SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

Senior capabilities

The primary engagement at SteadySec is the Retained Security Partner for founder-led SMEs. The work below is senior security work Petr has led inside larger organisations. It is listed so the work is findable. It is not being sold as a packaged service.

These engagements assume an organisation already operates around CIS IG3 or a mature, working ISMS under ISO 27001. If you are establishing the baseline first, the SME paths are the right entry point.

Enterprise track record

Four areas of work

Each entry below is work Petr has led or built inside a larger organisation. The scope, team structure, and reporting line are agreed before any engagement starts.

DevSecOps

Security built into the pipeline

Threat modelling at design, SAST and DAST gating in the build, SBOM and supply-chain controls, secret scanning, IaC review, signed builds, and runtime feedback that reaches developers without slowing the team down.

The goal is fewer late-stage findings and a release process that engineering trusts.

Cyber Threat Intelligence

Standing up a CTI function

Setting up the function end to end: the mandate and source mix (OSINT, commercial feeds, ISAC membership), analyst tasking and tradecraft, a reporting cadence for both the SOC and the board, and integration with detection engineering and risk management.

We have built this capability inside a large enterprise, from charter to first board-level briefing.

Threat Hunting

Hypothesis-driven hunting

Hunting cycles built on concrete hypotheses, purple-team loops with the SOC, and measurable coverage against MITRE ATT&CK - not a generic dashboard.

Findings feed back into detection content, so each hunt improves the standing posture.

Incident Response & Crisis

Leading major incidents

Incident command, coordination across legal, communications and the executive team, regulator notifications where they apply, and post-incident review that changes controls instead of producing a long document.

Available as senior support to an existing IR function, not as a 24/7 SOC replacement.

When this is for you

Who this fits

Fits

  • A working ISMS with active risk treatment, evidence and review cycles.
  • A dedicated security team or SOC already in place.
  • Regular board-level security reporting.
  • Budget and mandate for senior advisory work on a defined initiative.

If this matches you, use the Discovery Calculator to size a retainer around the capability you need. We agree the goal, then mature the programme month by month.

Open Discovery Calculator

Does not fit yet

  • Still building a baseline. Start with the SME retainer instead.
  • Looking for a 24/7 managed SOC. This is advisory work, not an operational replacement.
  • Looking for a fixed-scope project. This senior work runs by retainer, sized in hours against an agreed goal.

If the SME retainer is the better starting point, see Retained Security Partner, Practical Security, or ISO 27001.

If the scope fits

Ready to start?

Engagements at this level start with a scoping conversation, not a proposal template. Pick whichever channel suits you.