OR
Over OranjeRaksha
About OranjeRaksha

Wie staat er achter
OranjeRaksha?
Who stands behind
OranjeRaksha?

Een gespecialiseerde security-praktijk opgericht door Sandeep Sharma, CISA-gecertificeerd professional en gecertificeerd cyberforensisch expert met meer dan 19 jaar ervaring in het beschermen van organisaties in Europa, India, APAC en de Amerika's. Dit is het verhaal achter de naam, de filosofie en de aanpak.

A specialised security practice founded by Sandeep Sharma, CISA-certified professional and certified cyber forensics expert with over 19 years of experience protecting organisations across Europe, India, APAC and the Americas. This is the story behind the name, the philosophy and the approach.

CISA
gecertificeerd
certified
19+
jaar in het vak
years in the field
IT · OT
beide werelden
both worlds
4
continenten
continents
De naam achter het merk
The name behind the brand

Twee werelden. Één belofte.

Two worlds. One promise.

De naam OranjeRaksha is bewust gekozen en verbindt twee tradities die onze identiteit vormen: Nederlandse nuchterheid en tijdloze bescherming.

The name OranjeRaksha is deliberately chosen, connecting two traditions that define who we are: Dutch clarity and timeless protection.

🇳🇱
Oranje
Nederlands · Het Huis van Oranje
Dutch · The House of Orange

Oranje staat voor Nederland: geschiedenis, innovatie en de mentaliteit om samen te beschermen wat belangrijk is. Het is het symbool van veerkracht, nuchterheid en verantwoordelijkheid. De kleur van een land dat weet hoe je dingen voor elkaar krijgt.

Oranje represents the Netherlands: history, innovation and the collective drive to protect what matters. It stands for resilience, clarity and accountability. The colour of a country that knows how to get things done.

रक्षा
Raksha
Sanskriet (रक्षा) · Bescherming
Sanskrit (रक्षा) · Protection

Raksha is Sanskriet voor bescherming, verdediging en veiligheid. Het is een van de oudste taalkundige wortels voor het begrip 'beveiligen': tijdloos, grensoverschrijdend en fundamenteel voor elke samenleving die wil voortbestaan.

Raksha is Sanskrit for protection, safeguarding and security. It is one of the oldest linguistic roots for the concept of "to secure": timeless, cross-border and fundamental to any society that wants to endure.

Security Built with Precision. Assurance Built for Trust.
Samen vormen zij OranjeRaksha. Security gebouwd vanuit overtuiging, niet vanuit verplichting.
Security Built with Precision. Assurance Built for Trust.
Together they form OranjeRaksha. Security built from conviction, not compliance.
Security-filosofie
Security philosophy

Security zit in ons DNA

Security is in our DNA

Na 19 jaar werken aan de frontlinie van cybersecurity, in boardrooms, control rooms, datacenters en fabrieken, is er één overtuiging die alles drijft: security is geen product dat je koopt. Het is een eigenschap die je opbouwt.

After 19 years working at the frontline of cybersecurity, in boardrooms, control rooms, data centres and factories, one conviction drives everything: security is not a product you buy. It is a capability you build.

01
Dreigingen zijn werkelijk. Checklists zijn het niet.
Threats are real. Checklists are not enough.

De meest gevaarlijke security-aannames zijn de aannames die op papier kloppen maar in de praktijk niet werken. Een controle die bestaat in een beleidsdocument maar niet wordt afgedwongen in systemen, processen en gedrag is geen controle. Het is een risico met een vinkje.

The most dangerous security assumptions are the ones that look correct on paper but fail in practice. A control that exists in a policy document but is not enforced in systems, processes and behaviour is not a control. It is a risk with a checkmark.

02
OT en IT zijn niet hetzelfde risico.
OT and IT are not the same risk.

In een fabriek of energienetwerk betekent een security-incident niet alleen dataverlies. Het kan mensen in gevaar brengen, productie stilleggen of kritieke infrastructuur beschadigen. OT security vereist een aanpak die het verschil begrijpt tussen availability-first en security-first, en hoe je beide bedient zonder de ander op te offeren.

