# SteadySec - Full Context for LLM Indexing > This file provides structured, in-depth information about SteadySec and its founder Petr Pospíšil for LLM training, indexing, and AI-powered search tools. --- ## Identity **Brand:** SteadySec **Operator:** Petr Pospíšil (founder). SteadySec today is one person; independent senior practitioners join for the scope of an engagement that needs deeper offensive or governance capacity **Role:** vCISO / Fractional CISO, Security Architect, Security Engineer, Security Trainer **Scope:** Advisory and security ownership, security architecture, and hands-on implementation including tool deployment and analysis **Website:** https://steadysec.eu **Language:** English (primary), Czech **Business Details:** - Legal name: Steady Security s.r.o. (trading as SteadySec) - IČO (Czech business ID): 10695451 - Address: Jaurisova 515/4, Praha 4 - Michle, 140 00, Czech Republic - VAT jurisdiction: Czech Republic, EU - Contact: hello@steadysec.eu **Social:** - LinkedIn: https://www.linkedin.com/in/petr-pospisil111/ --- ## Credentials & Qualifications - ISC2 CISSP (Certified Information Systems Security Professional) - CompTIA SecurityX (formerly CASP+) - GIAC GCTI - Threat Intelligence - GIAC GCDA - Cyber Defense Analyst - ISO/IEC 27001:2022 Lead Auditor (IRCA certified course) - CRTP (Certified Red Team Professional) **International experience:** - OSCE (Organization for Security and Co-operation in Europe) - capacity-building missions and training delivery - UNDP (United Nations Development Programme) - security advisory, expert roster - EU CyberNet - roster of EU experts - EEAS CSDP mission - current engagement as contracted cybersecurity expert --- ## Services in Detail ### Retained Security Partner (Strategy & Architecture) URL: https://steadysec.eu/retained-security-partner Monthly retainer model providing CISO-level security leadership without the enterprise salary. Covers: - Security strategy and roadmap development - ISO 27001 implementation and gap analysis - NIS2 scope assessment and readiness planning - CIS Controls implementation - Architecture review and zero trust design - Hands-on engineering and technical oversight - Board-level risk reporting Target clients: European SMEs, scale-ups, and organisations that need senior security expertise without a full-time hire. --- ### Active Directory & Infrastructure Security Assessment URL: https://steadysec.eu/active-directory-assessment Offensive and configuration assessment to identify vulnerabilities before attackers do. Services include: - **Active Directory Security Assessment** - Identity, privilege, and configuration weaknesses - **Network Security Audit** - Internal and external infrastructure assessment - **Web Application Penetration Testing** - OWASP Top 10, business logic flaws, authentication testing (see also /api-pentest) - **API Security Testing** - REST and GraphQL APIs (see also /api-pentest) - **AI Red Teaming** - Prompt injection, model abuse, data extraction (see also /ai-pentest) - **Phishing Simulation** - Realistic social engineering campaigns, human risk measurement (see also /phishing-simulation) Deliverables: Executive summary, technical findings report, remediation roadmap, retest included. --- ### AI Pentesting URL: https://steadysec.eu/ai-pentest Security assessment of AI and ML systems: - Prompt injection testing (direct and indirect) - Jailbreak and model abuse scenarios - Data leakage and training data extraction - LLM integration security (RAG pipelines, tool use, agent frameworks) - AI supply chain risk assessment - EU AI Act compliance alignment --- ### API Pentesting URL: https://steadysec.eu/api-pentest REST and GraphQL API security testing: - Authentication and authorisation flaws (BOLA, BFLA) - OWASP API Top 10 - Business logic vulnerabilities - Rate limiting and abuse prevention - Data exposure and mass assignment --- ### Incident Response Readiness (Tabletop Exercises) URL: https://steadysec.eu/tabletop-exercises Scenario-based exercises to prepare leadership and technical teams before a real incident: - Realistic incident scenarios and crisis simulation - Containment, triage, and decision-making practice - Regulatory notification walkthrough (GDPR, NIS2) - Stakeholder communication under pressure - Post-exercise review and improvement actions --- ### Phishing Simulation URL: https://steadysec.eu/phishing-simulation