At full delivery capacity until the end of 2026.
Frequently asked questions
These are the questions worth asking before any engagement. We have written the answers here so you know what you are walking into.
Working Together
What does a vCISO actually do, and how is it different from hiring a full-time one? +
A full-time CISO in Central Europe typically costs €80,000-150,000 a year in salary alone, plus benefits, and is often more than a company needs before it has a mature security programme. A vCISO gives you the same strategic leadership (security roadmap, risk management, vendor oversight, board-level reporting, compliance) on a retainer that scales to what you actually need. Because we work across several clients, patterns from one environment inform the next.
How much does it cost to work with you? Do you offer fixed-price packages or hourly rates? +
Retainer pricing is published for the standard engagement levels: the monthly tiers and the fixed-price Starter Assessment and Starter Month are all listed on the Retained Security Partner page. The exact tier is confirmed after the Starter Assessment or Starter Month, because company size, urgency, regulatory pressure, and implementation workload change the real effort. Fixed-scope projects such as penetration tests and audits are quoted separately based on scope. The best starting point is the free Discovery Calculator.
Do you work only in the Czech Republic or across Europe? +
SteadySec is registered in Prague and most of the work has been with Czech companies, but international work is a natural part of how we operate. We have run training programmes for OSCE and UNDP in Bosnia and Herzegovina, worked with Dutch companies, and taken on US-based clients as well. Remote engagements work well across time zones for strategy and advisory work, and on-site delivery is possible anywhere with reasonable notice.
How quickly can you start, and what does the onboarding look like? +
For retainer engagements, we typically start within 2-4 weeks of signing. The first month is discovery: we review your existing policies, infrastructure, contracts, and risk landscape before making any recommendations. For a penetration test, scoping and scheduling usually takes 1-2 weeks, and execution follows shortly after.
Do you work with companies that have no existing security setup? +
Yes, and that is where the impact is highest. Starting from scratch means we can build things correctly from the beginning rather than retrofitting security onto bad foundations. We have worked with companies whose entire "security policy" was a Post-it note. There is no judgement in it. What matters is where you need to be.
If we have a security incident while you are on retainer, who carries the responsibility? +
Legally, the duties sit with your company and its management. NIS2, GDPR, and ISO 27001 all place risk acceptance and the final decisions with the organisation itself, not with an external advisor, and a retainer does not move that. What the retainer changes is how prepared you are: risks assessed and written down, the highest-priority controls in place, incident response exercised rather than only documented, and the evidence of all three available when a customer, insurer, or regulator asks. We run the programme, recommend the treatment, implement or guide the fix, and say plainly where residual risk remains, including where a risk is better transferred through insurance than reduced further. No security programme removes the possibility of an incident, and nobody credible will tell you otherwise. What you get is a defensible position and a rehearsed response.
Can you sign an NDA before we discuss our environment? +
Yes, always. We do not ask clients to expose their architecture, vulnerabilities, or compliance gaps without a mutual NDA in place. If you want to send one before our first call, we will review and return it within 24 hours. If you do not have a template, we have a standard one we use.
Do you have references or case studies I can see? +
Most of our clients operate in regulated sectors and prefer confidentiality, and we respect that. For public references, Petr's work with OSCE and UNDP on cyber security capacity building in Bosnia and Herzegovina is documented and we are happy to share details. For commercial clients, we can provide anonymised case study summaries on request, or in some cases arrange a direct reference call after a signed NDA.
NIS2 & Compliance
Is my company affected by NIS2? How do I know if I need to comply? +
NIS2 applies to medium and large companies (50 or more employees, or annual turnover above €10 million) operating in critical sectors: energy, transport, health, digital infrastructure, manufacturing, financial services, postal services, and others. It also applies to their supply chains in some cases, which means smaller companies can be pulled in indirectly. If you are unsure whether it applies to you, that uncertainty is itself a risk worth resolving. We can assess your scope in a single consultation.
How long does NIS2 compliance typically take? +
For a company starting from zero, realistic full compliance takes 6-18 months depending on company size and existing controls. Demonstrable progress matters, though. Showing regulators a structured roadmap and active implementation is far better than doing nothing while you wait for a perfect plan. We typically prioritise the highest-risk gaps first so you have a defensible position within the first 90 days.
What happens if my company fails a NIS2 audit? +
NIS2 enforcement sits with national authorities; in the Czech Republic that is NÚKIB. Penalties for essential entities can reach €10 million or 2% of global annual turnover, whichever is higher. For important entities the cap is €7 million or 1.4%. Beyond fines, there is mandatory incident reporting and potential personal liability for senior management. That last point is new and important: NIS2 explicitly holds C-suite executives accountable, not just the IT department.
