Skip to content
Cofinanțat de Uniunea EuropeanăGuvernul României

03 / SERVICII

Cybersecurity

Build. Verify. Protect.

Most security problems do not come from spectacular attacks. They come from ordinary things left open: a weak password, a forgotten setting, an outdated component. We look for them before somebody else does.

What we do
Find the weak spots and tell you how they close
Who it is for
Anyone holding customer data or depending on a system
How it starts
We agree together what gets checked and over what period

Signs you need this

  • You hold data about customers, patients or beneficiaries and are not sure how well it is protected.
  • A client or a funder is asking you to prove your systems have been checked.
  • You launched something recently and nobody from outside has looked at it.
  • The application was built by someone else and you do not know what was left behind.
  • You have already had an incident and want to make sure it does not repeat.
  • People who used the system have since left and you do not know what access still exists.

What you actually get

  • A written report aimed at management, not only at specialists.
  • Problems ordered by how serious they are, not alphabetically.
  • For each problem: what it means in practice, if someone took advantage of it.
  • Concrete steps to fix it, not general recommendations.
  • A second check after you have repaired things, to confirm they are closed.

STEP BY STEP

How it goes, from the first conversation to the end

Each step also says what is expected of you. It is usually less than people fear.

  1. 01

    We agree what gets checked

    Together we choose what is in scope: a website, an application, the servers, or everything. We put the limits in writing, so there are no surprises.

    Partea ta

    Tell us what worries you most. That instinct is usually right.

  2. 02

    We get access

    You give us the access needed and we agree a working window that does not disturb your activity.

    Partea ta

    Warn your technical team, if you have one, so they are not alarmed by what they see.

  3. 03

    We check

    We look at how the data is protected, who may reach what, which settings were left open and which components are out of date.

  4. 04

    We tell you at once if something is serious

    We do not wait for the final report to tell you there is a serious problem. If we find something critical, you hear the same day.

  5. 05

    You get the report

    We go through it together, point by point. You can ask anything, including “what happens if we do not fix this”.

    Partea ta

    Bring whoever will do the repairs into the conversation.

  6. 06

    You fix, then we check again

    You can solve it with your own people or we can help. At the end we check again, so you have confirmation it is closed.

What it costs

It depends on how much has to be checked and how deep we go. A small application is checked quickly; a system with many parts takes longer.

The first conversation is free and commits you to nothing. After it you get in writing what we would build, how long it takes and what it costs — so you can compare us with anyone else.

What drives the price

  • How many applications and servers are in scope
  • How many kinds of users and rights exist
  • Whether the code needs reviewing too, not only the behaviour
  • Whether the re-check after repairs is included

What you should know upfront

  • No check guarantees there is absolutely nothing left. We tell you what we looked for and what we found, not that you are invulnerable.
  • We work only with your written agreement and only within the limits we set together.
  • What we learn about you stays between us. We do not use the results anywhere and we show them to nobody.

Frequently asked

Can the check break something of mine?

We agree upfront what is allowed and what is not. If you prefer, we work on a copy of the system rather than the one in daily use. Risk is discussed before, not after.

Would an antivirus not be simpler?

An antivirus protects computers from malicious programs. It has no way of knowing that in your application one user can see another client's data. They are different things.

What do I do if you find something serious?

You hear the same day, not at the end of the work. We tell you immediately what can be done as a quick measure and what needs fixing properly.

Do you have to have built the application?

No. We check systems built by others too. That is often exactly the situation.

Not sure this is the right service?

Write to us about what is getting in the way, in your own words. We will tell you which option fits — or whether none of them does.