Questions answered

Frequently Asked Questions

Everything you need to know about how we work, from a two-minute scan to a full engagement. Can't find what you're looking for? Get in touch.

Straight answersNo sales pressureDecision-oriented guidance
Before we work togetherThe aim is to make fit, scope, and next steps easier to understand.

Clarity before commitment

Common questions are answered plainly so you can judge fit before starting a conversation.

Practical engagement rhythm

Mandates are scoped around realistic timing, ownership, and the decision cadence your organization needs.

Direct senior conversation

When the FAQ does not cover your situation, the next step is a focused discussion, not a scripted sales process.

It gives boards and owners the evidence to act. Structured workshops and evidence review cover the active assessment domains, with live question and domain counts drawn from the current template. Every score is anchored and evidence-based: a claim without shown evidence caps at 3, so "we back up daily" scores differently from a demonstrated restore test. You leave with a heatmap, the red flags that matter, and the strategic decision in front of leadership.

Almost certainly yes. AI is in most organizations whether leadership approved it or not: staff paste data into public chatbots, features quietly ship inside tools you already pay for, and no one owns the risk. The exposure is real, from data leakage and compliance gaps to decisions made on unverified output, and it usually stays invisible until something goes wrong. The free AI GRIP Scan is the fastest way to see where you stand.

The AI GRIP Scan is a free, self-service scorecard. It takes about two minutes and returns a 0 to 100 view of the AI governance, visibility and safeguards your organization can confirm today, with a short breakdown by theme. It is designed as a first signal: the one-day AI Exposure Audit verifies which tools and data uses are actually present, and the full Shadow AI Assessment goes deeper.

They are three rungs of the same ladder. The AI GRIP Scan is free and self-service: your first signal in two minutes. The AI Exposure Audit is one day on site, ending in your three biggest AI risks named and a boardroom briefing. The Shadow AI Assessment is the full engagement: verified discovery of what is actually in use, policy, enablement, governance, and a funded roadmap. Relevant EU AI Act concepts are used as context, without certifying legal compliance. Most organizations start at whichever rung matches how urgent the question already feels.

An AI governance framework connects the organization's AI inventory and use cases to accountable owners, permitted and restricted use, data rules, human oversight, vendor decisions, incident handling, AI literacy, and evidence that controls operate. Galactus makes that framework practical for the organization and uses relevant EU AI Act concepts as context. It is not a legal opinion or a certification of compliance.

The IT chapter that can affect price, deal structure, and warranties. Galactus assesses technology debt, integration effort, security and continuity exposure, key-person risk, and inherited vendor and licensing commitments. The deal team receives one concise, red-flag-first report inside the agreed window, with depth scaled to the access the deal allows.

Exit Readiness is buyer-side due diligence run on yourself, before the buyer's advisors do it. It uses the same instrument as our IT Due Diligence, so it surfaces exactly what they will find: the gaps that cost price, the warranties you cannot yet stand behind, the IP and license questions your lawyers will need. Start 12 to 24 months out and you have time to fix what would otherwise become a discount or a broken deal. Findings touching IP, license settlements, or deal terms are input for your legal counsel, not legal advice.

The free AI GRIP Scan is a self-reported scorecard and first signal. Facilitated Galactus assessments go further: scores are anchored, evidence thresholds cap unverified claims, critical red flags override averages, and coverage is disclosed honestly. Delivered results are frozen so the final report does not change after the fact.

Yes. Galactus has no reseller agreements, referral fees, commissions, or vendor incentives. Recommendations are made solely in the client’s interest.

Mid-market companies and SMEs, roughly 50 to 1,000+ employees: large enough to have real IT complexity, not always large enough for a full-time C-level IT executive. Galactus also supports larger organizations and private-equity portfolios on defined mandates such as due diligence, value creation, or interim leadership.

Yes. Galactus is based in Boom, near Antwerp, and works across Europe. Assessments can combine on-site and remote work where the evidence standard and mandate allow it.

It depends on scope. The AI GRIP Scan is free. Assessments (IT Health, the AI track, IT Due Diligence, Exit Readiness) are fixed-fee for a defined scope. C-level advisory is usually a monthly retainer, and interim or crisis leadership is billed per day or per month. Costs are clear from the first conversation: no hidden fees, no scope-creep surprises.

Availability and start dates are confirmed only after the decision, scope, access, and delivery model are understood. The public response promise of two business days covers the initial reply; it is not a commitment to begin or complete an engagement within that period.

Usually that is exactly how it works. Sven works with the existing team rather than around it. The objective is to leave stronger ownership, clearer governance, better processes, and knowledge that stays inside the organization.

Regular strategic sessions with your executive team or board, independent validation of major technology and investment decisions, and support at the moments that matter: a transformation, a major program, M&A, or a governance reset. It ranges from a monthly advisory cadence to intensive support during a specific initiative, and it is also built for private-equity value creation.

A fractional CIO works a recurring number of days each month when the organization needs ongoing senior accountability without a full-time executive. An interim CIO or IT Director steps in more intensively for a vacancy, transition, transformation, or recovery period. Both are defined, principal-led mandates delivered directly by Sven, with the authority, objectives, cadence, and handover condition agreed before the work starts.

Yes. Galactus can provide interim IT leadership for a defined period or take a hands-on Crisis & Rescue mandate when control, delivery, or stability is at risk. Availability, scope, and any start date are confirmed after the first discussion; the service is not positioned as a 24/7 emergency-response channel.

Galactus is independent, principal-led, and built around defensible decisions. Sven Van Roosenbroek leads every mandate directly. Facilitated assessments use anchored scoring and verified evidence; advisory and intervention work translates technology into decisions, ownership, and measurable execution.

Every Galactus mandate is led directly by Sven Van Roosenbroek. Where specialist input is required, that involvement is made explicit in the scope, while accountability for the engagement remains clear.

It depends on the question, but evidence may include contracts, architecture records, asset and identity exports, budgets, policies, incident records, restore tests, project data, vendor reporting, and direct system observation. A claim without evidence is treated as unverified rather than assumed to be true.

You will be told directly. The recommendation may be to narrow the question, involve legal or security counsel, use a specialist implementation partner, wait until better evidence is available, or solve the issue internally. The first conversation is designed to establish fit, not force an engagement.

Still have questions?

Bring the situation and the decision to a direct senior conversation. You will get an honest view on fit and the next responsible step.