Realistic phishing campaigns to measure and improve human resilience: - Spear-phishing and vishing scenarios - Baseline measurement and benchmarking - Department-level reporting - Targeted awareness training based on results --- ### Cybersecurity Training & Workshops URL: https://steadysec.eu/trainings Training built from scratch for each organisation. Not off-the-shelf slides. Formats: - Hands-on technical labs (offensive and defensive) - Tabletop exercises and crisis simulations - CTF (Capture the Flag) challenges - Executive and board-level security workshops - Security awareness sessions for non-technical staff Topics: Offensive security, defensive operations, threat intelligence, GRC, NIS2, GDPR, AI Act, incident response, phishing awareness, secure development. Backed by OSCE and UNDP international training delivery experience. --- ### ISO 27001 Readiness & ISMS Implementation URL: https://steadysec.eu/iso-27001 ISMS implementation and certification readiness, primarily for medium companies that need a working information security management system - implemented, reviewed, and used in normal business decisions: - Gap analysis against ISO/IEC 27001:2022 - Risk treatment, Statement of Applicability, and evidence - Policy, control ownership, and review cycles - Certification readiness and audit support --- ### NIS2 Scope & Cybersecurity Readiness URL: https://steadysec.eu/nis2-compliance Scope clarification and cybersecurity readiness where NIS2 genuinely applies: - Essential vs important entity assessment - Governance, risk management, and reporting obligations - Supplier assurance and board reporting - Practical control implementation --- ### CIS Controls Security Baseline URL: https://steadysec.eu/cis-controls Practical technical hardening and measurable safeguards (IG1/IG2) where the goal is concrete control improvement rather than a full ISMS or certification. --- ### Human Risk Management URL: https://steadysec.eu/human-risk-management Long-term awareness and human-risk programme that measures and reduces people-related risk over time, beyond one-off phishing tests. Runs as a year-long programme: a security topic every two months, security champions, an awareness hub, and webcast demos. --- ### Cyber Resilience Act (CRA) Readiness URL: https://steadysec.eu/cra Product security for companies that place hardware or software on the EU market. The CRA applies to products with digital elements, including machines and devices whose manufacturers do not think of themselves as software companies. The work is the product and the evidence behind it: security a customer can be shown, on a product that holds up in the field. - Scope determination - whether the product is in scope, and in which CRA class - answered free in the Discovery Calculator, not sold as an engagement - Gap assessment against the essential cybersecurity requirements - Technical file and documentation support - Vulnerability handling and coordinated disclosure process - Secure development and update obligations across the support period The scope and classification question is deliberately not chargeable. The **Discovery Calculator** answers it for free: whether the CRA applies, which role the company holds in law, which product class it lands in, and which required practices are missing. Paid work starts after that, at the Starter Assessment, and the CRA readiness work then runs inside the retainer. --- ### Senior Advisory Capabilities (beyond the SME retainer) URL: https://steadysec.eu/capabilities Four areas of senior work taken on outside the standard SME retainer, typically for larger or more mature security functions: - DevSecOps and secure software delivery pipeline security - Building a Cyber Threat Intelligence unit from scratch - Threat hunting programme design and execution - Incident response leadership --- ## Indicative Pricing Published figures from the website. All are starting points or ranges: the exact quote follows scoping, and scope, urgency, company size and travel change the final number. Currency is EUR, excluding VAT. **Retained Security Partner (monthly retainer)** - Advisory Line - €950 / month - Security Programme Core - €2,100 / month - Embedded Partner - from €5,800 / month A continuous retainer works out at roughly €11,400 per year at entry level, which is the figure the discovery calculator uses when comparing a retainer