Security Documentation

In today’s world, where most data exists in digital form, cybersecurity is an integral part of personal data protection.

Under Act No. 69/2018 Coll. on Cybersecurity and on Amendments to Certain Acts, an operator of an essential service is required to implement security measures and to verify the effectiveness of those measures and compliance with the requirements set forth in this Act. An essential service operator is any entity that meets at least one specific sectoral criterion and one impact criterion.

As a company specializing in security services, we can lend you a helping hand and provide you with:

1. Analysis of specific sector-based criteria and impact criteria – through a detailed analysis, we will assess compliance with sector-based and impact criteria to determine the potential impact a cybersecurity incident could have on an information system or network. The output is a document based on which you can determine whether you fall under the list of essential service operators.

2. Cybersecurity Analysis – if the analysis of specific sector-based criteria and impact criteria demonstrates that you have a legal obligation to be included on the list of essential service providers, you must conduct a cybersecurity assessment in accordance with Act No. 69/2018 Coll. and National Security Authority Decree No. 227/2025 Coll. on security measures.

3. Development of Proposed Cybersecurity Measures – Based on the cybersecurity analysis, we will develop customized proposals for security measures (security documentation) in accordance with Decree No. 227/2025 Coll. of the National Security Authority on security measures, which establishes the content of security measures, the scope of general security measures for networks, information systems, and operational technologies, and the content and structure of security documentation.

4. Implementation of Cybersecurity Measures – We also develop and implement these proposed measures. From secure access management, through data control and protection against misuse, theft, or other inappropriate handling of your company’s data, to the protection of applications that clients regularly use in their work.

5. Specialized employee training—through our experts, we can provide your employees with information on social engineering and cybersecurity. Training sessions are conducted in direct collaboration with the client and with the general public in mind.

6. Advisory and consulting services – provided by our team of experts in the relevant fields. If necessary, we can represent you in proceedings before the National Security Authority.

For the purposes of organizing cybersecurity, we can provide you with the service of appointing a cybersecurity manager who:

  • has the authority to submit proposals and report information regarding cybersecurity directly to the statutory body of the essential service operator,
  • ensures the implementation of security measures within the cybersecurity management system,
  • is independent from the management of IT service operations and development,
  • and meets the knowledge standards for the position of cybersecurity manager as specified by a special regulation.

We also address this area from the perspective of technical consulting and implementation – you can find more information about our Cybersecurity service on the TRC website: Link

Are you interested in this service?