01
Accounts and permissions
We see who controls the data, cameras and administration.
Cyber audit
Who has yours dates? We will check accounts, deposits, cameras, contractors and first response team.
Division Director GBH Cyber
Your cybersecurity is not driven by a marketer, but by an engineer.
He built secure systems for IBM and Trezor. Now they are building them for your organization.
NÚKIB
duties without chaos
NIS2
impact on leadership
Data
accounts, roles, backups
Building
cameras and approaches
Practical impact
It's not a checklist. These are decisions that will reduce the risk in traffic.
Cyber audit it must not end in a technical novel. We will check accounts, dates, cameras and suppliers and we will translate the findings into priorities understood by management.
Accounts, permissions, camera administration and external management must have clear boundaries and responsibilities.
An audit separates critical data, backups, network and operational dependencies from things that can wait.
The output translates the technical findings into priorities, budget, responsible persons and further training of the team.
We will check accounts, data, suppliers, cameras and physical mode. The output is leadership priorities, not a technical novel.
Accounts and rights
Sensitive data
Suppliers
Building
Division Director GBH Cyber
Adam Schinzel
Senior software engineer, IBM and Trezor/SatoshiLabs.
An audit is for management who need to know where the real risk is and what to change first.
01
We see who controls the data, cameras and administration.
02
Critical data has clear recovery.
03
We consider CCTV, inputs and mode together.
04
External management has clear boundaries and responsibilities.
05
First phone call, disconnection, records, decision.
06
We translate duties into steps for management.
Short, clear, according to priority. What to solve now, what to plan and what to transfer to training.
NIS2 and the new Act on cyber security they transfer responsibility to management. An audit and a prepared team will cost less than a fine, downtime and data loss.
up to €10 million
or 2% of turnover — fines according to NIS2
Management is responsible
personal responsibility for the measures taken
24 / 72 h
statutory deadlines for reporting an incident
Suppliers
you are also responsible for the supply chain
These are not presentation scarecrows. They are publicly documented Czech incidents. Cyber audit it targets precisely the entry points that this class of attack has exploited — weak ones accounts, missing deposits, uncovered suppliers and missing crisis procedure. We do not guarantee that you will never experience an incident; we'll show you where you're vulnerable before an attacker does.
December 2019 Ryuk ransomware
On December 11, 2019, ransomware crippled hospital systems. Full operation did not resume until December 30, the damage exceeded 59 million crowns.
What we do with it: It started with email and poorly protected accounts. Cyber audit examines exactly these entry points.
Source: Czech Television (ČT24)
March 2020 · ransomware, the day after the state of emergency was declared
On March 13, 2020, a day after the state of emergency was declared, an attack encrypted the systems of the country's second largest hospital. Postponed operations, provisional damage of 150 million crowns.
What we do with it: One open attachment stopped the operation. That is why in the course we train phishing recognition and the procedure of the first hour.
Source: Aktuálně.cz268
of cyber security incidents recorded by NÚKIB in 2024 — the most so far, most often in the public sector
Source: NÚKIB, Report on the state of cyber security of the Czech Republic (2024)Operations center, traffic analysis, incidents and physical approaches — shot by shot.
Nope. In the case of schools, companies and institutions, data, cameras, access, suppliers and the mode of the building are all related. That is why we audit the cyber layer as part of operational security.
Nope. The audit is also suitable for organizations where IT is provided by an external administrator. This is where accounts, deposits, responsibilities and crisis procedures tend to be unclear.
Brief report with priorities, risks, recommended measures and incident checklist. For a larger scale, we will supplement the team's follow-up training plan.
Cyber audit
Send the type of organization, the number of sites and who manages your IT. We will suggest a reasonable audit scope.
Write whether you are dealing with a school, company or institution, the number of locations and the current state of IT administration. We will return the recommended range.