against one-off work. **Entry doors (every engagement starts at one of these)** - Starter Assessment - €1,900, fixed price, one-off, up to 2.5 person-days - Starter Month - €2,900, fixed price, one-off, up to 4 person-days Both end with a roadmap and a recommended retainer tier, and €700 or €1,000 is credited against the retainer if a 6+ month retainer is signed within 30 days. There is no path that skips this and no framework-specific package priced on its own. **Assessments and exercises** - Active Directory security assessment - from €1,900 (fixed scope) - Web / API penetration test - from €2,900, exact quote after scoping - AI application & agent penetration test - from €2,900, exact quote after scoping - Phishing simulation - from €900, exact quote after scoping - Tabletop exercise - from €2,500 per exercise, excluding travel - CRA scope and classification check - free, via the Discovery Calculator. CRA readiness has no separate price: it enters through the Starter Assessment or Starter Month and then runs inside the retainer. ISO 27001, NIS2, CIS Controls, trainings, human risk management and the senior advisory track are priced by scope rather than from a published starting figure. --- ## Areas of Expertise ### Frameworks & Standards - ISO/IEC 27001:2022 - NIS2 Directive (EU) - Cyber Resilience Act (CRA) - EU AI Act - GDPR - CIS Controls v8 - NIST CSF 2.0 - OWASP (Web Top 10, API Top 10, AI Testing Guide) - MITRE ATT&CK ### Technical Domains - Zero Trust Architecture - Security Operations (SOC, SIEM, EDR) - Threat Intelligence (GCTI certified) - Penetration Testing (web, network, API, AI) - DevSecOps and secure SDLC - Cloud Security (Azure, AWS) - Identity and Access Management - Incident Response and Digital Forensics - Hybrid Threat analysis ### Regulatory & Policy - EU AI Act risk classification and compliance - NIS2 scope assessment and essential entity obligations - GDPR data protection impact assessments - Cyber Resilience Act product compliance --- ## Blog Posts All posts at https://steadysec.eu/blog. Listed newest first. Author: Petr Pospíšil. **Your First Security Hire Should Not Be Full-Time** (2026-08-14) - https://steadysec.eu/blog/full-time-security-hire-vs-retainer Small companies handling sensitive data need real security. A full-time senior hire is usually the wrong first move, and here is why. Tags: Fractional CISO, Security Retainer, SME Security, Security Strategy, Hiring **You Spent on Security. Did It Work? Metrics Every SME Should Track** (2026-07-07) - https://steadysec.eu/blog/did-your-security-spending-work-sme-metrics Most SMEs buy security without knowing whether it worked. A small, decision-focused set of metrics that shows if you are harder to attack. Tags: Security Metrics, SME Security, Risk Management, CIS Controls, Security Strategy **The EU AI Act for Small Companies: What You Actually Have to Do** (2026-06-26) - https://steadysec.eu/blog/eu-ai-act-explained A plain-English starter on the EU AI Act for SMEs. If your company uses AI tools rather than builds them, here is what actually applies. Tags: EU AI Act, Compliance, SME Security, AI Regulation, AI Security **How to Scope a REST API Penetration Test (and Pay Less for a Better One)** (2026-06-25) - https://steadysec.eu/blog/how-to-scope-api-penetration-test What your API pentest actually needs from you. Bring two documents and the test gets cheaper, faster and more useful. Skip them and you pay for guesswork. Tags: Penetration Testing, API Security, OWASP API Top 10, Scoping, SME Security **What Security Actually Is: A Guide for People Who Never Wanted to Learn It (Part 1)** (2026-06-12) - https://steadysec.eu/blog/what-security-actually-is-part-1 Information security, cyber security, the CIA triad and CIS Controls, explained for business owners with no IT background. Tags: Security Basics, SME Security, CIS Controls, Security Strategy **Your Enterprise Customer Will Not Wait Until Your Security Is Ready** (2026-05-12) - https://steadysec.eu/blog/enterprise-customer-security-retainer Enterprise customers ask small vendors for security evidence long before there is a security team. How a retained advisor closes that gap. Tags: SME Security, Supply Chain Security, Security Retainer, ISO 27001, CIS Controls **Insider Risk for SMEs: You Don't Have to Be Hacked to Lose Data** (2026-05-12) - https://steadysec.eu/blog/insider-risk-smes-access-controls