Completed Projects by Area

A company operating in the field of fire protection component manufacturing

Cybersecurity

For a manufacturing company operating in the field of fire protection components, we carried out a project to implement process measures in accordance with the NIS2 Directive and Act No. 69/2018 Coll. on Cybersecurity. Initially, we assessed the scope of this legislation as it applies to the company as a manufacturing enterprise, defined its essential service and related infrastructure, and identified the assets requiring protection. Through a gap analysis, we determined the company’s current level of compliance with the legislative requirements and prepared a proposal for the necessary measures.
We then categorized the company’s networks and IT systems and classified information in accordance with the Cybersecurity Act, based on which we determined the minimum level of necessary security measures. The project also included a risk analysis with the development of a risk catalog and countermeasures, as well as the preparation of security documentation—the Security Policy, Security Strategy, and related implementation documentation necessary for the practical execution of cybersecurity processes.
We supplemented the project with phishing tests for employees and vulnerability testing of the company’s IT infrastructure and applications.

For a manufacturing company operating in the field of fire protection components, we carried out a project to implement process measures in accordance with the NIS2 Directive and Act No. 69/2018 Coll. on Cybersecurity. Initially, we assessed the scope of this legislation as it applies to the company as a manufacturing enterprise, defined its essential service and related infrastructure, and identified the assets requiring protection. Through a gap analysis, we determined the company’s current level of compliance with the legislative requirements and prepared a proposal for the necessary measures.
We then categorized the company’s networks and IT systems and classified information in accordance with the Cybersecurity Act, based on which we determined the minimum level of necessary security measures. The project also included a risk analysis with the development of a risk catalog and countermeasures, as well as the preparation of security documentation—the Security Policy, Security Strategy, and related implementation documentation necessary for the practical execution of cybersecurity processes.
We supplemented the project with phishing tests for employees and vulnerability testing of the company’s IT infrastructure and applications.

For a manufacturing company operating in the field of fire protection components, we carried out a project to implement process measures in accordance with the NIS2 Directive and Act No. 69/2018 Coll. on Cybersecurity. Initially, we assessed the scope of this legislation as it applies to the company as a manufacturing enterprise, defined its essential service and related infrastructure, and identified the assets requiring protection. Through a gap analysis, we determined the company’s current level of compliance with the legislative requirements and prepared a proposal for the necessary measures.
We then categorized the company’s networks and IT systems and classified information in accordance with the Cybersecurity Act, based on which we determined the minimum level of necessary security measures. The project also included a risk analysis with the development of a risk catalog and countermeasures, as well as the preparation of security documentation—the Security Policy, Security Strategy, and related implementation documentation necessary for the practical execution of cybersecurity processes.
We supplemented the project with phishing tests for employees and vulnerability testing of the company’s IT infrastructure and applications.

A company operating in the automotive industry

Cybersecurity

For a manufacturing company operating in the automotive industry, we provided cybersecurity services in accordance with Act No. 69/2018 Coll. on Cybersecurity and the NIS2 Directive. Based on a price quote, we developed and implemented security documentation and processes for the client covering the following areas:
We established a cybersecurity strategy and policies, including the organizational structure, responsibilities, and the role of the cybersecurity manager. In the area of personnel security, we adjusted access rights, the onboarding and offboarding processes, employee training, and identity management. We implemented security and compliance management through control mechanisms, an audit plan, and cybersecurity measures, as well as third-party management, including their identification and the establishment of requirements in contractual relationships.
Furthermore, we ensured asset management with asset and information classification, IT and operations management focused on network and communications security and operational measures, as well as a cyber incident response process, including a response plan, escalation, reporting, and incident logging. The implementation also included physical security of the environment and end devices, risk management focused on threat identification, impact analysis, and risk assessment, as well as the area of Business Continuity (BCP and DRP) with backup methodologies and testing of recovery plans.
We also implemented cryptographic measures in the form of encryption, vulnerability management to protect against malicious code, vulnerabilities, and cyber threats, and, finally, monitoring and logging to record and evaluate events.

For a manufacturing company operating in the automotive industry, we provided cybersecurity services in accordance with Act No. 69/2018 Coll. on Cybersecurity and the NIS2 Directive. Based on a price quote, we developed and implemented security documentation and processes for the client covering the following areas:
We established a cybersecurity strategy and policies, including the organizational structure, responsibilities, and the role of the cybersecurity manager. In the area of personnel security, we adjusted access rights, the onboarding and offboarding processes, employee training, and identity management. We implemented security and compliance management through control mechanisms, an audit plan, and cybersecurity measures, as well as third-party management, including their identification and the establishment of requirements in contractual relationships.
Furthermore, we ensured asset management with asset and information classification, IT and operations management focused on network and communications security and operational measures, as well as a cyber incident response process, including a response plan, escalation, reporting, and incident logging. The implementation also included physical security of the environment and end devices, risk management focused on threat identification, impact analysis, and risk assessment, as well as the area of Business Continuity (BCP and DRP) with backup methodologies and testing of recovery plans.
We also implemented cryptographic measures in the form of encryption, vulnerability management to protect against malicious code, vulnerabilities, and cyber threats, and, finally, monitoring and logging to record and evaluate events.

For a manufacturing company operating in the automotive industry, we provided cybersecurity services in accordance with Act No. 69/2018 Coll. on Cybersecurity and the NIS2 Directive. Based on a price quote, we developed and implemented security documentation and processes for the client covering the following areas:
We established a cybersecurity strategy and policies, including the organizational structure, responsibilities, and the role of the cybersecurity manager. In the area of personnel security, we adjusted access rights, the onboarding and offboarding processes, employee training, and identity management. We implemented security and compliance management through control mechanisms, an audit plan, and cybersecurity measures, as well as third-party management, including their identification and the establishment of requirements in contractual relationships.
Furthermore, we ensured asset management with asset and information classification, IT and operations management focused on network and communications security and operational measures, as well as a cyber incident response process, including a response plan, escalation, reporting, and incident logging. The implementation also included physical security of the environment and end devices, risk management focused on threat identification, impact analysis, and risk assessment, as well as the area of Business Continuity (BCP and DRP) with backup methodologies and testing of recovery plans.
We also implemented cryptographic measures in the form of encryption, vulnerability management to protect against malicious code, vulnerabilities, and cyber threats, and, finally, monitoring and logging to record and evaluate events.

A company engaged in manufacturing and sales in the field of printing and paper/gift products

Cybersecurity

For a manufacturing company operating in the field of printing and paper products, we provided comprehensive preparation of security documentation in accordance with the requirements for cybersecurity and information security under the NIS2 Directive and National Security Authority Decree No. 365/2018.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, ICT technology management and operations, compliance management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

For a manufacturing company operating in the field of printing and paper products, we provided comprehensive preparation of security documentation in accordance with the requirements for cybersecurity and information security under the NIS2 Directive and National Security Authority Decree No. 365/2018.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, ICT technology management and operations, compliance management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

For a manufacturing company operating in the field of printing and paper products, we provided comprehensive preparation of security documentation in accordance with the requirements for cybersecurity and information security under the NIS2 Directive and National Security Authority Decree No. 365/2018.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, ICT technology management and operations, compliance management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

A company engaged in the manufacture of components for agricultural and forestry machinery

Cybersecurity

For a manufacturing company that produces components used in agricultural and forestry machinery (SK NACE 28300 – Manufacture of agricultural and forestry machinery), we have prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The purpose of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for registration in the register of operators of essential services under the Cyber Security Act—and thus whether it will become a regulated entity—and to identify any potential impacts of the regulation on the company should the Act apply to it.
As part of the analysis, we assessed the company’s business activities, its classification under SK NACE, and other relevant criteria set forth in the legislation (particularly the size of the entity and the sector in which it operates). We prepared this assessment based on an individual review of the company, drawing on publicly available sources—primarily the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, the Register of Legal Entities, and the company’s website—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a manufacturing company that produces components used in agricultural and forestry machinery (SK NACE 28300 – Manufacture of agricultural and forestry machinery), we have prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The purpose of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for registration in the register of operators of essential services under the Cyber Security Act—and thus whether it will become a regulated entity—and to identify any potential impacts of the regulation on the company should the Act apply to it.
As part of the analysis, we assessed the company’s business activities, its classification under SK NACE, and other relevant criteria set forth in the legislation (particularly the size of the entity and the sector in which it operates). We prepared this assessment based on an individual review of the company, drawing on publicly available sources—primarily the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, the Register of Legal Entities, and the company’s website—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a manufacturing company that produces components used in agricultural and forestry machinery (SK NACE 28300 – Manufacture of agricultural and forestry machinery), we have prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The purpose of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for registration in the register of operators of essential services under the Cyber Security Act—and thus whether it will become a regulated entity—and to identify any potential impacts of the regulation on the company should the Act apply to it.
As part of the analysis, we assessed the company’s business activities, its classification under SK NACE, and other relevant criteria set forth in the legislation (particularly the size of the entity and the sector in which it operates). We prepared this assessment based on an individual review of the company, drawing on publicly available sources—primarily the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, the Register of Legal Entities, and the company’s website—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

A company operating in the chemical manufacturing sector

Cybersecurity

For a manufacturing company operating in the coatings industry, we developed a customized cybersecurity solution that included conducting a GAP analysis and a feasibility study of security configurations.
As part of the GAP analysis, in accordance with the requirements of the ISO 27001:2023 standard and the Cybersecurity Act, we identified gaps between the company’s current cybersecurity status and the required status, and documented the identified deficiencies and vulnerabilities in security configurations and procedures. Based on the results of the GAP analysis, we subsequently prepared a feasibility study in which we evaluated the costs, benefits, and risks of implementing the proposed security measures necessary to address the identified deficiencies.
The project’s output was a proposal for a security solution tailored to the company’s individual needs, along with a proposed implementation plan, which served as the basis for further steps to enhance cybersecurity and ensure compliance with applicable legislation.

