Senior [cybersecurity]. Without the Big Four bill. Just the judgment.

The same people who signed your last audit, without the machinery behind them. We attack to discover, architect to resist, translate it for the regulator, protect the data and automate the operation.

EX · TEAMS FROM Senior talent, without the enterprise overhead. We know that bill from the inside.
DXC·KPMG·Accenture·IBM·Deloitte·PwC

We came from the Big Four.
And from the incident room.

We've run critical banking infrastructure. We've responded to real incidents. We've signed audits that passed audits.

We built SlapSec because enterprise cyber consulting got expensive, slow and noisy. We go straight to the problem, with a senior team and no layers in between.

We don't stop at the report. We fix what we find.

ex-DXCex-KPMGex-Accentureex-IBMex-Deloitte senior team offensive-born

Six clauses we put
in writing.

This is how we work on every engagement. If any of them matters to you, we put it in the contract.

the founders
C · 01The truth, even when it costs us the deal.Always
C · 02Whoever signs the report did the work. We staff it ourselves.In-house
C · 03One named lead, kickoff to closeout.1 : 1
C · 04Proposal usually in 72 hours, fixed price when the scope is clean.~72 h
C · 05Critical findings go to you as soon as we confirm them.Priority
C · 06We transfer capability and leave. Your data stays yours. We wipe our working copies at closeout.Clean exit

Four fronts.
One standard of craft.

From a two-week pentest to a full Zero Trust rollout, with the same team and the same standard. Pick one front or run the whole cycle: each loop shrinks your attack surface.

01 / 04

Red Team
& Threat Intel

Red team and pentesting, both manual and automated, plus continuous external threat monitoring with our Digital Risk Radar. We find what a real attacker would exploit, before they do. PTES, OWASP, MITRE ATT&CK.

  • Web & API Pentest
  • Red Team Ops
  • Infra & AD Pentest
  • Cloud Pentest (AWS/Azure/GCP)
  • OT/ICS Pentest
  • