// 04 · SECURITY CONSULTING
Security consulting
Security consulting is dedicated time with a tester over a specific decision of yours: an architecture design, a vendor choice, an Active Directory setup, or preparation for an inspection. If you need to go through the whole environment rather than one decision, a systematic audit of the entire infrastructure is the better fit. Instead of generic recommendations you get a breakdown of how an attacker would go after the chosen design and which change closes off which path. Typically it’s two to three days of work.
// 01
When it pays to call before the test, not after
The cheapest fix is the one you make on paper. Show us the design of a new customer application before development and we walk through the data flows with STRIDE and name where risk arises: in authorization between roles, in tokens for integrations, and in an administrator interface exposed to the internet. Half a day over a diagram saves rewriting a module in production.
The second moment is choosing a vendor or a tool. A requirement like “will provide cybersecurity” in a brief has no criterion for saying whether the vendor met it, so its interpretation can be argued over for months. We help you write requirements that can be measured: which logs the vendor hands over, how often testing happens, what the deliverable looks like, and who holds the encryption keys.
The third is the situation after an incident or after a test by another company. We go through the report, separate the findings that are a real threat from the ones a scanner dumped in, and propose a remediation priority by how many paths each one closes to an attacker.
// 02
How a consultation runs
The format is a call or a half-day workshop, not a hundred-page document. We request materials in advance (a network diagram, a list of exposed services, an overview of administrative accounts, possibly an older report) and come with questions, not a blank notepad. The first session usually takes two to three hours.
The deliverable is a write-up of up to five pages: recommended decisions, risks that remain open, and the order of steps for the next quarter. Each step has an effort estimate and a note on who can handle it: your team, a vendor, or us.
Where it makes sense to verify an assumption, we propose a targeted test instead of another meeting. A one-day check of a single hypothesis, say whether an ordinary workstation can reach an administrative share, settles the discussion faster than three meetings and costs less than a month of delay.
// 03
An offensive view of defensive decisions
A consultant who doesn’t test can only lean on what the standard says. We add what actually makes an attacker’s job harder and what doesn’t. Disabling NTLM where it’s no longer needed, separating administrative accounts into their own tier, and cleaning up delegations in the domain move your defense further than another tool in the security operations center. Whether that holds in your environment is what a test of the Active Directory and Microsoft Entra ID design verifies.
We’ll just as readily tell you when a measure is pointless. There’s no sense paying for detection of exotic techniques while half your servers share the same local administrator password and the domain allows delegation that an ordinary account can abuse.
Regulation feeds into these decisions continuously. Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act), by which the Czech Republic transposed the NIS2 Directive (Directive (EU) 2022/2555), has been in effect since November 1, 2025 and changes what some companies have to document. Whether it applies to you and what exactly it asks of you is written up in our overview of which regime a company falls into and what follows from it, and separately in the glossary on when a security audit is enough and when you need a test.
// 04
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 05
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
We’ll go over the scope together.
Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.