Cybersecurity as a managed service
We help organisations establish, govern and continuously verify cybersecurity in line with the requirements of the new Czech Cybersecurity Act, Decree No. 409/2025 Coll. and NIS2 principles. We provide the key roles of CS manager, architect and auditor as an external service — expertly, independently and with an emphasis on security that actually works in day-to-day operations.
From requirements to real implementation
Beyond security governance we also offer complementary expert services that translate requirements into concrete projects, technologies and architectural decisions — project management and enterprise architecture. The requirements of Decree 409/2025 Coll. reach not only into governance and audit, but also into change management, acquisition, development, maintenance and secure system architecture.
Key benefits
- Alignment with Decree No. 409/2025 Coll. and NIS2 principles
- CS manager, architect and auditor roles as an external service
- Auditor separated from the manager and architect roles
- Emphasis on security that works in real operations
Key cybersecurity roles
CS Manager
The CS Manager (CSM) is a key role responsible for governing cybersecurity in the organisation, coordinating the implementation of measures and ensuring that security is not just formal documentation but a genuinely functioning system. In the higher-obligations regime it is one of the principal roles under current Czech legislation (Decree No. 409/2025 Coll., NIS2).
What the Manager service typically covers
- Governing the rollout and development of the ISMS and related documentation
- Coordinating risk management and proposing priorities for measures
- Managing incident readiness and obligations towards NÚKIB
- Regular reporting to leadership and support for decision-making
- Preparing the organisation for audits, inspections and reviews
Benefit for the organisation: The Manager brings the organisation a governance layer for cybersecurity — connecting legal requirements, risk management, internal processes and measures into one functioning whole. The organisation gains an accountable person who governs security systematically, demonstrably and in line with business needs.
CS Architect
The CS Architect (CSA) is responsible for designing and implementing security measures and ensuring that security is reflected in the organisation's technical and application architecture. They design the secure arrangement of infrastructure, systems, applications and changes so that they match real threats, risks and regulatory requirements.
What the Architect service typically covers
- Designing secure architecture for systems, networks, applications and services
- Designing and implementing technical measures with regard to risks and operations
- Embedding security into change management, acquisition, development and maintenance
- Assessing architectural options and technology decisions
- Supporting security architecture across infrastructure, cloud and applications
Benefit for the organisation: The Architect helps introduce security systematically, sustainably and in a technically sound way. Measures are not handled in isolation but form a consistent architecture supporting operations, change and the organisation's future development.
CS Auditor
The CS Auditor provides an independent, impartial view of whether security measures are set up correctly, work in practice and meet the requirements of legislation, internal rules and suitable standards. In the higher regime it is a standalone role that must be separated from performing the Manager and Architect roles.
What the Auditor service typically covers
- Planning and carrying out cybersecurity audits and partial internal reviews
- Assessing compliance of the ISMS and measures with legislation and rules
- Verifying the appropriateness and effectiveness of measures on all levels
- Producing the audit report, priorities and recommended corrective measures
- Supporting preparation for a NÚKIB inspection, customer or certification audit
Benefit for the organisation: The Auditor brings an independent reality check — showing what truly works, where the weak spots are and which measures have the highest priority. The outcome is not a formality, but a practical basis for increasing the organisation's resilience.
Complementary services beyond the CS roles
By combining security roles with project management and enterprise architecture, the organisation gains not only formal compliance but, above all, the practical ability to actually put security into operation — into concrete technologies, projects and the long-term architecture of the environment.
Project management
Running specific security initiatives from brief to delivery. Especially suitable where regulatory or security requirements need to be translated into concrete projects, infrastructure changes, technology implementations or post-audit corrective measures. Decree 409/2025 Coll. directly relates to change management, acquisition, development and maintenance.
We typically provide
- Coordination of security projects and corrective-measure roadmaps
- Managing the implementation of technical and organisational measures
- Coordinating internal teams, suppliers and external specialists
- Overseeing deadlines, priorities, budget and project outputs
- Translating audit findings and requirements into real implementation steps
Enterprise architect
Designing the organisation's target technology environment in a broader context. While the CS Architect focuses on security architecture, the enterprise architect helps design concrete technologies, platforms and products so that the resulting solution is not only secure but also operationally sustainable, cost-efficient and compatible with the organisation's overall architecture.
We typically provide
- Designing the target architecture of technologies and services per business and security
- Selecting suitable technologies, platforms and specific vendors
- Assessing the impact of technologies on security, operations, integration and growth
- Architectural support for modernising infrastructure, cloud, networks and identities
- Aligning security, technology and investment decisions
Got a project? Let's talk.
Whether you're solving a mechanical platform, IT transformation, cybersecurity or a construction project — we'd be glad to look at it together.
Contact us