# SteadySec - Your retained security partner > Boutique cybersecurity firm for European SMEs. One retained partner for NIS2 readiness, customer trust, assessments, architecture, and practical implementation support. ## Who We Are SteadySec today is one person: Petr Pospíšil, a vCISO (fractional CISO) and security architect, who scopes, leads and delivers every engagement personally. Where an engagement needs deeper offensive or governance capacity, independent senior practitioners join for that scope. Based in Prague, Czech Republic (EU). Remote-first across Europe, on-site when the work demands it. Scope of the founder's work: advisory and security ownership, security architecture, and hands-on implementation - tool deployment and analysis included, rather than a roadmap handed to a third party. Founder certifications: ISC2 CISSP, CompTIA SecurityX, GIAC GCTI (Threat Intelligence), GIAC GCDA (Detection Analyst), ISO/IEC 27001:2022 Lead Auditor (IRCA certified course), CRTP. International experience: OSCE capacity-building missions, UNDP security advisory (expert roster), EU CyberNet roster of EU experts, and a current EEAS CSDP mission as contracted cybersecurity expert. Contact: hello@steadysec.eu Business registration: IČO 10695451 Address: Jaurisova 515/4, Praha 4 - Michle, 140 00, CZ ## Services - **Retained Security Partner** - Monthly advisory retainer covering security programme leadership, architecture review, and hands-on implementation support. ISO 27001, NIS2, CIS Controls. /retained-security-partner - **ISO 27001 Readiness** - ISMS implementation and certification readiness for medium companies. /iso-27001 - **NIS2 Supplier Readiness** - Scope clarification and cybersecurity readiness where the regulation applies. /nis2-compliance - **Practical Security Baseline** - Practical technical hardening and measurable safeguards without full certification. /cis-controls - **AI Application & Agent Pentesting** - AI Application Security to the OWASP AI Testing Guide (AITG-APP). What an attacker can make your AI do: cross-customer data exposure, privilege escalation, tool and transaction abuse, knowledge-base poisoning, agent-to-agent escalation. AITG-INF / DAT / MOD are out of scope. /ai-pentest - **Web & API Pentesting** - Manual web application and REST/GraphQL API security testing. /api-pentest - **Active Directory Assessment** - Active Directory and identity security assessment. /active-directory-assessment - **Training & Workshops** - Workshops for technical teams and executives. Hands-on labs, CTF challenges. Backed by OSCE and UNDP training experience. /trainings - **Tabletop Exercises** - Incident-response readiness exercises for leadership and technical teams. /tabletop-exercises - **Phishing Simulation** - Realistic phishing campaigns and human risk assessment. /phishing-simulation - **Human Risk Programme** - Long-term awareness and human-risk programme. /human-risk-management - **Cyber Resilience Act (CRA) Readiness** - Product security for hardware and software placed on the EU market: secure design, vulnerability handling, security testing, and the technical file that evidences them. Scope, legal role, and product class are answered free by the Discovery Calculator. /cra - **Senior Capabilities (beyond the SME retainer)** - DevSecOps pipeline security, building a Cyber Threat Intelligence unit, threat hunting, and incident response leadership. /capabilities ## How Engagements Start There is one commercial path, and every paid engagement follows it. 1. **Free** - the Discovery Calculator at /discovery-calculator answers direction and applicability questions: which framework fits, and whether the Cyber Resilience Act reaches you, in which role, and in which product class. Scope, applicability and classification are never charged for. 2. **One fixed-price entry door** - Starter Assessment (€1,900, up to 2.5 person-days) or Starter Month (€2,900, up to 4 person-days). Both are one-off and both end with a high-level roadmap and a recommended retainer tier. €700 or €1,000 is credited against the retainer if a 6+ month retainer is signed within 30 days. 3. **The retainer** - where the programme actually runs. Tiers on /retained-security-partner: Advisory Line €950/month, Security Programme Core €2,100/month, Embedded Partner from €5,800/month. Fixed-scope technical work is quoted per scope and does not replace that path: Active Directory assessment from €1,900, web/API penetration test from €2,900, AI/LLM penetration test from €2,900, phishing simulation from €900, tabletop exercise from €2,500. All figures are indicative before scoping. ## Expertise NIS2 Compliance, ISO 27001, Cyber Resilience Act (CRA), EU AI Act, GDPR, Zero Trust Architecture, DevSecOps, Threat Intelligence, Hybrid Threats, Incident Response, Offensive Security, Blue Team Operations. ## Blog SME Field Notes: security analysis and practical guidance at /blog, written by Petr Pospíšil. Recurring subjects: how SMEs should structure a first security investment, fractional vs full-time security hiring, EU regulation (AI Act, NIS2, CRA), penetration test scoping, insider risk, and digital sovereignty. - Your First Security Hire Should Not Be Full-Time - /blog/full-time-security-hire-vs-retainer - You Spent on Security. Did It Work? Metrics Every SME Should Track - /blog/did-your-security-spending-work-sme-metrics - The EU AI Act for Small Companies: What You Actually Have to Do - /blog/eu-ai-act-explained - How to Scope a REST API Penetration Test (and Pay Less for a Better One) - /blog/how-to-scope-api-penetration-test - What Security Actually Is: A Guide for People Who Never Wanted to Learn It (Part 1) - /blog/what-security-actually-is-part-1 - Your Enterprise Customer Will Not Wait Until Your Security Is Ready - /blog/enterprise-customer-security-retainer - Insider Risk for SMEs: You Don't Have to Be Hacked to Lose Data - /blog/insider-risk-smes-access-controls - Leaving Microsoft 365 for Proton: A Practical Sovereign Stack Test - /blog/leaving-microsoft-for-proton-sovereign-stack - Shadow AI: Secrecy Is the Real Risk - /blog/shadow-ai-ethics-security ## Security Coordinated vulnerability disclosure policy at /security: reporting contact, scope, rules of engagement, safe harbour, and response commitments (acknowledgement within 3 working days, triage within 10). Machine-readable contact at /.well-known/security.txt. No bug bounty; credit is offered instead. ## Sitemap Services - /retained-security-partner - Monthly retained security partner engagement (core offer) - /iso-27001 - ISO 27001 readiness and ISMS implementation - /nis2-compliance - NIS2 scope clarification and supplier readiness - /cis-controls - CIS Critical Security Controls baseline - /cra - Cyber Resilience Act readiness (scope and class answered free in the Discovery Calculator) - /ai-pentest - AI and LLM penetration testing - /api-pentest - Web application and API penetration testing - /active-directory-assessment - Active Directory and identity security assessment - /phishing-simulation - Phishing simulation campaigns - /tabletop-exercises - Incident-response tabletop exercises - /human-risk-management - Long-term human risk programme - /trainings - Technical trainings and workshops - /capabilities - Senior advisory capabilities beyond the SME retainer Tools and enquiry - /discovery-calculator - Interactive discovery questionnaire that returns a recommended security direction (CIS Controls, NIS2 readiness, or ISO 27001). About 4 minutes, no sign-up. - /get-a-quote - Short forms that collect what a quote depends on, so the first call carries a price. /get-a-quote/ai-pentest is 10 questions about an AI application. Runs in the browser; nothing is transmitted until you send it. About - /about - About SteadySec: how the firm works and what it believes good security looks like - /about/petr-pospisil - Founder profile, credentials, and international mission experience - /about/grc-consultant - Independent senior GRC practitioner (freelance collaboration) - /about/offensive-security - Independent senior offensive security practitioner (freelance collaboration) - /faq - Frequently asked questions Policy and reference - /security - Security and vulnerability disclosure policy - /privacy - Privacy notice (GDPR Article 13 disclosures) - /legal-notice - Legal notice and operator details - /blog - Security analysis and practical guidance - /llms-full.txt - Full context version of this file - /sitemap-index.xml - XML sitemap