For a manufacturing company operating in the coatings industry, we developed a customized cybersecurity solution that included conducting a GAP analysis and a feasibility study of security configurations.
As part of the GAP analysis, in accordance with the requirements of the ISO 27001:2023 standard and the Cybersecurity Act, we identified gaps between the company’s current cybersecurity status and the required status, and documented the identified deficiencies and vulnerabilities in security configurations and procedures. Based on the results of the GAP analysis, we subsequently prepared a feasibility study in which we evaluated the costs, benefits, and risks of implementing the proposed security measures necessary to address the identified deficiencies.
The project’s output was a proposal for a security solution tailored to the company’s individual needs, along with a proposed implementation plan, which served as the basis for further steps to enhance cybersecurity and ensure compliance with applicable legislation.

For a manufacturing company operating in the coatings industry, we developed a customized cybersecurity solution that included conducting a GAP analysis and a feasibility study of security configurations.
As part of the GAP analysis, in accordance with the requirements of the ISO 27001:2023 standard and the Cybersecurity Act, we identified gaps between the company’s current cybersecurity status and the required status, and documented the identified deficiencies and vulnerabilities in security configurations and procedures. Based on the results of the GAP analysis, we subsequently prepared a feasibility study in which we evaluated the costs, benefits, and risks of implementing the proposed security measures necessary to address the identified deficiencies.
The project’s output was a proposal for a security solution tailored to the company’s individual needs, along with a proposed implementation plan, which served as the basis for further steps to enhance cybersecurity and ensure compliance with applicable legislation.

A company operating in the transportation and logistics sector

Cybersecurity

For a company operating in the transportation and logistics sector, we provided comprehensive preparation of security documentation in accordance with cybersecurity and information security requirements under the NIS2 Directive and National Security Authority Decree No. 362/2018. This work was part of a project funded by a grant to support the improvement of cybersecurity.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, information and communication technology management and operations, compliance management, business continuity management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

For a company operating in the transportation and logistics sector, we provided comprehensive preparation of security documentation in accordance with cybersecurity and information security requirements under the NIS2 Directive and National Security Authority Decree No. 362/2018. This work was part of a project funded by a grant to support the improvement of cybersecurity.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, information and communication technology management and operations, compliance management, business continuity management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

For a company operating in the transportation and logistics sector, we provided comprehensive preparation of security documentation in accordance with cybersecurity and information security requirements under the NIS2 Directive and National Security Authority Decree No. 362/2018. This work was part of a project funded by a grant to support the improvement of cybersecurity.
As part of the project, we developed a cybersecurity strategy and policies covering areas such as security risk management, information asset management, supplier relationship management, information and communication technology management and operations, compliance management, business continuity management, and security organization. We developed a methodology and classification scheme for classifying information and categorizing networks and information systems.
In the area of organizational and personnel security, we have established the relevant processes and prepared a plan for developing security awareness and training for employees and suppliers. We also developed a risk analysis methodology, an asset inventory, a catalog of threats and vulnerabilities, the cybersecurity risk analysis itself, and a high-level design proposal for the security architecture.
The scope of delivery also included guidelines for vulnerability management, the security of information systems and network operations, access management, change and capacity management, backup and recovery, cryptographic protection of information, cyber incident response, including reporting to the JISKB, event monitoring, and physical security.
In the area of business continuity, we developed a Business Impact Analysis (BIA), a Business Continuity Management (BCM) methodology, and sample Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) templates, including testing procedures for these plans.

A company operating in the telecommunications and network infrastructure sector

Cybersecurity

For a company operating in the field of telecommunications and network infrastructure, we carried out a project aimed at improving cybersecurity, funded through the Recovery and Resilience Facility. The goal of the project was to identify and assess security risks, vulnerabilities, and potential threats within the company’s information systems and environment, followed by a proposal to implement security measures into its processes with an emphasis on protecting sensitive and critical information assets.
As part of the asset analysis, we developed an asset management document defining procedures for asset management, classification, and media handling in accordance with the requirements of the ISO/IEC 27001 standard. We developed a methodology for classifying information and categorizing networks and information systems in accordance with National Security Authority Decree No. 362/2018 Coll., under which we classified the company’s individual groups of information assets (information intended for public disclosure, assets of routine and confidential administrative processes, assets of routine and confidential operational processes, classified information, as well as archives and backups) were classified according to their level of confidentiality, integrity, and availability, and assigned them the appropriate security category. The deliverable also included an inventory list of assets.
As part of the risk analysis, we developed a methodology for information security risk analysis based on the ISO/IEC 27005 and NIST 800-30 standards, based on which we identified relevant threats and vulnerabilities affecting individual groups of information assets, assessed the likelihood and impact of individual risks, and compiled a comprehensive list of the company’s risks.
Based on the results of the asset and risk analysis, we proposed a set of security measures covering the areas of information security organization, personnel security, risk management, access control, cryptography, information system operational security management, communications security, system acquisition and maintenance, supplier relationship management, information security incident management, business continuity management, information handling, remote work, and compliance management. The project resulted in the definition of the company’s strategic security objectives in the organizational, personnel, and technical areas, which formed the basis for the systematic implementation of cybersecurity into the company’s IT environment.

For a company operating in the field of telecommunications and network infrastructure, we carried out a project aimed at improving cybersecurity, funded through the Recovery and Resilience Facility. The goal of the project was to identify and assess security risks, vulnerabilities, and potential threats within the company’s information systems and environment, followed by a proposal to implement security measures into its processes with an emphasis on protecting sensitive and critical information assets.
As part of the asset analysis, we developed an asset management document defining procedures for asset management, classification, and media handling in accordance with the requirements of the ISO/IEC 27001 standard. We developed a methodology for classifying information and categorizing networks and information systems in accordance with National Security Authority Decree No. 362/2018 Coll., under which we classified the company’s individual groups of information assets (information intended for public disclosure, assets of routine and confidential administrative processes, assets of routine and confidential operational processes, classified information, as well as archives and backups) were classified according to their level of confidentiality, integrity, and availability, and assigned them the appropriate security category. The deliverable also included an inventory list of assets.
As part of the risk analysis, we developed a methodology for information security risk analysis based on the ISO/IEC 27005 and NIST 800-30 standards, based on which we identified relevant threats and vulnerabilities affecting individual groups of information assets, assessed the likelihood and impact of individual risks, and compiled a comprehensive list of the company’s risks.
Based on the results of the asset and risk analysis, we proposed a set of security measures covering the areas of information security organization, personnel security, risk management, access control, cryptography, information system operational security management, communications security, system acquisition and maintenance, supplier relationship management, information security incident management, business continuity management, information handling, remote work, and compliance management. The project resulted in the definition of the company’s strategic security objectives in the organizational, personnel, and technical areas, which formed the basis for the systematic implementation of cybersecurity into the company’s IT environment.

For a company operating in the field of telecommunications and network infrastructure, we carried out a project aimed at improving cybersecurity, funded through the Recovery and Resilience Facility. The goal of the project was to identify and assess security risks, vulnerabilities, and potential threats within the company’s information systems and environment, followed by a proposal to implement security measures into its processes with an emphasis on protecting sensitive and critical information assets.
As part of the asset analysis, we developed an asset management document defining procedures for asset management, classification, and media handling in accordance with the requirements of the ISO/IEC 27001 standard. We developed a methodology for classifying information and categorizing networks and information systems in accordance with National Security Authority Decree No. 362/2018 Coll., under which we classified the company’s individual groups of information assets (information intended for public disclosure, assets of routine and confidential administrative processes, assets of routine and confidential operational processes, classified information, as well as archives and backups) were classified according to their level of confidentiality, integrity, and availability, and assigned them the appropriate security category. The deliverable also included an inventory list of assets.
As part of the risk analysis, we developed a methodology for information security risk analysis based on the ISO/IEC 27005 and NIST 800-30 standards, based on which we identified relevant threats and vulnerabilities affecting individual groups of information assets, assessed the likelihood and impact of individual risks, and compiled a comprehensive list of the company’s risks.
Based on the results of the asset and risk analysis, we proposed a set of security measures covering the areas of information security organization, personnel security, risk management, access control, cryptography, information system operational security management, communications security, system acquisition and maintenance, supplier relationship management, information security incident management, business continuity management, information handling, remote work, and compliance management. The project resulted in the definition of the company’s strategic security objectives in the organizational, personnel, and technical areas, which formed the basis for the systematic implementation of cybersecurity into the company’s IT environment.