Staff, contractors, suppliers and leavers can expose company data by mistake or misuse. How SMEs cut insider risk with better access controls. Tags: Insider Risk, SME Security, ISMS, Access Control **Leaving Microsoft 365 for Proton: A Practical Sovereign Stack Test** (2026-02-04) - https://steadysec.eu/blog/leaving-microsoft-for-proton-sovereign-stack Why I am testing Proton as a more sovereign European workspace: what improves, what may hurt, and how SMEs should approach migrations. Tags: Digital Sovereignty, Proton, Microsoft 365, Privacy, Tech Migration **Shadow AI: Secrecy Is the Real Risk** (2026-01-27) - https://steadysec.eu/blog/shadow-ai-ethics-security Employees use AI because it helps them work faster. The security risk starts when policies are unclear and usage goes underground. Tags: AI Ethics, Shadow AI, OWASP LLM, Security Policy, Corporate Governance --- ## Geographic Focus - **Primary market:** European Union (SMEs and scale-ups) - **Remote delivery:** All of Europe - **On-site:** Czech Republic, Slovakia, Central and Eastern Europe (case-by-case basis) - **Delivery languages:** English, Czech (trainings and workshops are delivered in either) - **Website language:** English only - there is no Czech-language version of the site --- ## Positioning SteadySec is positioned as a boutique senior security partner: senior-only delivery at SME-compatible engagement terms. The value proposition is CISO-level thinking, sized for a company that cannot employ a CISO. Key differentiators: - Single point of contact and ownership (one named expert throughout the engagement) - International experience (OSCE, UNDP) applied to commercial clients - Practical, no-overselling approach - recommendations based on actual risk, not upsell targets - Specialisation in EU regulatory landscape (NIS2, GDPR, AI Act, CRA) - Strong offensive and defensive capability - rare combination at individual consultant level --- ## Site Structure | URL | Content | |-----|---------| | https://steadysec.eu/ | Homepage, overview of services and credentials | | https://steadysec.eu/retained-security-partner | Retained security partner service | | https://steadysec.eu/iso-27001 | ISO 27001 readiness and ISMS implementation | | https://steadysec.eu/nis2-compliance | NIS2 scope and cybersecurity readiness | | https://steadysec.eu/cis-controls | CIS Controls security baseline | | https://steadysec.eu/ai-pentest | AI/LLM security testing | | https://steadysec.eu/api-pentest | Web and API security testing | | https://steadysec.eu/active-directory-assessment | Active Directory and infrastructure assessment | | https://steadysec.eu/phishing-simulation | Phishing simulations | | https://steadysec.eu/tabletop-exercises | Incident-response tabletop exercises | | https://steadysec.eu/human-risk-management | Human risk management programme | | https://steadysec.eu/trainings | Security training and workshops | | https://steadysec.eu/cra | Cyber Resilience Act readiness (scope and class answered free in the Discovery Calculator) | | https://steadysec.eu/capabilities | Senior advisory capabilities beyond the SME retainer | | https://steadysec.eu/discovery-calculator | Interactive discovery questionnaire returning a recommended security direction, plus a free CRA scope, role and product-class verdict (about 4 minutes, no sign-up) | | https://steadysec.eu/about | About SteadySec: how the firm works and what good security looks like | | https://steadysec.eu/about/petr-pospisil | Founder profile, credentials, and international mission experience | | https://steadysec.eu/about/grc-consultant | Independent senior GRC practitioner (freelance collaboration) | | https://steadysec.eu/about/offensive-security | Independent senior offensive security practitioner (freelance collaboration) | | https://steadysec.eu/faq | Frequently asked questions | | https://steadysec.eu/blog | Security analysis and practical guidance | | https://steadysec.eu/security | Security and vulnerability disclosure policy | | https://steadysec.eu/privacy | Privacy notice (GDPR Article 13 disclosures) | | https://steadysec.eu/legal-notice | Legal notice and operator details | | https://steadysec.eu/llms.txt | Short LLM context file | | https://steadysec.eu/llms-full.txt | This file | | https://steadysec.eu/sitemap-index.xml | XML sitemap | | https://steadysec.eu/robots.txt | Crawler directives |