Skip to content
B
19 services

Cybersecurity

Compliance with Cybersecurity Law No. 48/2023 (in force since 01.01.2025). Requirements for providers in critical sectors.

All services in this category

CodeServicePrice
B.1.1Applicability determination

We determine whether the client falls under the law as 'essential' or 'important' provider.

1,320Details
B.1.2Provider registry registration

Preparation and submission of documents to the competent national cybersecurity authority.

1,320Details
B.2.1Network and systems security policy

Top-level document required by law.

1,320Details
B.2.2Risk Management framework

Risk register, likelihood/impact matrix, treatment plan, annual review.

1,560Details
B.2.3Asset Management — IT inventory

CMDB, automated inventory of servers, containers, SaaS subscriptions, certificates.

1,920Details
B.2.4Network segmentation

Separation of production/test/office networks; Zero Trust / microsegmentation.

1,920Details
B.2.5Backup and recovery (BCP/DRP)

3-2-1 strategy, immutable backups, restoration tests.

1,920Details
B.2.6Vulnerability management

Nessus/Trivy/OpenVAS deployment, CVSS-based remediation, patching SLA.

1,560Details
B.2.7Endpoint protection

EDR/AV on servers and workstations, central management, 24/7 alert response.

Monthly480Details
B.2.8Supply chain security

Vendor verification, SBOM, security questionnaire for vendors.

1,560Details
B.3.1Incident detection and classification procedure

Distinction between incident / significant incident / near-miss.

1,320Details
B.3.2Authority notification procedure

Templates: early warning, interim report, final report.

1,320Details
B.3.3Coordinated Vulnerability Disclosure (CVD) program

Public security.txt page, disclosure policy, researcher interaction process.

1,320Details
B.3.4SIEM / Log Management

Wazuh / Graylog / ELK deployment, event correlation, alerts, dashboards.

3,120Details
B.3.5SOC-as-a-Service (24/7)

Our team monitors 24/7, responds per runbook, escalates incidents.

Monthly1,800Details
B.4.1External pentest (Black-box / Grey-box)

External perimeter attack simulation, CVSS report, recommendations.

1,920Details
B.4.2Internal pentest

Penetration test from a compromised employee's position.

1,920Details
B.4.3Web app audit OWASP Top 10 / ASVS

Full audit of a single web application focusing on OWASP Top 10 and ASVS standard.

1,560Details
B.4.4Employee phishing simulations

Regular campaigns, click-rate metrics, training based on results.

Quarterly350Details