A company operating as a manufacturing enterprise in the automotive industry

Cybersecurity

For a manufacturing company operating in the automotive industry that specializes in surface finishing and painting of parts supplied to leading automakers, we conducted an organizational assessment to determine whether the company is a subject entity within the meaning of Directive (EU) (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The objective of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for entry into the register of operators of essential services, and thus whether it will become a regulated entity, while also identifying any potential impacts of the regulation on the company.
As part of the analysis, we assessed the company’s scope of business, its classification under the SK NACE system, and other relevant criteria set forth in the legislation (particularly the entity’s size and sector of operation). We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Commercial Register of the Slovak Republic, the Trade Register of the Slovak Republic, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a manufacturing company operating in the automotive industry that specializes in surface finishing and painting of parts supplied to leading automakers, we conducted an organizational assessment to determine whether the company is a subject entity within the meaning of Directive (EU) (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The objective of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for entry into the register of operators of essential services, and thus whether it will become a regulated entity, while also identifying any potential impacts of the regulation on the company.
As part of the analysis, we assessed the company’s scope of business, its classification under the SK NACE system, and other relevant criteria set forth in the legislation (particularly the entity’s size and sector of operation). We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Commercial Register of the Slovak Republic, the Trade Register of the Slovak Republic, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a manufacturing company operating in the automotive industry that specializes in surface finishing and painting of parts supplied to leading automakers, we conducted an organizational assessment to determine whether the company is a subject entity within the meaning of Directive (EU) (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
The objective of the analysis was to assess the impact of the NIS2 Directive on the company in connection with its transposition into Slovak law, specifically to determine whether the company meets the criteria for entry into the register of operators of essential services, and thus whether it will become a regulated entity, while also identifying any potential impacts of the regulation on the company.
As part of the analysis, we assessed the company’s scope of business, its classification under the SK NACE system, and other relevant criteria set forth in the legislation (particularly the entity’s size and sector of operation). We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Commercial Register of the Slovak Republic, the Trade Register of the Slovak Republic, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

The company operates in the manufacturing sector

Cybersecurity

We conducted a GAP analysis of the state of cybersecurity and information security for a manufacturing company, which is a prospective candidate for registration in the registry of essential service operators pursuant to Act No. 69/2018 Coll. on Cybersecurity and National Security Authority Decree No. 227/2025 Coll. on Security Measures.
The objective of the analysis was to assess the compliance of the company’s existing processes and technical measures with the requirements of applicable legislation and to identify areas where security measures need to be implemented or formalized.
As part of the analysis, we examined all 17 areas of security measures pursuant to Section 20(2) of the Act—cybersecurity organization and management, vulnerability and threat management, asset management, incident management, business continuity and backup, security in system development and maintenance, cryptography, human resources, identity and access management, network and system security, monitoring, physical security, and the supply chain. We evaluated each measure according to its level of compliance (compliant / partially compliant / non-compliant / not applicable), supplemented by specific findings from the client’s environment.
The output was a structured GAP analysis providing an overview of the current status, a description of the identified deficiencies, and recommendations for implementing security documentation (strategy, policies, information classification, risk analysis) within 12 months of registration in the PZS registry, which served as the basis for the subsequent implementation phase.

We conducted a GAP analysis of the state of cybersecurity and information security for a manufacturing company, which is a prospective candidate for registration in the registry of essential service operators pursuant to Act No. 69/2018 Coll. on Cybersecurity and National Security Authority Decree No. 227/2025 Coll. on Security Measures.
The objective of the analysis was to assess the compliance of the company’s existing processes and technical measures with the requirements of applicable legislation and to identify areas where security measures need to be implemented or formalized.
As part of the analysis, we examined all 17 areas of security measures pursuant to Section 20(2) of the Act—cybersecurity organization and management, vulnerability and threat management, asset management, incident management, business continuity and backup, security in system development and maintenance, cryptography, human resources, identity and access management, network and system security, monitoring, physical security, and the supply chain. We evaluated each measure according to its level of compliance (compliant / partially compliant / non-compliant / not applicable), supplemented by specific findings from the client’s environment.
The output was a structured GAP analysis providing an overview of the current status, a description of the identified deficiencies, and recommendations for implementing security documentation (strategy, policies, information classification, risk analysis) within 12 months of registration in the PZS registry, which served as the basis for the subsequent implementation phase.

We conducted a GAP analysis of the state of cybersecurity and information security for a manufacturing company, which is a prospective candidate for registration in the registry of essential service operators pursuant to Act No. 69/2018 Coll. on Cybersecurity and National Security Authority Decree No. 227/2025 Coll. on Security Measures.
The objective of the analysis was to assess the compliance of the company’s existing processes and technical measures with the requirements of applicable legislation and to identify areas where security measures need to be implemented or formalized.
As part of the analysis, we examined all 17 areas of security measures pursuant to Section 20(2) of the Act—cybersecurity organization and management, vulnerability and threat management, asset management, incident management, business continuity and backup, security in system development and maintenance, cryptography, human resources, identity and access management, network and system security, monitoring, physical security, and the supply chain. We evaluated each measure according to its level of compliance (compliant / partially compliant / non-compliant / not applicable), supplemented by specific findings from the client’s environment.
The output was a structured GAP analysis providing an overview of the current status, a description of the identified deficiencies, and recommendations for implementing security documentation (strategy, policies, information classification, risk analysis) within 12 months of registration in the PZS registry, which served as the basis for the subsequent implementation phase.

A company operating in the construction sector

Cybersecurity

For a company operating in the construction sector that provides scaffolding rental and assembly services and recruits qualified construction personnel for projects in Slovakia and abroad, we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify assets, risks, vulnerabilities, and potential threats within its information systems and operational environment, including the processing of sensitive data on employees and subcontractors working on projects in various EU countries.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset management, access control, security of network and information system operations, protection against malicious code, data backup and recovery, human resources security, and management of relationships with third parties (subcontractors and foreign partner companies). We placed particular emphasis on the protection of employees’ personal and payroll data processed in connection with the administration of cross-border employee secondments.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a company operating in the construction sector that provides scaffolding rental and assembly services and recruits qualified construction personnel for projects in Slovakia and abroad, we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify assets, risks, vulnerabilities, and potential threats within its information systems and operational environment, including the processing of sensitive data on employees and subcontractors working on projects in various EU countries.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset management, access control, security of network and information system operations, protection against malicious code, data backup and recovery, human resources security, and management of relationships with third parties (subcontractors and foreign partner companies). We placed particular emphasis on the protection of employees’ personal and payroll data processed in connection with the administration of cross-border employee secondments.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a company operating in the construction sector that provides scaffolding rental and assembly services and recruits qualified construction personnel for projects in Slovakia and abroad, we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify assets, risks, vulnerabilities, and potential threats within its information systems and operational environment, including the processing of sensitive data on employees and subcontractors working on projects in various EU countries.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset management, access control, security of network and information system operations, protection against malicious code, data backup and recovery, human resources security, and management of relationships with third parties (subcontractors and foreign partner companies). We placed particular emphasis on the protection of employees’ personal and payroll data processed in connection with the administration of cross-border employee secondments.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

A company operating in the food manufacturing sector

Cybersecurity

For a manufacturing company operating in the brewing industry, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and operational environment, including systems controlling the production process (beer production and processing) and related administrative and business operations.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, business continuity, and human resources security. We paid particular attention to the interconnection of production (operational) technologies with the company’s standard IT infrastructure and the configuration of appropriate segmentation between them.
The output was a structured GAP analysis providing an overview of the current security status, the identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the brewing industry, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and operational environment, including systems controlling the production process (beer production and processing) and related administrative and business operations.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, business continuity, and human resources security. We paid particular attention to the interconnection of production (operational) technologies with the company’s standard IT infrastructure and the configuration of appropriate segmentation between them.
The output was a structured GAP analysis providing an overview of the current security status, the identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the brewing industry, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and operational environment, including systems controlling the production process (beer production and processing) and related administrative and business operations.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, business continuity, and human resources security. We paid particular attention to the interconnection of production (operational) technologies with the company’s standard IT infrastructure and the configuration of appropriate segmentation between them.
The output was a structured GAP analysis providing an overview of the current security status, the identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