What is the difference between NIS2 and ISO 27001, and do I need both? +
They solve related but different problems. ISO 27001 is an international management standard, a voluntary certification that proves to customers and partners that you manage information security systematically. NIS2 is EU law, a legal obligation with regulatory consequences. They overlap significantly. Implementing ISO 27001 covers a large portion of NIS2's technical requirements, so doing both together is more efficient than tackling them separately. We typically run them in parallel.
Cyber Resilience Act
Does the Cyber Resilience Act apply to small companies? +
Yes. The CRA has no size threshold: it applies to anyone placing a product with digital elements on the EU market, from a two-person firmware shop to a multinational. What changes with size is the burden, not the scope. Micro and small enterprises may use a simplified technical documentation format (Article 33(5)), fines are adapted for SMEs, and the Commission's July 2026 guidance is written around SME cases. Small does not mean exempt - it means the compliance programme should be proportionate.
Does the CRA apply to software, or only to hardware? +
Both. The CRA covers products with digital elements: hardware with embedded software or firmware, and software placed on the market on its own - applications, mobile apps, libraries, and components sold or licensed commercially. A common trap is the machinery manufacturer who answers "we do not sell software" while shipping devices full of firmware, or the company that white-labels a supplier's product under its own name and thereby becomes the manufacturer in law.
What is a CRA technical file? +
The technical documentation set out in Annex VII of the regulation: a description of the product and its intended use, the cybersecurity risk assessment, evidence of how the Annex I requirements are met, the SBOM, test reports, and the vulnerability handling process. It must be drawn up before the product goes to market and kept for 10 years or the support period, whichever is longer. It is the evidence behind your EU Declaration of Conformity and CE marking - not a formality you write afterwards.
Do I need an SBOM under the CRA? +
Yes, if you are the manufacturer. The CRA requires a Software Bill of Materials in a commonly used, machine-readable format covering at least the top-level dependencies of the product. SPDX and CycloneDX are the common format choices, but the regulation names the properties, not a specific format - what does not count is a PDF or a spreadsheet nobody updates. The SBOM is part of the technical documentation and has to stay current as the product changes.
Penetration Testing
What is the difference between a vulnerability scan and a penetration test? +
A vulnerability scan is automated: a tool checks your systems against a database of known weaknesses and produces a list. It is fast and cheap but tells you what might be exploitable, not what actually is. A penetration test is manual work. We use a combination of tools and human judgement to chain together vulnerabilities, bypass controls, and demonstrate real-world impact. The difference is like a metal detector versus a locksmith. One finds something, the other tells you whether it actually opens.
How disruptive is a pentest? Will it take systems offline? +
Only if we agree in advance that it should. For web application testing we always prefer working against a non-production environment, which eliminates any risk of impacting live users and also maximises the attack surface, since production environments are often locked down in ways that hide vulnerabilities that would be reachable in reality. For network and infrastructure tests we define the rules of engagement upfront: scope, excluded systems, out-of-hours restrictions, and emergency contacts. No client has had unplanned production downtime from our testing.
Do you test black-box or white-box, and does it affect the price? +
We always prefer white-box, for a straightforward reason: we are your consultants, not your enemy. You are paying us to find and exploit vulnerabilities, not to spend days mapping your application. A real attacker has unlimited time; every hour we spend on discovery is a billable hour that produces no findings. Share what we need (API documentation, role definitions, architecture overview) and we skip discovery and go straight to exploitation. In practice that means more findings in the same testing window. Black-box testing is valid if you specifically want to simulate an external attacker with no prior knowledge, but it takes longer to reach the same coverage. The choice is yours, and we will always recommend sharing the information.
What do I get at the end of a pentest, and who is it written for? +
You get a written report with two sections. The first is an executive summary: a plain-language explanation of what was found, the business risk, and the priority order for fixing it, written for a CEO or board member who does not need to know what SQL injection is. The second is a technical appendix: full reproduction steps, tool output, evidence screenshots, and specific remediation guidance for your IT team. We also walk through the findings on a call so questions get answered immediately, not buried in an inbox.
How often should we run a penetration test? +
At minimum, once a year and after any significant infrastructure change: a new application, cloud migration, acquisition, or major code release. NIS2 and ISO 27001 both expect regular testing as part of a risk management programme. For companies with active development cycles, we recommend quarterly reviews of new attack surface, with a full test annually.
Question not answered here?
Ask us directly
Send the question. I read everything and reply with a straight answer about whether this is something I can help with.