What are your security vulnerabilities? Physical and cyber protection audits
Security is often only addressed when there is a problem. That is, at the moment when you have limited control over the situation. Impacts incident they are then much more serious than if she had been risks identified and addressed in time, before the event itself occurs. How would v crisis situation has your organization survived, and would it even have procedures in place to fall back on?
Physical and cyber protection audits
A weak point must be seen before an incident occurs.
Many companies today focus on individual security measures, for example camera systems, access cards or internal rules. However, individual measures do not automatically mean a functional security system. Security audit it can show whether individual parts really work as a whole, from technical security to staff readiness to crisis procedures. It is not only about finding problems, but above all about obtaining a clear overview of risks, priorities and specific steps that will lead to increased security. This is exactly what GBH Academy focuses on and is able to provide both physical and cyber security audits.
PHYSICAL SECURITY AUDIT
The audit is focused on so-called soft targets, i.e. objects with a high concentration of people and a low level of protection. These may include schools, offices, hospitals, large companies, social services or cultural and sports institutions. In recent years, it has been shown how vulnerable these objects are. And unfortunately, the Czech Republic is no exception. We were convinced of this during the shooting at the Faculty of Arts of Charles University or at the office in Chřibská.
Although there is no blanket legal obligation to implement specific security measures yet, recommended standards that create the expected level of security are appearing more and more often. Today, companies and institutions are not only dealing with the protection of individuals, but also the question of their responsibility and preparedness for threats.
What will the audit bring?
A physical security audit GBH Academy is an independent assessment of a facility's readiness for a serious violent attack. Its goal is not only to identify weak points, but above all to propose concrete measures. In this way, the organization does not receive general recommendations, but a clear plan with priorities, a schedule and an estimate of the costs of the necessary changes.
An audit answers practical questions that the management of a company or institution often asks itself only when a crisis situation arises. How is the facility prepared for a serious attack? Where can you get into the building and how is the entry of people controlled? How would the staff handle the first few minutes before the police arrive? Or how much will the measures cost and how to schedule them in time? The output is then built so that the director, mayor, board and operations manager can work with it.
What are the stages of an audit?
The assessment takes place in several subsequent steps. First, the object itself and its surroundings are analyzed, including the identification of possible sources of threats and methods of attack. This is followed by a physical inspection of the building, during which, for example, the mode of entry of people into the building, the readiness of the interior spaces and the readiness for internal evacuation or the use of technologies such as cameras and electronic security systems are evaluated.
The same emphasis is also placed on the human factor. The level of employee training, the existence of crisis plans, the warning system and the setting of cooperation with the components of the integrated rescue system are evaluated. The output is not only the identification of risks, but above all a specific security plan containing recommended steps, an implementation schedule and procedures for dealing with emergency situations.
Preparedness can also be strengthened with model situations. As part of active attacker protection training, staff can practice how to respond in a crisis and verify the correctness of procedures in a controlled environment. This significantly increases the ability to react quickly and in a coordinated manner, even in the moment when it is no longer an exercise, but a real situation.
The audit is carried out by experts from practice
The analysis is processed directly by Lumír Němec, former commander of the special operations group of the URNA intervention unit of the Police of the Czech Republic and of the special units of the SOG of the Czech Army. He has experience from missions in Kosovo, Iraq and Afghanistan. Other members of the team include former members of the Army and the Police of the Czech Republic, who in practice encountered the protection of persons and objects, solving crisis situations and responding to security incidents.
The entire assessment is based on the methodology of the Ministry of the Interior of the Czech Republic, the standard ČSN 73 4400 and verified procedures from real practice. Thanks to this, the audit is not based on general recommendations, but on experience from an environment where the speed, accuracy and functionality of individual measures are decisive in practice.
CYBER SECURITY AUDIT
Today, cyber security is not only an issue for the IT department, but an essential part of the management of the entire organization. Data, access, e-mail communication and cloud systems form the infrastructure on which daily operations are based. But what happens when access data is leaked, an email inbox is hacked or key data is encrypted? And does your organization have clearly set procedures that work in such a situation without improvisation?
Experience shows that most cyber incidents are not caused by technology failures, but by inadequately set processes, weaknesses in approaches or human error. That is why it is no longer enough to just have antivirus protection or basic IT security. Organizations need a holistic view of how their systems, data and people are truly protected.
How is an audit useful?
Cyber Audit GBH Academy examines how the organization handles data, approaches, systems and suppliers and whether it is adequately prepared for current cyber threats. The result is an overview of possible risks and specific recommendations for strengthening security.
An important part is also the evaluation of the regulatory position of the organization within the framework of the new law on cyber security. This sets out obligations for providers of regulated services and introduces a two-tier system of security requirements. For many organizations, auditing is not only a matter of security, but also of necessary compliance with the legal framework. An audit is also often required for arranging cyber insurance or for public contracts.
What does an audit consist of?
The analysis takes place in three steps. First, it is evaluated to which level of regulation the organization falls and what it realistically has to fulfill. The following is a detailed analysis of the difference between the desired state and the reality of operation. Specifically, the audit focuses on identity and access management, working with passwords, multi-factor authentication, security of e-mail communication, backup, but also remote access and handling of sensitive data. The assessment also includes checking external service providers, who often represent the weakest link in the entire security structure.
Based on the analysis, a plan is created that converts the identified risks into concrete steps. It is not just a list of problems, but a practical guide to what the organization should do now, what to do in the following months and what to solve in the long term. It also includes the preparation of documents such as safety rules, internal guidelines and other documents required by legislation, which can be used directly in practice or handed over to the responsible teams.
At the same time, the audit also addresses who is responsible for cyber security in the organization. These roles must be clearly defined and functional. If necessary, they can be arranged through GBH Academy experts. The goal is for security not only to exist on paper, but also to function in real operation.
Who will assess your cyber security?
The audit is carried out by a team of experienced experts from large technology companies and former members of the intelligence services, that is, people who know how to counter commercial and industrial espionage attacks, wiretapping or monitoring of electronic communications. At the same time, they meet the legal requirements for qualifications, experience and independence. Their expertise is evidenced by the certifications of the National Office for Cyber and Information Security (NÚKIB) and the accredited certification body TAYLLORCOX. The approach combines the requirements of the law with practical experience from real security incidents.
Security is not a one-time measure, but a process that must be regularly verified and adjusted according to real risks. Both physical and cyber security audits GBH Academy give organizations a clear view of where they are today, what risks they are underestimating and what steps they need to take first. The GBH Academy team has completed contracts for more than a thousand organizations across sectors. Experience from these projects is reflected in every subsequent audit. The complete range of services can be found on the website GBH Academy. Přiblížit se nám můžete také skrze sociální sítě Facebook, Instagram a TikTok.
Are you interested in training?
Send us an inquiry — we'll get back with a tailor-made date and program proposal.
- Dlouhá 730/35, 110 00 Prague 1
- info@gbhdefence.com
- +420 252 548 480