A company operating in the field of industrial robotics and automation

Cybersecurity

For a manufacturing company operating in the field of industrial robotics and automation, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to assess the company’s information and cybersecurity status against the requirements of current legislation, with a focus on identifying and evaluating assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment—including systems related to the design, programming, and management of robotic and automated workstations implemented for clients in Slovakia and abroad.
As part of the GAP analysis, we identified discrepancies between the current state and legislative requirements across both organizational and technical areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development and maintenance of software products (including proprietary software for offline programming of welding and cutting processes), protection of intellectual property and know-how within clients’ project documentation, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting clients’ sensitive technical and project data, which the company handles when carrying out turnkey projects.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of industrial robotics and automation, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to assess the company’s information and cybersecurity status against the requirements of current legislation, with a focus on identifying and evaluating assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment—including systems related to the design, programming, and management of robotic and automated workstations implemented for clients in Slovakia and abroad.
As part of the GAP analysis, we identified discrepancies between the current state and legislative requirements across both organizational and technical areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development and maintenance of software products (including proprietary software for offline programming of welding and cutting processes), protection of intellectual property and know-how within clients’ project documentation, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting clients’ sensitive technical and project data, which the company handles when carrying out turnkey projects.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of industrial robotics and automation, we prepared an assessment of the current state of cybersecurity, along with a GAP analysis aimed at enhancing the security of its information systems.
The goal of the project was to assess the company’s information and cybersecurity status against the requirements of current legislation, with a focus on identifying and evaluating assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment—including systems related to the design, programming, and management of robotic and automated workstations implemented for clients in Slovakia and abroad.
As part of the GAP analysis, we identified discrepancies between the current state and legislative requirements across both organizational and technical areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development and maintenance of software products (including proprietary software for offline programming of welding and cutting processes), protection of intellectual property and know-how within clients’ project documentation, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting clients’ sensitive technical and project data, which the company handles when carrying out turnkey projects.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

A company operating in the construction sector

Cybersecurity

For a construction company specializing in turnkey projects, comprehensive construction work, installation work, and staffing for construction sites, which has been providing services in Slovakia and abroad (primarily in Germany) since 2013, we prepared an assessment of the current state of information and cybersecurity, along with a GAP analysis aimed at enhancing the security of the company’s information systems.
The goal of the project was to identify and evaluate information assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment. The GAP analysis was prepared in accordance with the requirements of the ISO 27001 standard in combination with the requirements of Act No. 69/2018 Coll. on Cybersecurity and the corresponding decree, in effect at the time the analysis was conducted. From the perspective of the Cyber Security Act,
the company is not listed in the register of essential service operators and does not fall under any of the categories of entities specified in the annexes to the Act; therefore, it does not have the status of an essential service operator. Nevertheless, the company was interested in voluntarily adapting to the increased requirements for information and cybersecurity, particularly given the cross-border nature of its activities and the processing of data on employees and personnel deployed to international projects.
As part of the analysis, we evaluated the organizational and technical aspects of security measures in accordance with ISO 27001 and the Cyber Security Act (ZoKB)—information security management, asset management, risk management, access control, security in the operation of information systems, protection of employee and subcontractor data, data backup and recovery, as well as security in the cross-border provision of construction and personnel services.
The outcome was a proposal for security measures and recommendations for integrating security elements into the company’s processes, with an emphasis on protecting sensitive and critical information assets, which served as the basis for the company’s next steps toward voluntarily improving cybersecurity.

For a construction company specializing in turnkey projects, comprehensive construction work, installation work, and staffing for construction sites, which has been providing services in Slovakia and abroad (primarily in Germany) since 2013, we prepared an assessment of the current state of information and cybersecurity, along with a GAP analysis aimed at enhancing the security of the company’s information systems.
The goal of the project was to identify and evaluate information assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment. The GAP analysis was prepared in accordance with the requirements of the ISO 27001 standard in combination with the requirements of Act No. 69/2018 Coll. on Cybersecurity and the corresponding decree, in effect at the time the analysis was conducted. From the perspective of the Cyber Security Act,
the company is not listed in the register of essential service operators and does not fall under any of the categories of entities specified in the annexes to the Act; therefore, it does not have the status of an essential service operator. Nevertheless, the company was interested in voluntarily adapting to the increased requirements for information and cybersecurity, particularly given the cross-border nature of its activities and the processing of data on employees and personnel deployed to international projects.
As part of the analysis, we evaluated the organizational and technical aspects of security measures in accordance with ISO 27001 and the Cyber Security Act (ZoKB)—information security management, asset management, risk management, access control, security in the operation of information systems, protection of employee and subcontractor data, data backup and recovery, as well as security in the cross-border provision of construction and personnel services.
The outcome was a proposal for security measures and recommendations for integrating security elements into the company’s processes, with an emphasis on protecting sensitive and critical information assets, which served as the basis for the company’s next steps toward voluntarily improving cybersecurity.

For a construction company specializing in turnkey projects, comprehensive construction work, installation work, and staffing for construction sites, which has been providing services in Slovakia and abroad (primarily in Germany) since 2013, we prepared an assessment of the current state of information and cybersecurity, along with a GAP analysis aimed at enhancing the security of the company’s information systems.
The goal of the project was to identify and evaluate information assets, security risks, vulnerabilities, and potential threats within the company’s information systems and environment. The GAP analysis was prepared in accordance with the requirements of the ISO 27001 standard in combination with the requirements of Act No. 69/2018 Coll. on Cybersecurity and the corresponding decree, in effect at the time the analysis was conducted. From the perspective of the Cyber Security Act,
the company is not listed in the register of essential service operators and does not fall under any of the categories of entities specified in the annexes to the Act; therefore, it does not have the status of an essential service operator. Nevertheless, the company was interested in voluntarily adapting to the increased requirements for information and cybersecurity, particularly given the cross-border nature of its activities and the processing of data on employees and personnel deployed to international projects.
As part of the analysis, we evaluated the organizational and technical aspects of security measures in accordance with ISO 27001 and the Cyber Security Act (ZoKB)—information security management, asset management, risk management, access control, security in the operation of information systems, protection of employee and subcontractor data, data backup and recovery, as well as security in the cross-border provision of construction and personnel services.
The outcome was a proposal for security measures and recommendations for integrating security elements into the company’s processes, with an emphasis on protecting sensitive and critical information assets, which served as the basis for the company’s next steps toward voluntarily improving cybersecurity.

A company operating in the construction sector

Cybersecurity

For a construction company operating in the underground and civil engineering sector (tunneling and excavation work, construction of highway and civil engineering sections in Slovakia and abroad), we prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
As part of the analysis, we assessed the company’s scope of business, its classification under SK NACE, and other relevant criteria established by legislation (in particular, the size of the entity and the sector in which it operates, including its role in the construction of critical transportation infrastructure), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cyber Security Act, and if so, to what extent.
We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a construction company operating in the underground and civil engineering sector (tunneling and excavation work, construction of highway and civil engineering sections in Slovakia and abroad), we prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
As part of the analysis, we assessed the company’s scope of business, its classification under SK NACE, and other relevant criteria established by legislation (in particular, the size of the entity and the sector in which it operates, including its role in the construction of critical transportation infrastructure), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cyber Security Act, and if so, to what extent.
We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a construction company operating in the underground and civil engineering sector (tunneling and excavation work, construction of highway and civil engineering sections in Slovakia and abroad), we prepared an organizational assessment analysis to determine whether the company is a regulated entity within the meaning of Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 (the NIS2 Directive), Act No. 69/2018 Coll. on Cybersecurity, and related applicable regulations.
As part of the analysis, we assessed the company’s scope of business, its classification under SK NACE, and other relevant criteria established by legislation (in particular, the size of the entity and the sector in which it operates, including its role in the construction of critical transportation infrastructure), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cyber Security Act, and if so, to what extent.
We prepared the assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

