Systems operational /// Red team on call
// Remote across Europe // info@slapsec.com
v2026.05 · Independent cyber consultancy

Senior [cybersecurity]. Without the Big Four bill. Just the judgment.

The same people who signed your last audit — without the machinery behind them. We attack to discover, architect to resist, translate it for the regulator, protect the data and automate the operation.

EX — TEAMS FROM Senior talent democratized. We know that bill — we used to send it.
DXC·KPMG·Accenture·IBM·Deloitte·PwC

We came from the Big Four.
And from the trenches.

We've run critical banking infrastructure. We responded to real incidents. We signed audits that passed audits. That's not something you learn in a deck.

We built SlapSec because enterprise cyber consulting got expensive, slow and noisy. We go straight at the problem — and skip the theater.

We don't sell you frameworks. We fix things.

ex-DXCex-KPMGex-Accentureex-IBMex-Deloitte senior team offensive-born

Six clauses we sign,
not just say.

Not values on a wall — clauses in the contract. Each one is measurable, and if we break any of them, you don't pay for that phase.

the founders
C · 01The truth, even when it costs us the deal. A good “no” beats a comfortable “yes”.Always
C · 02Whoever signs the report did the work. No ghost juniors.100 %
C · 03Same lead from kickoff to closeout.1 : 1
C · 04Proposal in 72 hours, fixed price when the scope is clean.≤ 72 h
C · 05Critical findings reported the day we see them. No strategic timing, no saved-up sales.D + 0
C · 06We transfer capability and get out. Your data stays yours — ours is wiped.Clean exit

Four fronts.
One standard of craft.

From a two-week pentest to a full Zero Trust rollout — same crew, same standard. Pick one front, or run the whole cycle: each loop shrinks your attack surface.

01 / 04Operational

Red Team
& Threat Intel

Red team and pentesting — manual and automated — plus continuous external threat monitoring with our Digital Risk Radar. We find what a real attacker would exploit, before they do. PTES, OWASP, MITRE ATT&CK.

  • Web & API Pentest
  • Red Team Ops
  • Infra & AD Pentest
  • Cloud Pentest (AWS/Azure/GCP)
  • OT/ICS Pentest
  • Mobile Pentest
  • Social Engineering
  • Bug Bounty & Retainer
  • Digital Risk Radar
  • Dark Web Monitoring
02 / 04Operational

Zero Trust
Architecture

Design, implement and operate 'never trust, always verify' architectures. Identity-first, segmented, verified, measured — vendor-agnostic, with the market's leading platforms.

  • IAM & PAM
  • Microsegmentation
  • SASE & ZTNA
  • EDR / XDR
  • Cloud Posture (CSPM/CIEM)
  • Design & Governance
03 / 04Operational

GRC &
Compliance

Every technical finding translated into regulatory frameworks — ENS, ISO 27001, PCI DSS, GDPR — and actionable business decisions. Governance and security direction as a service, without drowning you in paperwork.

  • Compliance mapping (ENS · ISO 27001)
  • PCI DSS & GDPR
  • vCISO retainer
  • Governance & roadmap
  • Risk-to-business translation
  • Audit readiness
04 / 04Operational

Data &
Automation

Protect the data wherever it lives — DLP, IRM, DSPM with SealPath, arexdata and Microsoft Purview — and automate the operation: AI-assisted triage, continuous hardening, unattended certificate rotation.

  • DLP
  • IRM (SealPath)
  • DSPM (arexdata)
  • Microsoft Purview
  • AI-assisted triage
  • SOAR orchestration
  • Continuous hardening (CIS)
  • Certificate automation

Cybersecurity for SMBs.
Enterprise craft, right-sized.

Attacks run on autopilot — company size is not a shield. You don't need a security department to be well defended: you need senior judgment, a few hours at a time.

Challenge 01

Your big customers demand it

Vendor security questionnaires, ISO 27001, supply-chain clauses… more and more contracts hinge on proving your security. We get you through them without stalling your business.

Challenge 02

No security team? You don't need one.

A senior vCISO a few hours a month: clear priorities, sound decisions, and someone to call when something smells off. No impossible hires, no CISO payroll.

Challenge 03

SMB budget, senior work

Tiered pentesting — from a Lite scan to deep manual testing — at a fixed price. You know what you pay, what you get, and when. No surprises, no fine print.

Challenge 04

Ransomware doesn't check your size

If you're exposed, you get found. We watch your external footprint — domains, leaked credentials, dark web — and close what actually matters first.

Book a 45-min call → Straight answers · fixed prices · no strings

Regulated. Complex.
No room for error.

We work where cyber failures are expensive, visible and regulated. Every engagement maps to the threat model and compliance obligations of your sector.

SEC/FIN.01

Financial Services

Retail, commercial and investment banking, insurance, fintech. DORA, EBA ICT, PSD2, PCI-DSS scope reduction.

DORAEBAPCI-DSS
SEC/ENE.02

Energy & Utilities

Generation, distribution, O&G. OT/IT convergence, NIS2 essential entity compliance, SCADA hardening.

NIS2IEC-62443OT
SEC/DEF.03

Defense & Aerospace

Supply-chain assurance, ENS Alta hardening, segmentation and air-gapped / OT environments for critical defense and aerospace systems.

ENS AltaSupply-chainAir-gap
SEC/HLT.04

Healthcare & Pharma

Patient data protection, medical device security, clinical systems hardening, GDPR Art.9 special category data.

