At MOATUS we leverage technical understanding of IT and cyber to translate technical risk and regulatory pressure into quantified business impact and clear, executable priorities.
We focus on measurable outcomes: improved resilience, reduced risk exposure and secure‑by‑design delivery that enables growth rather than blocks it.
Clients value our analytical rigour, no-nonsense pragmatism and ability to cut through complexity.

Our name
The name MOATUS reflects our vision on digital security. It is a portmanteau of the English moat (the protective trench surrounding a fortress). Additionally, it is a deliberate nod to talus (an unshakeable foundation) and impetus (a forward driving force).
To us, this means that robust security and risk management are not obstacles. Instead, they form the secure foundations that give your organisation the confidence and momentum to innovate and grow unhindered.
Our way of working - MOATUS OPERANDI
Large consultancy firms often deliver abstract presentations. Purely technical providers often miss the bigger picture. We bring these worlds together through four core principles:
- Value and risk as compass: We speak the language of both technology and the boardroom. We link ‘business value’ and risks directly to your daily operations. This means we always view processes, IT systems and controls holistically, balancing how they optimally align with risk reduction and value creation.
- Advice to execution: We understand the business and technical implications of adjusting processes or governance structures. We know and recognise the complexity of actual implementations from our own experience, providing the reality check necessary to tackle risks cost-effectively. With a healthy dose of creativity, we ensure a strategy does not just remain on paper but is actionable in practice.
- Creative resilience: We look beyond the beaten track. How do we increase your resilience, also in collaboration with suppliers and supply chain partners? We are not hindered by the status quo. Sometimes a paper-based process is safer. Sometimes moving away from a massive IT system is the smartest choice. Sometimes doing nothing is an option. We seek the best solution for you, not the most obvious one.
- Radically honest and always bespoke: We do not do copy-paste or lip-service. If we receive a question that does not address the core issue? We say so. We always consider your specific context and risk profile. We honestly weigh the costs and benefits of every solution. Sometimes it is simply not the right time (or the right investment) to solve a particular puzzle.
Our experience
MOATUS Risk Advisory builds on more than 16 years of specialist experience in IT, privacy and cyber risk management.
Founder Job van Ommen spent years as a Director member of the leadership within the cyber team of a Big Four firm. In this role, he led large-scale cyber transformation programmes, particularly for major (international) financial institutions.
His expertise spans the full spectrum: from advising at board level and designing target architectures, to the practical implementation of security standards (such as NIST CSF and ISO 27K) and translating complex legislation (including DORA and NIS2) to the operational level..
MOATUS brings you the in-depth knowledge, methodology and attitude of a Big Four firm, combined with the agility and personal dedication of a specialist boutique.