A company operating in the manufacturing sector

Cybersecurity

For a manufacturing company operating in the field of design and production of specialized machinery and equipment for the food industry (confectionery and bakery production), we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including systems used in the design, construction, and testing of custom production lines and machines (CAD/design software, data from the company’s own testing center).
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development, design, and maintenance of technical documentation and software tools, protection of know-how and project documentation prepared on a custom basis for individual clients, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting sensitive design and technological data, which represent the company’s key know-how in the implementation of custom projects.
The output was a structured GAP analysis providing an overview of the current state of security, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of design and production of specialized machinery and equipment for the food industry (confectionery and bakery production), we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including systems used in the design, construction, and testing of custom production lines and machines (CAD/design software, data from the company’s own testing center).
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development, design, and maintenance of technical documentation and software tools, protection of know-how and project documentation prepared on a custom basis for individual clients, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting sensitive design and technological data, which represent the company’s key know-how in the implementation of custom projects.
The output was a structured GAP analysis providing an overview of the current state of security, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of design and production of specialized machinery and equipment for the food industry (confectionery and bakery production), we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including systems used in the design, construction, and testing of custom production lines and machines (CAD/design software, data from the company’s own testing center).
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, security in the development, design, and maintenance of technical documentation and software tools, protection of know-how and project documentation prepared on a custom basis for individual clients, data backup and recovery, as well as security in the operation of networks and information systems. We placed particular emphasis on protecting sensitive design and technological data, which represent the company’s key know-how in the implementation of custom projects.
The output was a structured GAP analysis providing an overview of the current state of security, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

A company operating in the field of specialized construction work

Cybersecurity

For a company operating in the field of other specialized construction work, with a focus on heating and air conditioning installations, we have prepared an organizational assessment analysis to determine whether the company is a subject to the requirements under Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 of December 14, 2022, on measures to ensure a high common level of cybersecurity in the Union, amending Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (hereinafter referred to as the “NIS2 Directive”), Act No. 69/2018 Coll. on Cybersecurity and on Amendments to Certain Acts, as amended (hereinafter also referred to as the “Cybersecurity Act”), and related applicable regulations.
As part of the analysis, we assessed the company’s business activities, its classification under the SK NACE classification, and other relevant criteria set forth by legislation (in particular, the size of the entity and the sector in which it operates), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cybersecurity Act, and, if so, to what extent.
We prepared this assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a company operating in the field of other specialized construction work, with a focus on heating and air conditioning installations, we have prepared an organizational assessment analysis to determine whether the company is a subject to the requirements under Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 of December 14, 2022, on measures to ensure a high common level of cybersecurity in the Union, amending Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (hereinafter referred to as the “NIS2 Directive”), Act No. 69/2018 Coll. on Cybersecurity and on Amendments to Certain Acts, as amended (hereinafter also referred to as the “Cybersecurity Act”), and related applicable regulations.
As part of the analysis, we assessed the company’s business activities, its classification under the SK NACE classification, and other relevant criteria set forth by legislation (in particular, the size of the entity and the sector in which it operates), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cybersecurity Act, and, if so, to what extent.
We prepared this assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

For a company operating in the field of other specialized construction work, with a focus on heating and air conditioning installations, we have prepared an organizational assessment analysis to determine whether the company is a subject to the requirements under Directive (EU) 2022/2555 of the European Parliament and of the Council (EU) 2022/2555 of December 14, 2022, on measures to ensure a high common level of cybersecurity in the Union, amending Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (hereinafter referred to as the “NIS2 Directive”), Act No. 69/2018 Coll. on Cybersecurity and on Amendments to Certain Acts, as amended (hereinafter also referred to as the “Cybersecurity Act”), and related applicable regulations.
As part of the analysis, we assessed the company’s business activities, its classification under the SK NACE classification, and other relevant criteria set forth by legislation (in particular, the size of the entity and the sector in which it operates), based on which we determined whether the company is subject to the obligations arising from the NIS2 Directive and the Cybersecurity Act, and, if so, to what extent.
We prepared this assessment based on an individual review of the company, drawing on publicly available sources—the Register of Financial Statements, the Slovak Commercial Register, the Slovak Trade Register, and the Register of Legal Entities—as well as information obtained during individual consultations with the client.
The outcome was a clear opinion on the applicability of the NIS2 Directive and the Cybersecurity Act to the organization, which served as the basis for any further steps regarding the company’s cybersecurity framework.

A company operating in the electronics manufacturing sector

Cybersecurity

For a manufacturing company operating in the field of electronics manufacturing services (EMS)—including the placement and assembly of printed circuit boards, complete product assemblies, and electromechanical assemblies for global clients, including the automotive industry—we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including production process control systems and the parent group’s information systems with which the Slovak facility is interconnected.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, production process continuity, and human resources security. We placed particular emphasis on the integration of production (operational) technologies with the corporate IT infrastructure and the protection of sensitive project and product data that the company processes on behalf of its international clients, including entities in the automotive industry.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of electronics manufacturing services (EMS)—including the placement and assembly of printed circuit boards, complete product assemblies, and electromechanical assemblies for global clients, including the automotive industry—we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including production process control systems and the parent group’s information systems with which the Slovak facility is interconnected.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, production process continuity, and human resources security. We placed particular emphasis on the integration of production (operational) technologies with the corporate IT infrastructure and the protection of sensitive project and product data that the company processes on behalf of its international clients, including entities in the automotive industry.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

For a manufacturing company operating in the field of electronics manufacturing services (EMS)—including the placement and assembly of printed circuit boards, complete product assemblies, and electromechanical assemblies for global clients, including the automotive industry—we prepared an assessment of the current state of cybersecurity along with a GAP analysis aimed at enhancing the security of information systems.
The goal of the project was to compare the company’s information and cybersecurity status with the requirements of applicable legislation and to identify and evaluate assets, risks, vulnerabilities, and potential threats within the company’s information systems and environment, including production process control systems and the parent group’s information systems with which the Slovak facility is interconnected.
As part of the analysis, we assessed organizational and technical gaps across various areas of security measures—cybersecurity organization and management, asset and information system management, access control, network and information system operational security, protection against malicious code, data backup and recovery, production process continuity, and human resources security. We placed particular emphasis on the integration of production (operational) technologies with the corporate IT infrastructure and the protection of sensitive project and product data that the company processes on behalf of its international clients, including entities in the automotive industry.
The output was a structured GAP analysis providing an overview of the current security status, identification of deficiencies, and recommendations for implementing the security documentation and measures necessary to achieve compliance with applicable legislation, which served as the basis for the company’s next steps in the area of cybersecurity.

Client ID protected by the GDPR

GDPR Compliance for Schools and Educational Institutions

For clients in the education sector, we have implemented a comprehensive compliance process focused on personal data protection in accordance with Act No. 245/2008 Coll. on Upbringing and Education (the Education Act). In the public sector, where large amounts of personal data are processed—including that of students, their legal guardians, as well as school principals, teachers, and other employees—we established procedures for processing special categories of personal data and implemented appropriate technical and organizational measures, including physical and facility security.
We have also addressed the issue of video surveillance for our clients—in connection with the legal basis under Article 6(1)(e) of the GDPR, we have prepared a data protection impact assessment. Ensuring compliance with the GDPR also involved establishing a system for obtaining consent to the processing of children’s personal data and that of their legal guardians, as well as providing guidance on selecting appropriate online platforms for distance learning with regard to adequate protection of personal data.
As part of our role as a data protection officer, we provide clients in the education sector with comprehensive and regular compliance advice on an ongoing basis.

For clients in the education sector, we have implemented a comprehensive compliance process focused on personal data protection in accordance with Act No. 245/2008 Coll. on Upbringing and Education (the Education Act). In the public sector, where large amounts of personal data are processed—including that of students, their legal guardians, as well as school principals, teachers, and other employees—we established procedures for processing special categories of personal data and implemented appropriate technical and organizational measures, including physical and facility security.
We have also addressed the issue of video surveillance for our clients—in connection with the legal basis under Article 6(1)(e) of the GDPR, we have prepared a data protection impact assessment. Ensuring compliance with the GDPR also involved establishing a system for obtaining consent to the processing of children’s personal data and that of their legal guardians, as well as providing guidance on selecting appropriate online platforms for distance learning with regard to adequate protection of personal data.
As part of our role as a data protection officer, we provide clients in the education sector with comprehensive and regular compliance advice on an ongoing basis.

For clients in the education sector, we have implemented a comprehensive compliance process focused on personal data protection in accordance with Act No. 245/2008 Coll. on Upbringing and Education (the Education Act). In the public sector, where large amounts of personal data are processed—including that of students, their legal guardians, as well as school principals, teachers, and other employees—we established procedures for processing special categories of personal data and implemented appropriate technical and organizational measures, including physical and facility security.
We have also addressed the issue of video surveillance for our clients—in connection with the legal basis under Article 6(1)(e) of the GDPR, we have prepared a data protection impact assessment. Ensuring compliance with the GDPR also involved establishing a system for obtaining consent to the processing of children’s personal data and that of their legal guardians, as well as providing guidance on selecting appropriate online platforms for distance learning with regard to adequate protection of personal data.
As part of our role as a data protection officer, we provide clients in the education sector with comprehensive and regular compliance advice on an ongoing basis.

