Service 03

Cyber security solutions

Most breaches are boring, documented, and preventable. We reduce the number of ways in, shorten the time an intruder goes unnoticed, and leave your team a runbook they have actually rehearsed.

  • Zero trust
  • Identity hardening
  • Segmentation
  • Detection engineering
  • SOC enablement
  • Incident response

The problem

Perimeters age. Credentials leak.

The interesting attacks make the news. The ones that happen to you are usually older and duller: a credential reused from a breach four years ago, a service account with permissions nobody has reviewed since it was created, a flat network where reaching one machine means reaching all of them.

Detection is the other half. Most organisations find out from a customer, a partner, or an extortion note — not from their own logs. Dwell time, not the initial foothold, is what turns an incident into a disaster.

What we install

Controls your own team can operate on a Tuesday, not a platform that needs a specialist to breathe.

01

Zero-trust segmentation

Flat networks become segments with explicit paths between them. Reaching one host stops meaning reaching the estate.

02

Identity hardening

Short-lived credentials, enforced MFA, service accounts scoped to their actual job, and a review process that runs without being chased.

03

Detection engineering

Detections written against your systems and tuned on your data — so alerts mean something and the team stops ignoring the channel.

04

Logging that survives

Centralised, retained, and tamper-evident. An attacker who clears a local log does not clear your evidence.

05

SOC enablement

Your team gets the runbooks, triage paths, and escalation criteria to run the watch themselves, with us behind them rather than in front.

06

Rehearsed response

We walk the runbook with the people who would use it, at an awkward hour, until it is boring. A plan nobody has practised is a document, not a capability.

What we assess first

Concrete, not theoretical.

  • Identity and access — Who can reach what, with which credential, and how long it lives. Usually the fastest risk reduction available.
  • Network paths — What talks to what today versus what needs to. Segmentation follows the answer.
  • Exposure — What is reachable from the internet, including the things nobody remembered were published.
  • Detection coverage — Which techniques you would actually notice, mapped honestly against the ones you would not.
  • Backup and recovery — Whether a restore has been tested this year, and whether backups survive an attacker with admin rights.
  • Third parties — The vendors and integrations with standing access to your systems and data.

What you get

Each step ends in something you can inspect.

  • Week oneA prioritised findings list with the fixes ordered by risk reduced per day of work — not an alphabetised inventory of everything.
  • ThenThe high-value controls implemented: identity, segmentation, logging. Measured before and after.
  • ThenDetections written and tuned, with the runbook to go with each one.
  • OngoingRehearsals, drift checks, and a named escalation path for when something does happen.

Questions

Straight answers.

Is this a penetration test?

A test tells you what an attacker could do on one day. This is the engineering that changes the answer: closing paths, hardening identity, and making sure you would see it next time. We are happy to work alongside your testers, or to fix what their report found.

We already have antivirus and a firewall.

So did most of the organisations in this year's breach reports. Those tools stop commodity noise. They do not address reused credentials, over-permissioned service accounts, flat internal networks, or the absence of anyone watching the logs.

Can our team run this afterwards?

That is the point. We deliberately avoid leaving behind a platform only we understand. You get runbooks, tuned detections, and rehearsals with the people who will be on the call at three in the morning.

Do you work with companies outside Serbia?

Yes. We work from Novi Sad across Europe, on Central European Time, so a normal working day overlaps with every European office.

Contact

Name the perimeter that has to hold.

Tell us what you are protecting and what worries you about it. An engineer reads the brief, and we answer from Novi Sad within one business day.