Security we operate, not just recommend.
We are not consultants who hand over an analysis and drive away. We deploy concrete measures into your network, manage them and make sure they actually work.
Security is not one product but layers
An attacker has to get through all of them. You choose how far you want to go — each layer also works on its own.
Perimeter
Managed firewall, traffic filtering, protection against attacks from outside
Network
Segmentation into VLANs, separate guests and IoT, controlled traffic between segments
Devices
Protection of computers and servers, patch management, disk encryption
Identity
Two-factor authentication, password management, permission governance
Data
Backups separated from production, tested recovery, protection against ransomware
People and processes
Training, policies, incident response plan, regulatory compliance
Managed firewall
We deliver the firewall, set it up and above all keep managing it — rules, updates and responses to what shows up in operation. Most companies have a firewall nobody has touched since installation; that is exactly the difference.
Request a firewall- Traffic filtering by application, not just ports
- Protection against known attacks and malicious domains
- DDoS protection at the level of our network
- VPN for employees and branch interconnection
- Ongoing rule management and updates
- Monthly report of filtered traffic
Network segmentation and secure VLANs
When one computer in a company gets infected, it must not reach the accounting server or the production line. We divide the network so that a problem stops where it started — and so that visitors on the Wi-Fi cannot see your data.
Request segmentation- Company devices separated from everything else
- Guest Wi-Fi without access to the company network
- Cameras, printers and IoT in their own segment
- Production and technology separated from offices
- Servers with controlled access only from where it is needed
Protection of computers and servers
Most successful attacks start on an ordinary employee's laptop, not on a server.
Antivirus protection
Centrally managed protection with oversight on our side, not an icon in the tray nobody watches.
Patch management
We make sure systems and applications are patched — the most common hole is a forgotten update.
Disk encryption
A lost laptop is then not a data breach, just lost hardware.
Device control
Restricting USB and unapproved software where it makes sense.
Who gets where
A stolen password is the easiest way in these days. We deploy two-factor authentication, a password manager for the team and review who has access to what — it often turns out that former employees still have active accounts.
Request an access audit- Two-factor authentication on key systems
- Company password manager instead of shared spreadsheets
- Review of permissions and removal of unnecessary ones
- Single sign-on across applications
- Controlled process for employee onboarding and offboarding
Preparation for ZoKB requirements
The new Act No. 264/2025 Coll., on Cybersecurity, has been in force since 1 November 2025 and implements the requirements of the NIS2 Directive into Czech law. We will help you assess whether you provide a regulated service, map the requirements and implement the necessary technical and organizational measures. Legal assessment and fulfilment of statutory obligations remains the responsibility of your organization.
Request a consultation- Assessment of whether the regulation applies to you
- Gap analysis against the requirements
- Measures proposal sorted by priority
- Deployment of technical measures
- Policies, documentation and incident response plan
- Preparation for inspections and incident reporting
What we watch continuously
24/7 monitoring
We watch network and server traffic and notice what does not fit — before anyone else does.
Incident response
You have agreed in advance who intervenes, how fast and what happens in the first hour — not only once things are on fire.
Employee training
Phishing, passwords, safe handling of data. Including simulated phishing so you know where you stand.
Where to start
You do not have to deploy everything at once. Most companies start with the Basics and expand as they grow.
Basics
- Managed firewall
- Endpoint protection
- Backup with tested recovery
- Monthly report
Standard
- Everything in Basics
- Network segmentation and secure VLANs
- Two-factor authentication and password management
- 24/7 monitoring
- Employee training
Compliance
- Everything in Standard
- Gap analysis against ZoKB requirements
- Policies and documentation
- Incident response plan
- Support during inspection
We set the price according to the number of devices, branches and the required response time — we prepare an offer after a short consultation.
Security in practice
We are a small company — does this even apply to us?
Attacks today do not target specific companies but blanket-target whatever is vulnerable. A smaller company is often an easier target precisely because it has no IT department.
Do we have to replace the whole network because of this?
No. We start with what brings the most for the least disruption — typically a firewall, backups and device protection. Segmentation comes in a later step.
What if we already have some vendor?
We can take over only part, or work alongside your current vendor. We gladly review what you already have before proposing anything.
How quickly do you respond to an incident?
According to the agreed service level. Response times are part of the contract, not a promise.
Can we find out whether we have already been attacked?
The initial analysis includes checking for signs of compromise and leaked data associated with your domain.