Client ID protected by the GDPR

GDPR Compliance in the Financial Sector

As a company, we have also addressed personal data protection issues in the financial sector for clients in Slovakia and the Czech Republic. We took an individualized approach to each client, which in turn led to the implementation of a comprehensive and tailored GDPR compliance framework within the company’s processes. We oversaw the preparation of security documentation, the notification obligations to data subjects, and the establishment of basic processes in accordance with Act No. 18/2018 Coll. on the Protection of Personal Data and the GDPR. We provided our clients with guidance on automated decision-making, including profiling, in accordance with Article 22 of the GDPR.

As part of our role as the data protection officer, we are available to clients through regular and comprehensive compliance consulting.

As a company, we have also addressed personal data protection issues in the financial sector for clients in Slovakia and the Czech Republic. We took an individualized approach to each client, which in turn led to the implementation of a comprehensive and tailored GDPR compliance framework within the company’s processes. We oversaw the preparation of security documentation, the notification obligations to data subjects, and the establishment of basic processes in accordance with Act No. 18/2018 Coll. on the Protection of Personal Data and the GDPR. We provided our clients with guidance on automated decision-making, including profiling, in accordance with Article 22 of the GDPR.

As part of our role as the data protection officer, we are available to clients through regular and comprehensive compliance consulting.

As a company, we have also addressed personal data protection issues in the financial sector for clients in Slovakia and the Czech Republic. We took an individualized approach to each client, which in turn led to the implementation of a comprehensive and tailored GDPR compliance framework within the company’s processes. We oversaw the preparation of security documentation, the notification obligations to data subjects, and the establishment of basic processes in accordance with Act No. 18/2018 Coll. on the Protection of Personal Data and the GDPR. We provided our clients with guidance on automated decision-making, including profiling, in accordance with Article 22 of the GDPR.

As part of our role as the data protection officer, we are available to clients through regular and comprehensive compliance consulting.

Client ID protected by the GDPR

GDPR Compliance in the Investment Sector

We have long provided comprehensive protection of clients’ personal data in the investment sector, operating successfully in both the Slovak and Czech markets. In addition to providing regular consulting services, we have handled the comprehensive management of day-to-day operations, the preparation of security documentation, and—within the framework of GDPR compliance—the rights and obligations of legal entities and individuals in preventing and detecting money laundering and terrorist financing pursuant to Act No. 297/2008 Coll. on Protection against Money Laundering and on Protection against Terrorist Financing, and on Amendments to Certain Acts.

We have long provided comprehensive protection of clients’ personal data in the investment sector, operating successfully in both the Slovak and Czech markets. In addition to providing regular consulting services, we have handled the comprehensive management of day-to-day operations, the preparation of security documentation, and—within the framework of GDPR compliance—the rights and obligations of legal entities and individuals in preventing and detecting money laundering and terrorist financing pursuant to Act No. 297/2008 Coll. on Protection against Money Laundering and on Protection against Terrorist Financing, and on Amendments to Certain Acts.

We have long provided comprehensive protection of clients’ personal data in the investment sector, operating successfully in both the Slovak and Czech markets. In addition to providing regular consulting services, we have handled the comprehensive management of day-to-day operations, the preparation of security documentation, and—within the framework of GDPR compliance—the rights and obligations of legal entities and individuals in preventing and detecting money laundering and terrorist financing pursuant to Act No. 297/2008 Coll. on Protection against Money Laundering and on Protection against Terrorist Financing, and on Amendments to Certain Acts.

Client ID protected by the GDPR

GDPR Compliance for Online Stores and Websites

Since our inception, we have also provided our clients with consulting and services in the field of e-commerce. We have offered solutions in the area of personal data protection to e-shop administrators and website operators by preparing security documentation and information notices for data subjects. We have drafted consent forms for data subjects for purposes related to marketing or promotion. As part of GDPR compliance, we configured cookies in accordance with the appropriate legal basis and ensured the correct wording of texts and other requirements subject to the GDPR and Act No. 18/2018 Coll. on the Protection of Personal Data.

Since our inception, we have also provided our clients with consulting and services in the field of e-commerce. We have offered solutions in the area of personal data protection to e-shop administrators and website operators by preparing security documentation and information notices for data subjects. We have drafted consent forms for data subjects for purposes related to marketing or promotion. As part of GDPR compliance, we configured cookies in accordance with the appropriate legal basis and ensured the correct wording of texts and other requirements subject to the GDPR and Act No. 18/2018 Coll. on the Protection of Personal Data.

Since our inception, we have also provided our clients with consulting and services in the field of e-commerce. We have offered solutions in the area of personal data protection to e-shop administrators and website operators by preparing security documentation and information notices for data subjects. We have drafted consent forms for data subjects for purposes related to marketing or promotion. As part of GDPR compliance, we configured cookies in accordance with the appropriate legal basis and ensured the correct wording of texts and other requirements subject to the GDPR and Act No. 18/2018 Coll. on the Protection of Personal Data.

Client ID protected by the GDPR

GDPR Compliance in Healthcare

Our experts, who have extensive experience, have been actively providing services in the healthcare sector for several years as part of our personal data protection efforts. We have taken an individualized approach with every client from the very beginning, which is why we can confidently say that the services we have provided have been exceptional and comprehensive. Many healthcare facilities, pharmacies, clinics, health centers, and hospitals have placed their trust in us.
Given that the processing of a special category of personal data requires a higher level of security, we have secured the services of a data protection officer, managed the technical aspects of personal data protection, and prepared detailed security and health documentation in accordance with Act No. 576/2004 Coll. on Health Care, Services Related to the Provision of Health Care, and on Amendments to Certain Laws. We provided regular training for physicians and healthcare professionals who work with sensitive patient personal data, and we conducted annual and regular inspections, based on which we assessed and documented the current status and ensured compliance with the necessary requirements related to the processing and protection of personal data in the healthcare sector.

As part of our GDPR compliance efforts, we also provided our clients with regular consulting services, which allowed them to avoid having to deal with personal data protection issues in detail.

Our experts, who have extensive experience, have been actively providing services in the healthcare sector for several years as part of our personal data protection efforts. We have taken an individualized approach with every client from the very beginning, which is why we can confidently say that the services we have provided have been exceptional and comprehensive. Many healthcare facilities, pharmacies, clinics, health centers, and hospitals have placed their trust in us.
Given that the processing of a special category of personal data requires a higher level of security, we have secured the services of a data protection officer, managed the technical aspects of personal data protection, and prepared detailed security and health documentation in accordance with Act No. 576/2004 Coll. on Health Care, Services Related to the Provision of Health Care, and on Amendments to Certain Laws. We provided regular training for physicians and healthcare professionals who work with sensitive patient personal data, and we conducted annual and regular inspections, based on which we assessed and documented the current status and ensured compliance with the necessary requirements related to the processing and protection of personal data in the healthcare sector.

As part of our GDPR compliance efforts, we also provided our clients with regular consulting services, which allowed them to avoid having to deal with personal data protection issues in detail.

Our experts, who have extensive experience, have been actively providing services in the healthcare sector for several years as part of our personal data protection efforts. We have taken an individualized approach with every client from the very beginning, which is why we can confidently say that the services we have provided have been exceptional and comprehensive. Many healthcare facilities, pharmacies, clinics, health centers, and hospitals have placed their trust in us.
Given that the processing of a special category of personal data requires a higher level of security, we have secured the services of a data protection officer, managed the technical aspects of personal data protection, and prepared detailed security and health documentation in accordance with Act No. 576/2004 Coll. on Health Care, Services Related to the Provision of Health Care, and on Amendments to Certain Laws. We provided regular training for physicians and healthcare professionals who work with sensitive patient personal data, and we conducted annual and regular inspections, based on which we assessed and documented the current status and ensured compliance with the necessary requirements related to the processing and protection of personal data in the healthcare sector.

As part of our GDPR compliance efforts, we also provided our clients with regular consulting services, which allowed them to avoid having to deal with personal data protection issues in detail.

Client ID protected by the GDPR

GDPR Compliance in the Manufacturing Sector

Our company’s diverse client base consisted of both small and large manufacturing companies. In addition to preparing security documentation and handling basic administrative tasks, we focused on securing intermediary contracts with third parties for manufacturing companies and addressed issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA). For our clients in the manufacturing sector, we also provided oversight of personal data protection in our capacity as the data protection officer.
We oversaw appropriate monitoring via the CCTV system in the manufacturing facility, inspected individual cameras, and defined the scope of their data processing. As part of this service, we conducted regular training for authorized personnel alongside monitoring activities to ensure the appropriateness and up-to-date nature of the processing of data subjects’ personal data.
We provided clients with comprehensive GDPR compliance consulting, including in cases involving complaints, where we communicated with the Office for Personal Data Protection. We also took a tailored approach to drafting consent forms for the processing of personal data and regularly informed clients about the latest developments regarding guidelines and methodologies issued by the Office for Personal Data Protection that directly affected them.

