Cyber audit

Cyber audit

Who has yours dates? We will check accounts, deposits, cameras, contractors and first response team.

Two female experts go through documents at the table — cyber audit and analysis

Division Director GBH Cyber

Adam Schinzel

Your cybersecurity is not driven by a marketer, but by an engineer.

He built secure systems for IBM and Trezor. Now they are building them for your organization.

Adam Schinzel, Division Director GBH Cyber
NIS2 specialist NÚKIB IBM Vault (SatoshiLabs)

NÚKIB

duties without chaos

NIS2

impact on leadership

Data

accounts, roles, backups

Building

cameras and approaches

The audit must show what management should change first

Two female experts go through documents at the table — cyber audit and analysis Cyber audit

Practical impact

It's not a checklist. These are decisions that will reduce the risk in traffic.

Cyber audit it must not end in a technical novel. We will check accounts, dates, cameras and suppliers and we will translate the findings into priorities understood by management.

  1. 01

    Who has access

    Accounts, permissions, camera administration and external management must have clear boundaries and responsibilities.

  2. 02

    What stops traffic

    An audit separates critical data, backups, network and operational dependencies from things that can wait.

  3. 03

    What is the management to decide

    The output translates the technical findings into priorities, budget, responsible persons and further training of the team.

GBH Cyber

The audit is intended to show where traffic may be falling.

We will check accounts, data, suppliers, cameras and physical mode. The output is leadership priorities, not a technical novel.

Accounts and rights

Sensitive data

Suppliers

Building

Start an audit
Adam Schinzel, Division Director GBH Cyber

Division Director GBH Cyber

Adam Schinzel

Senior software engineer, IBM and Trezor/SatoshiLabs.

Not another checklist. Specific weaknesses that can stop operations

An audit is for management who need to know where the real risk is and what to change first.

Hand with phone and verification code at keyboard — accounts and permissions

01

Accounts and permissions

We see who controls the data, cameras and administration.

Modern server room in blue light — backups and data recovery

02

Data and backups

Critical data has clear recovery.

CCTV camera on the facade of the building monitoring the entrance

03

Cameras and physical security

We consider CCTV, inputs and mode together.

Two female experts go through the documents — the boundaries and responsibility of suppliers

04

Suppliers

External management has clear boundaries and responsibilities.

Smaller computer security team — incident procedure

05

Incident procedure

First phone call, disconnection, records, decision.

Detail of a network switch with cables — critical infrastructure under NIS2

06

NÚKIB / NIS2

We translate duties into steps for management.

Management gets a decision document, not a technical novel

Short, clear, according to priority. What to solve now, what to plan and what to transfer to training.

01

Map of risks and priorities

02

List of accounts and critical accesses

03

Recommendations for cameras, data and suppliers

04

Incident checklist for management

05

Design of a follow-up cyber course

06

Output usable for management meetings

Cybersecurity is no longer voluntary

NIS2 and the new Act on cyber security they transfer responsibility to management. An audit and a prepared team will cost less than a fine, downtime and data loss.

up to €10 million

or 2% of turnover — fines according to NIS2

Management is responsible

personal responsibility for the measures taken

24 / 72 h

statutory deadlines for reporting an incident

Suppliers

you are also responsible for the supply chain

What the audit is looking for actually happened. And it stopped traffic

These are not presentation scarecrows. They are publicly documented Czech incidents. Cyber audit it targets precisely the entry points that this class of attack has exploited — weak ones accounts, missing deposits, uncovered suppliers and missing crisis procedure. We do not guarantee that you will never experience an incident; we'll show you where you're vulnerable before an attacker does.

The historic building of the Rudolf and Stefanie Benešov Hospital (Máchova 400) — the target of the 2019 ransomware attack Logo of Czech Television / ČT24

December 2019 Ryuk ransomware

Benešov Hospital

On December 11, 2019, ransomware crippled hospital systems. Full operation did not resume until December 30, the damage exceeded 59 million crowns.

What we do with it: It started with email and poorly protected accounts. Cyber ​​audit examines exactly these entry points.

Source: Czech Television (ČT24)
Campus of the Faculty Hospital Brno-Bohunice Aktuálně.cz logo

March 2020 · ransomware, the day after the state of emergency was declared

University Hospital Brno

On March 13, 2020, a day after the state of emergency was declared, an attack encrypted the systems of the country's second largest hospital. Postponed operations, provisional damage of 150 million crowns.

What we do with it: One open attachment stopped the operation. That is why in the course we train phishing recognition and the procedure of the first hour.

Source: Aktuálně.cz

268

of cyber security incidents recorded by NÚKIB in 2024 — the most so far, most often in the public sector

Source: NÚKIB, Report on the state of cyber security of the Czech Republic (2024)

Cyber audit in practice

Operations center, traffic analysis, incidents and physical approaches — shot by shot.

Security Operations Center GBH Cyber
Operations Center
Cyber security analyst at workplace with monitors
Traffic analysis
Team response to a cyber incident
Incident response
Data hall with server racks
Data hall
Physical penetration test of the access system
Cameras and approaches
Access control system — card reader at the door
Access control
Is cyber audit separate from physical security?

Nope. In the case of schools, companies and institutions, data, cameras, access, suppliers and the mode of the building are all related. That is why we audit the cyber layer as part of operational security.

Do we need our own IT department?

Nope. The audit is also suitable for organizations where IT is provided by an external administrator. This is where accounts, deposits, responsibilities and crisis procedures tend to be unclear.

What do we get as output?

Brief report with priorities, risks, recommended measures and incident checklist. For a larger scale, we will supplement the team's follow-up training plan.

Cyber audit

Scan accounts, data and cameras before an incident does

Send the type of organization, the number of sites and who manages your IT. We will suggest a reasonable audit scope.

Cyber audit for your organization

Write whether you are dealing with a school, company or institution, the number of locations and the current state of IT administration. We will return the recommended range.