// 04 · SECURITY CONSULTING

Security consulting

Security consulting is dedicated time with a tester over a specific decision of yours: an architecture design, a vendor choice, an Active Directory setup, or preparation for an inspection. If you need to go through the whole environment rather than one decision, a systematic audit of the entire infrastructure is the better fit. Instead of generic recommendations you get a breakdown of how an attacker would go after the chosen design and which change closes off which path. Typically it’s two to three days of work.

// 01

When it pays to call before the test, not after

The cheapest fix is the one you make on paper. Show us the design of a new customer application before development and we walk through the data flows with STRIDE and name where risk arises: in authorization between roles, in tokens for integrations, and in an administrator interface exposed to the internet. Half a day over a diagram saves rewriting a module in production.

The second moment is choosing a vendor or a tool. A requirement like “will provide cybersecurity” in a brief has no criterion for saying whether the vendor met it, so its interpretation can be argued over for months. We help you write requirements that can be measured: which logs the vendor hands over, how often testing happens, what the deliverable looks like, and who holds the encryption keys.

The third is the situation after an incident or after a test by another company. We go through the report, separate the findings that are a real threat from the ones a scanner dumped in, and propose a remediation priority by how many paths each one closes to an attacker.

// 02

How a consultation runs

The format is a call or a half-day workshop, not a hundred-page document. We request materials in advance (a network diagram, a list of exposed services, an overview of administrative accounts, possibly an older report) and come with questions, not a blank notepad. The first session usually takes two to three hours.

The deliverable is a write-up of up to five pages: recommended decisions, risks that remain open, and the order of steps for the next quarter. Each step has an effort estimate and a note on who can handle it: your team, a vendor, or us.

Where it makes sense to verify an assumption, we propose a targeted test instead of another meeting. A one-day check of a single hypothesis, say whether an ordinary workstation can reach an administrative share, settles the discussion faster than three meetings and costs less than a month of delay.

// 03

An offensive view of defensive decisions

A consultant who doesn’t test can only lean on what the standard says. We add what actually makes an attacker’s job harder and what doesn’t. Disabling NTLM where it’s no longer needed, separating administrative accounts into their own tier, and cleaning up delegations in the domain move your defense further than another tool in the security operations center. Whether that holds in your environment is what a test of the Active Directory and Microsoft Entra ID design verifies.

We’ll just as readily tell you when a measure is pointless. There’s no sense paying for detection of exotic techniques while half your servers share the same local administrator password and the domain allows delegation that an ordinary account can abuse.

Regulation feeds into these decisions continuously. Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act), by which the Czech Republic transposed the NIS2 Directive (Directive (EU) 2022/2555), has been in effect since November 1, 2025 and changes what some companies have to document. Whether it applies to you and what exactly it asks of you is written up in our overview of which regime a company falls into and what follows from it, and separately in the glossary on when a security audit is enough and when you need a test.

// 04

How we classify findings

Vulnerability severity classification
SeverityCVSS
Critical9.0 – 10.0
High7.0 – 8.9
Medium4.0 – 6.9
Low0.1 – 3.9

// 05

Frequently asked questions

A diagram of the network or the application, a list of services exposed to the internet, an overview of administrative accounts, and your last security report, if you have one. It doesn’t have to be complete or neatly drawn; we also work from a sketch made during the call. The more specific the question you bring (say, whether a given service belongs in the DMZ), the more useful those two to three hours will be.

Yes, on the technical side. We go through what you have documented, where evidence is missing, and which test deliverables will hold up in an inspection. We don’t do the legal assessment of whether and in which regime you fall under the regulation; that is for your lawyers or compliance team. We have summarized what exactly the Act requires of you and where testing fits in. If you’re dealing with certification rather than the Act, the same goes for the documents an ISO/IEC 27001 auditor expects.

Yes, gladly. Consultations are ordered by topic: an integration design now, a vendor choice next quarter, the remediation priority after a test. We don’t hold reserved capacity for you in advance and we don’t offer a flat fee; we set a date once you know what you want to talk about. When you come back with the next topic, we skip the introduction to your environment and get straight to the point.

Yes, with one condition: we don’t check our own work. If we design an architecture, we won’t then assess it as an independent third party. We will run the test, but the conflict of interest will be stated in the report and we’ll recommend that someone else do the final verification. For environments where we advised only on individual measures, that isn’t a problem.

// INCLUDED WITH EVERY ENGAGEMENT

Free one-time data leak check

With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.

How continuous leak monitoring works

// NEXT STEP

We’ll go over the scope together.

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.