SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

The Team

Petr Pospíšil

Founder - vCISO & Security Architect

Advisory, architecture, and hands-on implementation

A relaxed but direct security advisor. Petr leads every SteadySec engagement, combining hands-on technical depth with the business judgement to decide what genuinely needs attention first.

Petr Pospíšil at an OSCE capacity-building programme

Petr Pospíšil

vCISO & Security Architect

How I Work

My approach

I prefer documented processes over quick fixes. Quick fixes are workarounds that quietly become problems later. When one is genuinely needed I will do it - then write it down and feed it back into the process. The working pattern is Plan, Do, Check, Act: agree it, run it, measure it, improve it.

Management owns the business risk. My job is to make it visible, reduce it with sensible controls, and help you decide what to accept, transfer, or fix first.

BEST FIT

European small and medium companies up to roughly 250 people. Headcount matters less than the size of the IT footprint supporting the business - facing ISO 27001 readiness, customer due diligence, or NIS2 scope questions.

STARTING POINT

Assessment first, then retainer if you need an ongoing rhythm for implementation and security decisions.

Background

Career path

From breaking systems, to defending them, to owning the strategy. Ten years in total, and each stage changes how I read risk today.

01

Ethical hacker / Penetration tester

Penetration testing and red teaming. Testing defences by attacking them, and proving how an intrusion would really succeed.

02

Threat hunter / L2-L3 Security Analyst

The other side of the same problem: hunting intruders already inside, and investigating the incidents when an alarm did fire.

03

Cyberdefense and Operations Manager

Running defence for a global retail enterprise, focused on threat intelligence and strategy.

04

Independent security consultant

Advising European organisations on security, architecture and compliance, with assignments for UNDP, OSCE and an EU CSDP mission alongside the SteadySec client base.

Institutional Work

Affiliations and certifications

Alongside client work, I sit on the EU CyberNet and UNDP expert rosters, deliver capacity-building for OSCE and UNDP, and am currently contracted as a cybersecurity expert on an EU CSDP mission.

EU CyberNet

EU CyberNet

Roster of EU experts

Listed on the EU expert roster. Trained at the EU CyberNet Summer Schools in Berlin (2025) and Lisbon (2024).

UNDP

UNDP

Expert roster

Vetted UN cybersecurity expert - cleared for global deployment on capacity-building programmes.

EEAS

CSDP mission

Contracted cybersecurity expert on an EU Common Security and Defence Policy mission.

Certifications

Certifications matter less than judgement, but for some engagements they are the door-opener. Each one below names its awarding body and what it evidences, so you can weigh it rather than count it. All badges are publicly verifiable: verify every credential.

CISSP

ISC2

The credential most enterprise procurement teams look for. Covers security management across governance, architecture and operations rather than a single product.

Certified Information Systems Security Professional

ISO 27001 Lead Auditor

IRCA certified course

Trained to audit an ISMS against the standard. It means readiness work is shaped by what a certification auditor will actually test.

ISO/IEC 27001:2022 Lead Auditor

GCTI

GIAC

Threat intelligence: turning what attackers are doing into decisions about what to defend first.

GIAC Cyber Threat Intelligence

GCDA

GIAC

Detection engineering and monitoring: whether your logging would actually catch an intrusion.

GIAC Certified Detection Analyst

CRTP

Altered Security

Hands-on Active Directory attack technique. This is the practical basis for the AD assessment work.

Certified Red Team Professional

SecurityX

CompTIA

Enterprise security architecture: designing controls that hold together across a whole estate, not per system.

CompTIA SecurityX (formerly CASP+)

Also held

  • CySA+ / CompTIA
  • PenTest+ / CompTIA
  • eCPPT / INE Security
  • SC-200 / Microsoft
  • Splunk Admin / Splunk
  • Splunk Power User / Splunk
  • Splunk User / Splunk

Beyond the SME engagement

Senior work in larger organisations

The main engagement is the SME retainer. Outside of that, I have led security work inside larger organisations: DevSecOps across the pipeline, building a Cyber Threat Intelligence function, threat hunting programmes, and major incident response.

This depth is relevant once an organisation runs a mature ISMS or operates around CIS IG3. If that describes you, the capabilities page lists where I can help.

See senior capabilities

Relevant only if your organisation is already operating a mature ISMS. Otherwise the SME retainer is the right place to start.

Get started

Start a conversation with Petr

An assessment first, then a retainer if you need an ongoing rhythm. Direct advice, practical priorities, and security work your team can actually maintain.