Consulting / Security auditing

Security auditing (ISO 27001 · ISO 22301 · DORA · pentest)

We audit the way certification bodies do, because our lead auditors work with them. Whether you need an ISO/IEC 27001, ISO 9001 or ISO 22301 gap analysis, an internal audit before the certification visit, a DORA assessment, a penetration test with a report your customers will accept, or help putting together the technical documentation for the National Bank of Slovakia — the same team covers all of it.

What you receive
  • ISO/IEC 27001, ISO 9001 and ISO 22301: gap analysis, internal audit, statement of applicability, risk treatment and business-continuity plans ready for the certification body
  • DORA: ICT risk-management assessment, register of information, incident-reporting and third-party arrangements mapped to the regulation
  • Penetration test of web, API, mobile and cloud estates with CVSS-scored findings, proof-of-concept, fixes and a free re-test within 60 days
  • Technical submissions to the National Bank of Slovakia and other regulators: architecture, security and continuity documentation prepared and defended with you
  • Executive summary your board, customers and insurers can read
Typical triggers
  • You are going for ISO/IEC 27001, ISO 9001 or ISO 22301 certification, or your recertification audit is coming up
  • DORA applies to you and you need to show ICT risk management, testing and third-party oversight that hold up
  • A customer, partner or insurer asks for a recent penetration test
  • The National Bank of Slovakia or another regulator requires technical documentation for a licence, product or outsourcing arrangement
How an engagement runs
  1. 1
    ScopingStandard or regulation in scope, systems, rules of engagement, deadline of the certification or submission
    1 h
  2. 2
    Assessment & testingDocument review, interviews and hands-on testing by certified auditors and ethical hackers
    5–15 d
  3. 3
    Report & remediation planFindings, gaps and a prioritised plan — walked through live with your team
    2 d
  4. 4
    Re-test & certification supportFindings verified closed; we stand next to you at the audit or the regulator meeting
    as needed
Consulting

Other consulting services

Risk and impact assessments

Risk and business-impact analyses by experts certified by the Slovak National Security Authority (NBÚ) and ISACA (CRISC) — using ISO/IEC 27005, ISO 31000 and Cybersecurity Act methodologies, with controls your team can realistically run.

Read more →

Technical due diligence

Our certified auditors combine governance know-how with deep technical skill and experience to assess your partner’s code, infrastructure, team and security against well-designed methodologies — so you make the right decision before the money moves.

Read more →

AWS configuration & scaling

Well-Architected reviews, IAM and network hardening, cost cuts and autoscaling designs from an AWS Partner who runs business-critical applications on it every day. The applications we work on grow to tens of terabytes — with response times and costs kept under control.

Read more →
Contact

A consultation with one of our engineers

Tell us what you are dealing with. Within two working days you get a concrete proposal with scope and price.

  • Reply from a senior engineer or lead auditor, not an account manager
  • Fixed scope and price before any work starts
  • ISO 9001 and ISO 27001 certified processes, NDA on request