2026-08-14
Your First Security Hire Should Not Be Full-Time
Small companies handling sensitive data need real security. A full-time senior hire is usually the wrong first move, and here is why.
Read postAt full delivery capacity until the end of 2026.
SteadySec is a boutique security firm for European small and medium companies. We turn regulation, customer pressure, and scattered technical work into a practical security programme. We stay deliberately small and the work is done by named senior people, so you always know who is doing it.
How We Work
Certificates and reports are the easy part of choosing a security partner. Before you work with us, you should understand how we think, what we believe good security looks like, and whether our style fits the way your company makes decisions.
We prefer documented processes over quick fixes. Quick fixes are workarounds that quietly become problems later. When one is genuinely needed we will do it - then write it down and feed it back into the process. The working pattern is Plan, Do, Check, Act: agree it, run it, measure it, improve it.
Management owns the business risk. Our job is to make it visible, reduce it with sensible controls, and help you decide what to accept, transfer, or fix first.
BEST FIT
European small and medium companies up to roughly 250 people. Headcount matters less than the size of the IT footprint supporting the business - facing ISO 27001 readiness, customer due diligence, or NIS2 scope questions.
STARTING POINT
Assessment first, then a retainer if you need an ongoing rhythm for implementation and security decisions.
Who You Work With
SteadySec today is one person. Petr Pospíšil scopes, leads, and delivers every engagement personally - there is no account manager between you and the work. Where an engagement needs deeper offensive or governance capacity, independent senior collaborators join for that scope.
Founder - vCISO & Security Architect
Leads every engagement. CISSP, ISO 27001 Lead Auditor, GIAC threat intelligence and detection credentials, with OSCE and UNDP capacity-building experience across Europe.
Read profileWHO DOES THE WORK
The person you meet in the first call is the person doing the work - from assessment and review through to implementation and management reporting. Nothing is handed down to a junior you never met.
WHY "WE"
SteadySec is built as a firm, not a personal brand. Independent senior practitioners join engagements where their craft is needed, and they are named to you before the work starts.
CAPACITY, HONESTLY
One founder means a limited number of retainers at any time. If an engagement does not fit the calendar or the skill set, we say so and point you somewhere sensible rather than stretching to cover it.
What We Believe
Independence is the difference between security advice you can trust and a sales conversation in disguise. These rules apply to every engagement, SME or enterprise.
Vendor-neutral
We do not take commissions, referral fees, or revenue share from tool vendors. If we recommend a product, it is because it fits your problem - not because someone is paying for the slot.
Open-source-first for SMEs
For an SME with limited security budget, an open-source tool that runs well for years is usually a better answer than a per-seat licence. Lower cost, no lock-in, and your data stays where you control it.
Commercial when it earns its place
Paid tools are recommended when they materially reduce risk or operational load - for example, where managed support, regulatory features, or scale make the licence cost worth it. Never by default.
Collaboration
SteadySec is not hiring employees. We work with independent senior practitioners who run their own practice and want a partner firm for the parts they do best. You keep your independence, your rates, and your other clients. Two areas are open for collaboration.
Freelance collaboration
Penetration testing, red teaming, and the wider technical assessment track. Security is too broad a field to cover alone. If you run this craft independently and want a partner firm to bring you into scoped engagements, get in touch.
How we would work togetherFreelance collaboration
ISO 27001, NIS2, and supplier-assurance depth for governance-heavy engagements. If this is your craft and you work independently, there is room to own it here without giving up your own practice.
How we would work togetherFrom the Blog
2026-08-14
Small companies handling sensitive data need real security. A full-time senior hire is usually the wrong first move, and here is why.
Read post2026-07-07
Most SMEs buy security without knowing whether it worked. A small, decision-focused set of metrics that shows if you are harder to attack.
Read post2026-06-26
A plain-English starter on the EU AI Act for SMEs. If your company uses AI tools rather than builds them, here is what actually applies.
Read postGet started