SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

About SteadySec

SteadySec is a boutique security firm for European small and medium companies. We turn regulation, customer pressure, and scattered technical work into a practical security programme. We stay deliberately small and the work is done by named senior people, so you always know who is doing it.

How We Work

Our approach

Certificates and reports are the easy part of choosing a security partner. Before you work with us, you should understand how we think, what we believe good security looks like, and whether our style fits the way your company makes decisions.

We prefer documented processes over quick fixes. Quick fixes are workarounds that quietly become problems later. When one is genuinely needed we will do it - then write it down and feed it back into the process. The working pattern is Plan, Do, Check, Act: agree it, run it, measure it, improve it.

Management owns the business risk. Our job is to make it visible, reduce it with sensible controls, and help you decide what to accept, transfer, or fix first.

BEST FIT

European small and medium companies up to roughly 250 people. Headcount matters less than the size of the IT footprint supporting the business - facing ISO 27001 readiness, customer due diligence, or NIS2 scope questions.

STARTING POINT

Assessment first, then a retainer if you need an ongoing rhythm for implementation and security decisions.

Who You Work With

Led and delivered by the founder

SteadySec today is one person. Petr Pospíšil scopes, leads, and delivers every engagement personally - there is no account manager between you and the work. Where an engagement needs deeper offensive or governance capacity, independent senior collaborators join for that scope.

Petr Pospíšil at an OSCE capacity-building programme

Petr Pospíšil

Founder - vCISO & Security Architect

Leads every engagement. CISSP, ISO 27001 Lead Auditor, GIAC threat intelligence and detection credentials, with OSCE and UNDP capacity-building experience across Europe.

Read profile

WHO DOES THE WORK

The person you meet in the first call is the person doing the work - from assessment and review through to implementation and management reporting. Nothing is handed down to a junior you never met.

WHY "WE"

SteadySec is built as a firm, not a personal brand. Independent senior practitioners join engagements where their craft is needed, and they are named to you before the work starts.

CAPACITY, HONESTLY

One founder means a limited number of retainers at any time. If an engagement does not fit the calendar or the skill set, we say so and point you somewhere sensible rather than stretching to cover it.

What We Believe

Our working rules

Independence is the difference between security advice you can trust and a sales conversation in disguise. These rules apply to every engagement, SME or enterprise.

Vendor-neutral

We do not take commissions, referral fees, or revenue share from tool vendors. If we recommend a product, it is because it fits your problem - not because someone is paying for the slot.

Open-source-first for SMEs

For an SME with limited security budget, an open-source tool that runs well for years is usually a better answer than a per-seat licence. Lower cost, no lock-in, and your data stays where you control it.

Commercial when it earns its place

Paid tools are recommended when they materially reduce risk or operational load - for example, where managed support, regulatory features, or scale make the licence cost worth it. Never by default.

From the Blog

Recent writing

Get started

Work with a security partner you can name

Start with an assessment. We will map where you are, what genuinely needs attention, and the practical next steps - no inflated scope, no pressure.