend your first association event and collect names, not just business cards.
  3. Days 46–75: Follow up on event conversations; run the "who's still shopping post-deadline" question at every association touchpoint; aim for 2–3 real discovery calls booked with named end-users surfaced this way.
  4. Days 76–90: Bring your strongest lead — whether an end-customer or a channel partner — back to Cordaata's founding team for a joint call once it's warm enough to matter.
  5. Ongoing: Re-check the CCB's published NIS2 enforcement and registration updates monthly — this regulatory wave is still moving, and it's your best source of new trigger events.
10

Sources

Cordaata's own facts (founding year, headquarters, employee count, product mechanism, blog content) come directly from cordaata.com and its LinkedIn company page — not guessed. No named founders, funding round, or customer/case study could be found anywhere public as of this writing; that absence is stated plainly rather than filled in. NIS2 and DORA details come from the Centre for Cyber Security Belgium (ccb.belgium.be), the official NIS2 directive tracking site, and multiple independent compliance-industry summaries — cross-checked where more than one source was available. Named consultancies and associations (ISACA Belgium, Cyber Security Coalition, ICTLAB, EY Belgium, NIS2 Safe/Logicle, ISO2700x, New Paradigm Security) are real, current organizations as of this research, not invented placeholders — verify current contacts and offerings directly before outreach, since consultancy service lines and event calendars change. Competitor names (Kovrr, Axio, Citalid, DeNexus, Safe Security, RiskLens, FortifyData, C-Risk) are corroborated across more than one independent source and treated as reasonably reliable, unlike the unreliable, non-overlapping aggregator-sourced competitor lists this playbook's prior (incorrect-company) draft relied on. First-touch scripts are rehearsal material only.