// ABOUT US

Your ethical hackers

SYSNETSHIELD is a Czech offensive security company: penetration testing, red teaming, phishing simulations, and security consulting for companies in the Czech Republic, Slovakia, and abroad. Patrik Žák has been in the IT business since 2015, and we have worked under the SYSNETSHIELD name since October 2023. The company was formed by two people who each cover a different part of the field. We are based on Korunní Street in Vinohrady, Prague, and we test for clients in manufacturing, healthcare, financial services, and government agencies. Our market is the Czech Republic and Slovakia, but our clients aren’t limited to it: we run engagements for companies in Europe, the Americas, and Africa. What we do is listed in the services overview, the whole team’s write-ups come out on the blog, and our Red Team Lead Patrik Žák publishes the Security Sunday newsletter every Sunday, plus videos on YouTube.

// TEAM

Founders

Patrik Žák, Red Team Lead at SYSNETSHIELD

Patrik Žák

Co-founder · Red Team Lead

He leads red team operations and infrastructure tests and holds six certifications: CRTO and CRTL for red teaming, CPTS and CNPen for penetration testing, CCPenX-AWS for the cloud, and C-AI/MLPen for AI systems. Of these, the cloud certification is aimed at penetration testing in AWS. He found an integer overflow in the unflatten() function of MikroTik RouterOS, published in the National Vulnerability Database (NVD) as CVE-2026-39042 at CVSS 7.5 (High). He teaches a penetration testing course for robot_dreams.

Patrik Žák’s full profile
Juraj Daniš, penetration tester at SYSNETSHIELD

Juraj Daniš

Co-founder · Penetration Tester

He tests web applications and APIs: from authorization flaws to business logic that a scanner doesn’t flag on its own. He also works on the security of IoT devices and industrial OT systems. He holds four certifications: CRTO, CNPen, CAPenX, and WEB1, the last two aimed directly at application security. He co-founded the company with Patrik Žák in October 2023 and is its managing director and co-owner.

Juraj Daniš’s full profile

// CERTIFICATIONS AND METHODOLOGY

  • CRTO, Red Team Operator (Zero-Point Security)
  • CRTL, Red Team Lead (Zero-Point Security)
  • CPTS, HTB Certified Penetration Testing Specialist (Hack The Box)
  • CCPenX-AWS, Certified Cloud Pentesting eXpert-AWS (The SecOps Group)
  • CNPen, Certified Network Pentester (The SecOps Group)
  • C-AI/MLPen, Certified AI/ML Pentester (The SecOps Group)
  • CAPenX, Certified AppSec Pentesting eXpert (The SecOps Group)
  • WEB1, Web Application Pentester Level 1 (TryHackMe)

We test applications against OWASP requirements and run each engagement according to PTES (Penetration Testing Execution Standard) and NIST SP 800-115. That makes the report comparable across tests and against another vendor’s deliverable. We also map the covert operations we run to MITRE ATT&CK techniques, so at every step you can see what the defenders should have caught. With certifications, the abbreviation alone says nothing about the exam format: a separate glossary entry explains what you can tell from a certification’s abbreviation.

Our own finding in the NVD

Integer overflow in the unflatten() function of the libumsg.so library in MikroTik RouterOS. An unauthenticated attacker can crash the service, causing a denial of service. CVSS 7.5 (High), CWE-190.

CVE-2026-39042

// WORK WITH US

Tell us what you want tested

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.