Five disciplines, thirteen ways to be useful to you.
You do not have to guess the right service. Tell us where you are stuck and we will suggest the shortest route.
Compliance
Cyber Security Act compliance
Gap analysis and thirteen measures, all the way to evidence.OPEN →02Audit readiness
An ordered evidence file and a review before the auditor arrives.OPEN →03Incident management
The procedure, the 24-hour and 72-hour reporting deadlines and the records that prove it is alive.OPEN →04ISO/IEC 27001
Mapping your records to the catalogue controls, without duplicated work.OPEN →Leadership and oversight
vCISO
Security leadership under contract, without a permanent hire.OPEN →06Data protection officer
The role under contract, records of processing, impact assessments and data subject requests.OPEN →07Risk management
Assessment, risk register and risk treatment plan.OPEN →Artificial intelligence
AI governance
Risk classification and a framework under the AI Act.OPEN →09Artificial intelligence threats
Synthetic media, fraud and autonomous attacks.OPEN →Training and talks
Staff training
Cyber security workshops for the board, IT and staff, with simulated phishing.OPEN →11Talks and conferences
Conference appearances and internal briefings for the board, in Croatian and English.OPEN →Our own products
ZKS Copilot
A question about the law, an answer with the article and a link.OPEN →13HeartOSINT
A copilot against romance scams.OPEN →Four situations that bring people to us
In each of them there is a first step that takes weeks, not months.
“The categorisation notice arrived and nobody inside has taken the work on.”
CONSEQUENCEThe twelve month deadline runs whether or not a project lead has been named. The people who would have to do the work are usually freed from their other duties too late.
WAY OUTA gap analysis against the thirteen measures gives a scored starting point and a plan with named owners within two to three weeks.
“We have the documentation, but we do not know whether it would pass an audit.”
CONSEQUENCEThe auditor asks for written evidence for 137 controls. A review almost always shows that a large part of the required documentation is missing, more often the evidence of practice than the documents themselves.
WAY OUTAn internal review that simulates the audit procedure, using the same scoring formulas. You know the finding before the auditor arrives.
“The board wants a report on cyber risk and we have no register.”
CONSEQUENCERisk management is the third of the thirteen measures. If the process is not documented, that is a direct non-compliance and grounds for a finding at the audit.
WAY OUTA risk register, a matrix following the NCSC-HR guidelines and a risk treatment plan. Three to six weeks for a medium-sized organisation.
“We rolled out artificial intelligence tools before we wrote the rules.”
CONSEQUENCEMost organisations do not know which artificial intelligence systems they use at all, because they are built into HR, finance and communication tools.
WAY OUTAn inventory and classification by the risk categories of the AI Act, with an acceptable use policy the team can apply straight away.
In all four the first step is the same: establish where you stand, scored and documented. The scope, duration and price of the full programme are estimated only after that.
Engagement models
One model has a fixed end, three run on. The last column matters most: how much of your team’s time it takes. We tell you that before you sign, not after.
How we start
Two weeks usually pass between the first call and the start of work. Every step has a deadline, and until you sign all it takes from you is half an hour of conversation.
Introductory call, 30 minutes, free of charge
A conversation about your situation, your obligations and your priorities. No slide deck and no commitment. By the end of the call you have an estimate of the scope and a realistic deadline.
Written proposal
A clearly bounded scope, a list of deliverables, a deadline and a price. What the proposal says is what gets delivered.
Agreement and start of work
We meet the key people on your side and set up the working framework.
Delivery and support
You can see how the work is progressing at any time. After the project ends we stay available for questions, changes in the law and preparation for an inspection.
What we do not do
Knowing what someone does not do is as useful as knowing what they do. If you need something from this list, tell us and we will point you further, with no referral fee.
How we set scope and price
Price follows scope, and scope follows the findings. That is why we do not quote a figure before we know where you stand. These are the factors that move it, so you can judge the order of magnitude in advance.
- The advanced level of measures instead of the basic one
- Several sites or separate legal entities in scope
- Operational technology and industrial control systems
- Documentation that barely exists
- Less than three months until an audit or inspection
- A large number of external suppliers with system access
- An existing ISO/IEC 27001 management system
- An internal security lead who takes on part of the work
- A clearly bounded scope, for example one measure or one system
- An orderly register of assets and business processes
- Running Cyber Security Act compliance and data protection as one project
- Phased delivery aligned with the budget cycle
How we bill
The proposal, with the content described in step 02, arrives within three to five working days of the introductory call. Travel costs and third party fees are listed separately or do not arise.
Every engagement begins with a confidentiality agreement, before any data is exchanged.
An indicative price list and terms of business are available as a separate document, on request.
Frequently asked questions
The questions we are asked most often before we start.
How does an engagement start?
With a thirty minute introductory call, free of charge. The written proposal follows within three to five working days.What does it cost?
Price follows scope, and scope is only known after a readiness review. That is why we start with a gap analysis and discuss the full programme with real numbers.How much of our time does it take?
It depends on the model, but we always tell you before you sign. For a readiness review it is usually a few hours per interviewee over two to three weeks.Do you work outside Zagreb?
We work across Croatia. Part of the work is remote, while conversations with the board and measure owners are usually in person.Can we take just one part?
You can. Most clients start with a gap analysis or a single measure and then decide how to continue.Related pages
The pages that explain the obligations behind these services.
Not sure what you need? Tell us where you are stuck.
Half an hour, no obligation. Tell us where you are stuck and we will tell you what the first step is.