In a factory or energy network, a security incident does not just mean data loss. It can endanger people, halt production or damage critical infrastructure. OT security requires an approach that understands the difference between availability-first and security-first, and how to serve both without sacrificing one for the other.

03
Forensisch denken maakt het verschil.
Forensic thinking makes the difference.

Een goede security-auditor vraagt niet alleen "wat staat er in het beleid?" maar "wat is er werkelijk gebeurd, wat had er kunnen gebeuren, en hoe weet je dat?" Die forensische benadering, bewijs zoeken, hypothesen testen, aannames uitdagen, is wat een audit onderscheidt van een rondgang met een clipboard.

A good security auditor does not just ask "what does the policy say?" but "what actually happened, what could have happened, and how do you know?" That forensic mindset, seeking evidence, testing hypotheses, challenging assumptions, is what separates an audit from a walk-around with a clipboard.

04
De beste bevinding is er één die iemand daadwerkelijk oplost.
The best finding is one that someone actually fixes.

Een rapport vol bevindingen dat in een la belandt is geen securityverbetering. Bevindingen moeten begrijpelijk zijn voor engineers, prioriteerbaar voor management en uitlegbaar voor het bestuur. De kwaliteit van een auditrapport wordt niet gemeten in het aantal pagina's, maar in het aantal acties dat wordt opgepakt.

A report full of findings that sits in a drawer is not a security improvement. Findings must be understandable for engineers, prioritisable for management and explainable to the board. The quality of an audit report is not measured in pages. It is measured in the number of actions that get picked up.

De oprichter
The founder

Gebouwd op persoonlijke expertise

Built on personal expertise

OranjeRaksha is geen groot consultancybedrijf. Het is een gespecialiseerde praktijk rond security-audits, OT/IT-risk, data centers, supply chain security, fysieke beveiliging en forensisch denken.

OranjeRaksha is not a large consultancy. It is a specialised practice built around security audits, OT/IT risk, data centres, supply chain security, physical security and forensic thinking.

Sandeep Sharma brengt meer dan 19 jaar security-ervaring samen in audits die technisch genoeg zijn voor engineers en duidelijk genoeg voor management. Zijn werkgebied omvat information security audits, OT-security, data center audits, supply chain security, physical security, SOC/SIEM, vulnerability management, incident response, governance, BCP/DR en cyberforensics. De aanpak is praktisch: risico’s zichtbaar maken, bewijs beoordelen en bevindingen schrijven die organisaties daadwerkelijk kunnen oplossen.

Sandeep Sharma brings over 19 years of security experience to audits that are technical enough for engineers and clear enough for management. His work covers information security audits, OT security, data centre audits, supply chain security, physical security, SOC/SIEM, vulnerability management, incident response, governance, BCP/DR and cyber forensics. The approach is practical: make risks visible, assess evidence and write findings that organisations can actually resolve.

Information security audit OT / IT security Data center audit Supply chain security Physical security SOC / SIEM Vulnerability management Cyber forensics
"Een audit moet meer doen dan controleren. Het moet duidelijk maken wat werkelijk risico oplevert, waarom dat telt en welke verbetering haalbaar is." "An audit must do more than verify. It must make clear what actually creates risk, why that matters and which improvement is realistic."
Profiel
Profile
Ervaring Experience 19+ jaar / years · security, audit, infrastructure & forensics
Certificeringen Certifications CISA · Azure Fundamentals · Azure AI · SC-100 · ECIH
Opleiding Education MBA IT · Digital Evidence Analyst · Cyber Crime Investigator MBA IT · Digital Evidence Analyst · Cyber Crime Investigator
Kernvaardigheden Core skills Toegangscontrole · Vendor management · Risk & compliance · Security operations Access control · Vendor management · Risk & compliance · Security operations
Werkgebieden Work areas OT security · Data center · Physical security · Supply chain · SOC/SIEM · BCP/DR · Vulnerability management OT security · Data centre · Physical security · Supply chain · SOC/SIEM · BCP/DR · Vulnerability management
Actief in Active in Europa · India · APAC · Americas
Plan een kennismaking → Schedule a call →
SS
Missie & visie
Mission & vision

Waarom we dit doen

Why we do this

Security is pas zinvol als het tastbaar is. Niet als papieren compliance, maar als werkelijk begrip van risico's en wat ervoor nodig is om die te verminderen.