HIPAAMDRGDPR-9
SEC/PUB.05

Public Sector

Central and regional administration, critical digital services, transparent procurement, ENS CCN-STIC.

ENSCCN-STICeIDAS
SEC/RET.06

Retail & E-commerce

Omnichannel architecture, card data scope reduction, fraud prevention, bot mgmt, account takeover defense.

PCI-DSSBot-MgmtFraud

Same rigor.
Half the bill.
Zero games.

We drafted those proposals for years. We know which line items protect you — and which ones just protect the margin.

Criteria
Slapsec
Big Four
Boutique
Senior-only, same lead end to end
~
Fixed-price proposals
~
Proposal in under 72h
~
Vendor-independent advice
~
Zero subcontracting
~
Typical day rate
€·€
€·€·€·€
€·€·€
Deck-to-code ratio
1:9
9:1
5:5

A result you can defend
to your board.

Offensive engagements stay confidential by design — this is the build we can show in public. One flagship project, real numbers.

Security Automation · Certificate Ops#CASE-SSL

Unattended SSL/TLS certificate rotation

The problem. Certificates expiring without warning caused service outages, incidents and urgent manual work. Hundreds of certs scattered across services — no reliable inventory, no clear owner.

Our solution. A pipeline that discovers, inventories and rotates every certificate via ACME, deploys to the services and verifies the result end to end — with zero manual intervention.

Discover Issue Rotate Deploy Verify
0Outages from expired certs
100%Inventory under control
24/7Unattended renewal

Hard numbers.
No fine print.

Four stats, zero asterisks. If we can't stand behind a number, it doesn't go on the page.

15+
Avg. years senior exp.
200+
Projects delivered
96%
Client satisfaction
0
Subcontracted staff

No smoke. No
deck marathons.
In, solved, out.

How an engagement actually runs — four phases, from first call to handover.

PHASE 01

Honest
diagnosis

45-minute discovery call. We tell you if it's our terrain — straight up.

< 72h
PHASE 02

Scope
& price

Fixed-price when possible. Clear deliverables, clear timeline. No time-and-materials roulette. You know exactly what you're signing.

Fixed
PHASE 03

Senior
execution

Weekly working sessions, direct answers, findings shared as they land. Reports you can actually read, prioritized by business risk — no surprises at the final readout.

Sr. only
PHASE 04

Transfer
& exit

We leave internal capability behind. The goal isn't a 5-year retainer — it's your team owning what they should own. Clean handover.

Handover

The people on your
engagement are senior.

Every engagement is staffed by practitioners who hold the credentials below — and you meet the actual team before you sign, not after.

CISSPCISMCISAOSCPOSEPOSWECRTPCRTOCRTLeMAPTCEHCCSPCCSKISO 27001 LAISO 27001 LIISO 22301 LAGIAC GCIHGIAC GPENGIAC GCFACISO-GSABSATOGAFPMPAZ-500AWS Sec SpecialtyGCP Pro Sec
Microsoft EntraOktaCyberArkSailPointZscalerPalo Alto NetworksCiscoFortinetCrowdStrikeMicrosoft DefenderSentinelOneWizPrisma CloudSealPatharexdataMicrosoft PurviewForcepointAWSAzureGCP
PTESOWASP Top 10OWASP ASVSMITRE ATT&CKNIST CSF 2.0NIST SP 800-53ISO 27001ISO 27701SOC 2PCI-DSS 4.0GDPRHIPAAENSENS AltaCCN-STIC

What CISOs ask
before signing.

The honest answers we give in every first call. If something's missing, tell us and we'll add it.

We came from there. We know exactly how their engagements are built: senior partner on kickoff and closeout, junior consultants doing the actual work, heavy slide output, high day rates. We do the opposite — senior-only, one point of contact, technical deliverables. The methodology is the same (ISO, NIST, MITRE, TIBER-EU); the overhead isn't.
Depends on scope, but our typical ranges — pentest: 2–6 weeks, red team: 6–12 weeks, Zero Trust rollout: 8–16 weeks, GRC / audit readiness: 4–8 weeks (vCISO runs as a monthly retainer), data protection (DLP/DSPM): 4–10 weeks. Day rates land around half the Big Four equivalent for comparable seniority. We quote fixed-price when the scope is clean, T&M when discovery is needed, and we tell you which upfront.
Yes. Standard MNDA / DPA / BAA available on request, and we sign yours. We can scope work under ENS Alta and CCN-STIC requirements, and support clearance and jurisdiction needs on a per-engagement basis — tell us what your project requires.
Four tiers, matched to your maturity and budget: Lite (automated scan, broad and fast, 2-day SLA), Essential (automated + manual, OWASP Top 10), Advanced (deep manual testing, business-logic, exploit PoC, retest + workshop) and Pro (full red team, adversary simulation and social engineering).
That's most of what we do. We embed alongside your team, transfer knowledge, document what we do, and leave when your folks can run it. Extension-of-team is often cheaper than a traditional engagement and produces stickier internal capability.
We tell you. Always. If it's critical, we help contain it within the current engagement at no extra charge. If it's a new workstream, we scope it separately and you decide. We will never sit on a finding to create a follow-on sale — that's a reputation we can't rebuild.

Got a problem
worth solving?

One 45-minute call, straight answers. If we're the right fit, a clear proposal follows fast — if we're not, we'll point you to whoever is.

slapsec@intake — secure