Our company’s diverse client base consisted of both small and large manufacturing companies. In addition to preparing security documentation and handling basic administrative tasks, we focused on securing intermediary contracts with third parties for manufacturing companies and addressed issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA). For our clients in the manufacturing sector, we also provided oversight of personal data protection in our capacity as the data protection officer.
We oversaw appropriate monitoring via the CCTV system in the manufacturing facility, inspected individual cameras, and defined the scope of their data processing. As part of this service, we conducted regular training for authorized personnel alongside monitoring activities to ensure the appropriateness and up-to-date nature of the processing of data subjects’ personal data.
We provided clients with comprehensive GDPR compliance consulting, including in cases involving complaints, where we communicated with the Office for Personal Data Protection. We also took a tailored approach to drafting consent forms for the processing of personal data and regularly informed clients about the latest developments regarding guidelines and methodologies issued by the Office for Personal Data Protection that directly affected them.

Our company’s diverse client base consisted of both small and large manufacturing companies. In addition to preparing security documentation and handling basic administrative tasks, we focused on securing intermediary contracts with third parties for manufacturing companies and addressed issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA). For our clients in the manufacturing sector, we also provided oversight of personal data protection in our capacity as the data protection officer.
We oversaw appropriate monitoring via the CCTV system in the manufacturing facility, inspected individual cameras, and defined the scope of their data processing. As part of this service, we conducted regular training for authorized personnel alongside monitoring activities to ensure the appropriateness and up-to-date nature of the processing of data subjects’ personal data.
We provided clients with comprehensive GDPR compliance consulting, including in cases involving complaints, where we communicated with the Office for Personal Data Protection. We also took a tailored approach to drafting consent forms for the processing of personal data and regularly informed clients about the latest developments regarding guidelines and methodologies issued by the Office for Personal Data Protection that directly affected them.

Fitness Center Chain Operator

GDPR Compliance in the Manufacturing Sector

Our company’s diverse client base includes both small and large manufacturing companies. In addition to preparing safety documentation and handling basic administrative tasks, we focus on securing brokerage agreements with third parties for manufacturing companies, and we address issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA).

Our company’s diverse client base includes both small and large manufacturing companies. In addition to preparing safety documentation and handling basic administrative tasks, we focus on securing brokerage agreements with third parties for manufacturing companies, and we address issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA).

Our company’s diverse client base includes both small and large manufacturing companies. In addition to preparing safety documentation and handling basic administrative tasks, we focus on securing brokerage agreements with third parties for manufacturing companies, and we address issues related to the transfer of personal data to countries outside the European Union (EU) and the European Economic Area (EEA).

A company operating in the retail sector

Industrial Safety

For a company operating in the wholesale and retail sectors, we provided comprehensive industrial security services with the aim of preparing the documentation necessary to obtain an industrial security clearance for the relevant classification level in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and National Security Authority Decree No. 301/2013 Coll.
As part of the project, we conducted an analysis of the environment in which classified information is expected to be processed and, based on this analysis, recommended the classification level, the secure area, and the method of processing classified information using technical equipment, as well as measures to ensure administrative and personnel security. We prepared the business operator’s security plan in accordance with National Security Authority Decree No. 301/2013 Coll., an application for the issuance of an industrial security certificate, and provided assistance in preparing the related applications and declarations necessary for conducting the security clearance review. The scope of work also included a personnel security directive in accordance with NBÚ Decree No. 134/2016 Coll.
In the area of specialized documentation, we prepared documentation and an administrative security directive in accordance with NBÚ Decree No. 48/2019 Coll., and provided the supporting materials (security project for the technical device, guidelines, forms) required for the certification of the technical device intended for the processing of classified information in accordance with NBÚ Decree No. 339/2004 Z. z., configured and prepared the technical equipment for certification, and proposed the optimization of the secure area in accordance with NBÚ Decree No. 336/2004 Coll., as amended by Decree No. 315/2006 Coll. The scope of delivery also included documentation on physical and facility security, including an inspection log and a visitor log.
The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ inspection and obtaining the company’s industrial security certification.

For a company operating in the wholesale and retail sectors, we provided comprehensive industrial security services with the aim of preparing the documentation necessary to obtain an industrial security clearance for the relevant classification level in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and National Security Authority Decree No. 301/2013 Coll.
As part of the project, we conducted an analysis of the environment in which classified information is expected to be processed and, based on this analysis, recommended the classification level, the secure area, and the method of processing classified information using technical equipment, as well as measures to ensure administrative and personnel security. We prepared the business operator’s security plan in accordance with National Security Authority Decree No. 301/2013 Coll., an application for the issuance of an industrial security certificate, and provided assistance in preparing the related applications and declarations necessary for conducting the security clearance review. The scope of work also included a personnel security directive in accordance with NBÚ Decree No. 134/2016 Coll.
In the area of specialized documentation, we prepared documentation and an administrative security directive in accordance with NBÚ Decree No. 48/2019 Coll., and provided the supporting materials (security project for the technical device, guidelines, forms) required for the certification of the technical device intended for the processing of classified information in accordance with NBÚ Decree No. 339/2004 Z. z., configured and prepared the technical equipment for certification, and proposed the optimization of the secure area in accordance with NBÚ Decree No. 336/2004 Coll., as amended by Decree No. 315/2006 Coll. The scope of delivery also included documentation on physical and facility security, including an inspection log and a visitor log.
The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ inspection and obtaining the company’s industrial security certification.

For a company operating in the wholesale and retail sectors, we provided comprehensive industrial security services with the aim of preparing the documentation necessary to obtain an industrial security clearance for the relevant classification level in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and National Security Authority Decree No. 301/2013 Coll.
As part of the project, we conducted an analysis of the environment in which classified information is expected to be processed and, based on this analysis, recommended the classification level, the secure area, and the method of processing classified information using technical equipment, as well as measures to ensure administrative and personnel security. We prepared the business operator’s security plan in accordance with National Security Authority Decree No. 301/2013 Coll., an application for the issuance of an industrial security certificate, and provided assistance in preparing the related applications and declarations necessary for conducting the security clearance review. The scope of work also included a personnel security directive in accordance with NBÚ Decree No. 134/2016 Coll.
In the area of specialized documentation, we prepared documentation and an administrative security directive in accordance with NBÚ Decree No. 48/2019 Coll., and provided the supporting materials (security project for the technical device, guidelines, forms) required for the certification of the technical device intended for the processing of classified information in accordance with NBÚ Decree No. 339/2004 Z. z., configured and prepared the technical equipment for certification, and proposed the optimization of the secure area in accordance with NBÚ Decree No. 336/2004 Coll., as amended by Decree No. 315/2006 Coll. The scope of delivery also included documentation on physical and facility security, including an inspection log and a visitor log.
The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ inspection and obtaining the company’s industrial security certification.

A company operating in the field of road freight transport and logistics

Industrial Safety

For a client operating in the field of road freight transport and logistics, we handled the entire process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSO Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSO, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ vetting and obtaining the company’s industrial security certification.

A company operating in the field of mechanical engineering and the manufacture of metal components

Industrial Safety

For a client operating in the field of mechanical engineering and the manufacture of metal components for the automotive industry, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the business’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company engaged in the wholesale trade of agricultural machinery, equipment, and accessories

Industrial Safety

For a client operating in the agricultural machinery wholesale sector, equipment, and accessories, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the business owner’s security plan in accordance with NSO Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSO, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company operating in the field of business brokerage and computer services

Industrial Safety

For a client operating in the field of trade brokerage and computer services, we handled the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, arranged background checks for the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company engaged in surveying and cartographic activities

Industrial Safety

For a client operating in the field of surveying and cartography, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company engaged in the development and manufacture of optical and detection systems for security and defense applications

Industrial Safety

For a client operating in the field of development and production of optical and detection systems for security and defense applications, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we prepared the business’s security plan in accordance with NSA Decree No. 301/2013 Coll., drafted and submitted the application for an industrial security clearance, arranged background checks for the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company operating in the construction industry—building residential and non-residential structures

Industrial Safety

For a client operating in the construction industry — specializing in the construction of residential and non-residential buildings—we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company engaged in the manufacture of electric lighting fixtures and retail sales

Industrial Safety

For a client operating in the field of electric lighting fixture manufacturing and the retail sale of technical goods, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Z. z. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSO Decree No. 301/2013 Coll., prepared and submitted an application for an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSO, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company operating in the construction and wood processing industries

Industrial Safety

For a client operating in the construction and wood processing industries, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company operating in the field of contract manufacturing of electronics and electromechanical assemblies

Industrial Safety

For a client operating in the field of contract manufacturing of electronics and electromechanical assemblies, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for the issuance of an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

A company operating in the field of computer programming and IT services

Industrial Safety

For a client operating in the field of computer programming and IT services, we managed the comprehensive process of obtaining an industrial security clearance in accordance with Act No. 215/2004 Coll. on the Protection of Classified Information and Decree No. 301/2013 Coll. of the National Security Authority. As part of the project, we developed the company’s security plan in accordance with NSA Decree No. 301/2013 Coll., prepared and submitted an application for an industrial security clearance, conducted background checks on the company’s executives, and prepared the necessary supporting documentation for the NSA, including overviews, declarations, files, and a verification document. The project resulted in complete documentation and established processes necessary for successfully passing the NBÚ review and obtaining the company’s industrial security certification.

CENTRUM ENVIRONMENTÁLNEJ VÝCHOVY TURIEC, Jána Kostru 19, 03851 Turčianska Štiavnička

Civic Association

The Turiec Environmental Education Center is a civic association founded in 2013, whose goal is to integrate environmental education into the educational process at elementary and secondary schools. It offers students a variety of activities related to nature and landscape conservation, as well as activities that help raise awareness among the general public and professionals in the fields of environmental education and ecology.

The Turiec Environmental Education Center is a civic association founded in 2013, whose goal is to integrate environmental education into the educational process at elementary and secondary schools. It offers students a variety of activities related to nature and landscape conservation, as well as activities that help raise awareness among the general and professional public in the fields of environmental education and ecology.

We knew that the functioning and operation of the civic association depended on students in elementary and secondary schools, whose doors were gradually beginning to close at that time due to the adverse conditions of the emerging COVID-19 pandemic. The nonprofit’s activities were suspended for a time. However, the same cannot be said for the data being processed. Since the organization’s activities involve the collection of personal data from students and children—as defined by the GDPR—the Top Privacy team rolled up its sleeves and got to work.

In early 2020, we contacted the center’s director, Mr. Martin Kondek, M.A., for a brief conversation, during which we presented a proposal for mutual assistance and cooperation in the area of personal data protection. Thanks to his prompt response and willingness to cooperate, we obtained all the necessary information to implement the GDPR within the organization. The Top Privacy office ensured the comprehensive preparation, delivery, and subsequent explanation of the security documentation, along with the information notice for data subjects, in both printed and electronic formats, which is also available for viewing on the association’s website. We understood the need for positive promotion of happy children during the educational process through photos on the association’s website or in its brochures.  For this reason, we prepared consent forms for the processing of personal data, the relevant forms, and detailed instructions on how to handle such data securely.

“As a civic association required to have a GDPR compliance plan in place, we turned to Top Privacy s.r.o. We were very pleasantly surprised by their helpfulness, professional approach, and willingness to discuss the necessary details regarding personal data processing. They always made time for our questions and offered suitable solutions. If you’re considering which company to contact, we recommend Top Privacy. You’ll see for yourself that it’s the right choice,” adds the center’s manager, Mr. Kondek, M.A.

We assured our client that they can contact us at any time with questions regarding the GDPR, even after our collaboration has ended.

The Turiec Environmental Education Center is a civic association founded in 2013, whose goal is to integrate environmental education into the educational process at elementary and secondary schools. It offers students a variety of activities related to nature and landscape conservation, as well as activities that help raise awareness among the general and professional public in the fields of environmental education and ecology.

We knew that the functioning and operation of the civic association depended on students in elementary and secondary schools, whose doors were gradually beginning to close at that time due to the adverse conditions of the emerging COVID-19 pandemic. The nonprofit’s activities were suspended for a time. However, the same cannot be said for the data being processed. Since the organization’s activities involve the collection of personal data from students and children—as defined by the GDPR—the Top Privacy team rolled up its sleeves and got to work.

In early 2020, we contacted the center’s director, Mr. Martin Kondek, M.A., for a brief conversation, during which we presented a proposal for mutual assistance and cooperation in the area of personal data protection. Thanks to his prompt response and willingness to cooperate, we obtained all the necessary information to implement the GDPR within the organization. The Top Privacy office ensured the comprehensive preparation, delivery, and subsequent explanation of the security documentation, along with the information notice for data subjects, in both printed and electronic formats, which is also available for viewing on the association’s website. We understood the need for positive promotion of happy children during the educational process through photos on the association’s website or in its brochures.  For this reason, we prepared consent forms for the processing of personal data, the relevant forms, and detailed instructions on how to handle such data securely.

“As a civic association required to have a GDPR compliance plan in place, we turned to Top Privacy s.r.o. We were very pleasantly surprised by their helpfulness, professional approach, and willingness to discuss the necessary details regarding personal data processing. They always made time for our questions and offered suitable solutions. If you’re considering which company to contact, we recommend Top Privacy. You’ll see for yourself that it’s the right choice,” adds the center’s manager, Mr. Kondek, M.A.

We assured our client that they can contact us at any time with questions regarding the GDPR, even after our collaboration has ended.

Detský divadelný súbor Kamarát, Martin

Cyberbullying in a Theater Production

Our lives have changed significantly due to the COVID-19 pandemic, and we have started spending much more time online. Activities that we used to do outside the home as part of our work or school responsibilities have suddenly shifted to working directly from home. Children remain the most at-risk group in the online world, which is why we decided to focus our next project specifically on their safety and the security of their personal data.

Our lives have changed significantly due to the COVID-19 pandemic, and we have started spending much more time online. Activities that we used to do outside the home as part of our work or school responsibilities have suddenly shifted to being done directly from home. Children remain the most at-risk group in the online world, which is why we decided to focus our next project specifically on their safety and the security of their personal data.

“Better to see once than to hear a hundred times.” We were guided by this Slovak proverb in carrying out a project titled “Cyberbullying in a Theater Performance.” In collaboration with the Kamarát Children’s Theater Troupe in Martin, we created a short story that reflects the dangers of the virtual world. The troupe boasts a long history and the distinction of being the oldest children’s theater troupe in Slovakia, founded by artistic director and stage director Emília Hajdúchová. Today, it is led by Eva Benčíková, M.A., with whom we combined our ideas after a joint meeting and created a short script for the production. Our goal was to raise awareness among parents—as well as the children themselves—so that they would be more cautious and careful on social media.

The story takes place in a young girl’s bedroom. She is at an age when even the smallest problem is experienced very deeply and intensely. She therefore spends her days on social media with her friends, until she realizes that not all virtual relationships and friendships are real.

Despite the challenging circumstances, we believe that we will all meet soon and step into the world of dangerous cyberbullying on the theater stage.

Our lives have changed significantly due to the COVID-19 pandemic, and we have started spending much more time online. Activities that we used to do outside the home as part of our work or school responsibilities have suddenly shifted to being done directly from home. Children remain the most at-risk group in the online world, which is why we decided to focus our next project specifically on their safety and the security of their personal data.

“Better to see once than to hear a hundred times.” We were guided by this Slovak proverb in carrying out a project titled “Cyberbullying in a Theater Performance.” In collaboration with the Kamarát Children’s Theater Troupe in Martin, we created a short story that reflects the dangers of the virtual world. The troupe boasts a long history and the distinction of being the oldest children’s theater troupe in Slovakia, founded by artistic director and stage director Emília Hajdúchová. Today, it is led by Eva Benčíková, M.A., with whom we combined our ideas after a joint meeting and created a short script for the production. Our goal was to raise awareness among parents—as well as the children themselves—so that they would be more cautious and careful on social media.

The story takes place in a young girl’s bedroom. She is at an age when even the smallest problem is experienced very deeply and intensely. She therefore spends her days on social media with her friends, until she realizes that not all virtual relationships and friendships are real.

Despite the challenging circumstances, we believe that we will all meet soon and step into the world of dangerous cyberbullying on the theater stage.

Možnosť voľby

Civic Association

We would like to extend our sincere thanks to Top Privacy s.r.o. for their pro bono assistance with such an important topic as the GDPR—that is, the security and protection of personal data. We’re glad that everything is in order—whether at our breed-specific training sessions, on our website, or on our new website, which we’re working hard to launch. Special thanks go to Ms. Maruškinová, without whom none of this would have been possible. We appreciate your work and will continue to recommend your services to others.

"We would like to extend our sincere thanks to Top Privacy s.r.o. for their pro bono assistance with such an important topic as the GDPR—that is, the security and protection of personal data. We’re glad that everything is in order—whether at our family training sessions, on our website, or on our new website, which we’re working hard to launch. Special thanks go to Ms. Maruškinová, without whom none of this would have been possible.

We appreciate your work and will continue to recommend your services."
 

"We would like to extend our sincere thanks to Top Privacy s.r.o. for their pro bono assistance with such an important topic as the GDPR—that is, the security and protection of personal data. We’re glad that everything is in order—whether at our family training sessions, on our website, or on our new website, which we’re working hard to launch. Special thanks go to Ms. Maruškinová, without whom none of this would have been possible.

We appreciate your work and will continue to recommend your services."
 

What we helped our clients with