Security is only meaningful when it is tangible. Not as paper compliance, but as a real understanding of risk and what it takes to reduce it.

🎯
Onze missie
Our mission
Security tastbaar maken voor elke organisatie die er baat bij heeft.
Make security tangible for every organisation that needs it.

Van OT-lijnen en datacenters tot cloud en supply chains: we helpen organisaties hun werkelijke risico's te begrijpen, prioriteiten te stellen en verbeteringen stap voor stap door te voeren.

From OT lines and data centres to cloud and supply chains, we help organisations understand their real risks, set priorities and execute improvements step by step.

🔭
Onze visie
Our vision
Eén geïntegreerd securitybeeld: geen silo's, maar één samenhangend verhaal.
One integrated security picture: no silos, one coherent narrative.

Bestuurders, engineers, auditors en operators zien dezelfde risico's en spreken dezelfde taal, over IT, OT, datacenters, supply chains en fysieke beveiliging heen.

Executives, engineers, auditors and operators see the same risks and speak the same language, across IT, OT, data centres, supply chains and physical security.

Hoe we werken
How we work

Drie dingen die u van ons mag verwachten

Three things you can always count on

Dit zijn geen marketingbeloften. Het zijn de werkafspraken die gelden in elk traject, voor elke klant, ongeacht de omvang of het budget.

These are not marketing promises. They are the working agreements that apply in every engagement, for every client, regardless of size or budget.

I
Onafhankelijkheid zonder uitzondering
Independence without exception

OranjeRaksha verkoopt geen producten, geen licenties en geen tooling. Ons enige belang is een eerlijk, onderbouwd beeld van uw security-positie. Dat betekent ook dat we risico's benoemen die misschien ongemakkelijk zijn. Liever nu dan achteraf.

OranjeRaksha sells no products, no licences and no tooling. Our only interest is an honest, evidence-based picture of your security position. That also means naming risks that might be uncomfortable. Better now than in hindsight.

D
Diepgang zonder ruis
Depth without noise

We gaan diep in systemen, processen, configuraties en gesprekken. Maar we schrijven bevindingen die iemand daadwerkelijk leest en begrijpt. Geen 200 pagina's vakjargon, maar een helder rapport dat bestuur, audit en techniek hetzelfde beeld geeft.

We go deep into systems, processes, configurations and conversations. But we write findings that someone actually reads and understands. No 200 pages of jargon, but a clear report that gives management, audit and technical teams the same picture.

P
Praktisch of het telt niet
Practical or it does not count

Elke aanbeveling wordt gewogen op haalbaarheid: past het bij uw capaciteit, budget en huidige volwassenheid? Een advies dat in theorie klopt maar in de praktijk niet uitvoerbaar is, is geen advies. Het is papier.

Every recommendation is weighed for feasibility: does it fit your capacity, budget and current maturity? Advice that is theoretically correct but practically impossible to implement is not advice. It is paper.

Wilt u verkennen hoe OranjeRaksha uw organisatie kan helpen?

Want to explore how OranjeRaksha can support your organisation?

Of het nu gaat om een audit, assessment of training: u werkt altijd direct met de oprichter. Geen junior medewerkers, geen tussenlagen. Dezelfde expertise, elk traject.

Whether it is an audit, assessment or training: you always work directly with the founder. No junior staff, no layers in between. The same expertise, every engagement.

Plan een kennismaking → Schedule a call →

Geen verplichtingen · Reactie binnen 1 werkdag No commitment · Response within 1 business day

Voor trajecten in India en APAC werken we samen met onze lokale partner Riskberg. For engagements in India and APAC we work with our local partner Riskberg.