Senior [cybersecurity]. Without the Big Four bill. Just the judgment.
We came from the Big Four.
And from the incident room.
We've run critical banking infrastructure. We've responded to real incidents. We've signed audits that passed audits.
We built SlapSec because enterprise cyber consulting got expensive, slow and noisy. We go straight to the problem, with a senior team and no layers in between.
We don't stop at the report. We fix what we find.
Six clauses we put
in writing.
This is how we work on every engagement. If any of them matters to you, we put it in the contract.
the foundersFour fronts.
One standard of craft.
From a two-week pentest to a full Zero Trust rollout, with the same team and the same standard. Pick one front or run the whole cycle: each loop shrinks your attack surface.
Red Team
& Threat Intel
Red team and pentesting, both manual and automated, plus continuous external threat monitoring with our Digital Risk Radar. We find what a real attacker would exploit, before they do. PTES, OWASP, MITRE ATT&CK.
- Web & API Pentest
- Red Team Ops
- Infra & AD Pentest
- Cloud Pentest (AWS/Azure/GCP)
- OT/ICS Pentest
- Mobile Pentest
- Social Engineering
- Bug Bounty & Retainer
- Digital Risk Radar
- Dark Web Monitoring
Zero Trust
Architecture
Design, implement and operate “never trust, always verify” architectures. Identity-first, segmented, verified and measured. Vendor-agnostic, with the market's leading platforms.
- IAM & PAM
- Microsegmentation
- SASE & ZTNA
- EDR / XDR
- Cloud Posture (CSPM/CIEM)
- Design & Governance
GRC &
Compliance
Every technical finding translated into regulatory frameworks (ENS, ISO 27001, PCI DSS, GDPR) and into concrete business decisions. Governance and security direction as a service, without unnecessary paperwork.
- Compliance mapping (ENS · ISO 27001)
- PCI DSS & GDPR
- vCISO retainer
- Governance & roadmap
- Risk-to-business translation
- Audit readiness
Data &
Automation
Protect the data wherever it lives, with DLP, IRM and DSPM on SealPath, arexdata and Microsoft Purview. Then automate the operation: AI-assisted triage, continuous hardening, unattended certificate rotation.
- DLP
- IRM (SealPath)
- DSPM (arexdata)
- Microsoft Purview
- AI-assisted triage
- SOAR orchestration
- Continuous hardening (CIS)
- Certificate automation
Cybersecurity for SMBs.
Enterprise craft, right-sized.
Attacks are automated and company size is no protection. You don't need a security department to be well defended: you need senior judgment, a few hours a month.
Your big customers demand it
Vendor security questionnaires, ISO 27001, supply-chain clauses… more and more contracts hinge on proving your security. We get you through them without stalling your business.
No security team? You don't need one.
A senior vCISO a few hours a month: clear priorities, sound decisions and someone to call when something looks wrong. No impossible hires, no CISO on the payroll.
SMB budget, senior work
Tiered pentesting at a fixed price, from a Lite scan to deep manual testing. You know what you pay, what you get and when. No surprises, no fine print.
Ransomware doesn't check your size
If you're exposed, you get found. We watch your external footprint (domains, leaked credentials, dark web) and close what matters most first.
Regulated. Complex.
No room for error.
We work where cyber failures are expensive, visible and regulated. Every engagement maps to the threat model and compliance obligations of your sector.
Financial Services
Retail, commercial and investment banking, insurance, fintech. DORA, EBA ICT, PSD2, PCI-DSS scope reduction.
Energy & Utilities
Generation, distribution, O&G. OT/IT convergence, NIS2 essential entity compliance, SCADA hardening.
Defense & Aerospace
Supply-chain assurance, ENS Alta hardening, segmentation and air-gapped / OT environments for critical defense and aerospace systems.
Healthcare & Pharma
Patient data protection, medical device security, clinical systems hardening, GDPR Art. 9 special category data.
Public Sector
Central and regional administration, critical digital services, transparent procurement, ENS CCN-STIC.
Retail & E-commerce
Omnichannel architecture, card data scope reduction, fraud prevention, bot management, account takeover defense.
Same rigor.
Less overhead.
Clear terms.
We drafted those proposals for years. We know which line items you actually need and which ones you can cut.
A result you can defend
to your board.
Offensive engagements stay confidential by design. This is the build we can show in public: one project, real numbers.
Unattended SSL/TLS certificate rotation
The problem. Certificates expiring without warning caused service outages, incidents and urgent manual work. Hundreds of certs scattered across services, with no reliable inventory and no clear owner.
Our solution. A pipeline that discovers, inventories and rotates every certificate via ACME, deploys it to the services and verifies the result end to end. No manual intervention.
Hard numbers.
No fine print.
We only publish figures we can back up.
Four phases.
Clear scope.
In, solved, out.
How an engagement runs, from the first call to the handover.
Honest
diagnosis
45-minute discovery call. If it isn't our terrain, we say so.
~72hScope
& price
Fixed-price when possible. Clear deliverables, clear timeline. No open-ended time-and-materials billing. You know exactly what you're signing.
FixedSenior
execution
Weekly working sessions, direct answers, findings shared as they land. Reports meant to be read, prioritized by business risk. No surprises at the final readout.
Sr. onlyTransfer
& exit
We leave internal capability behind. The goal isn't a 5-year retainer. It's your team owning what they should own. Clean handover.
HandoverThe people on your
engagement are senior.
Every engagement is staffed in-house. The certifications below are the ones we hold between us. You meet the team that will do the work before you sign, not after.
What CISOs ask
before signing.
The answers we give in every first call. If something's missing, tell us and we'll add it.
Got a problem
worth solving?
One 45-minute call, straight answers. If we're the right fit, a clear proposal follows fast. If we're not, we'll point you to whoever is.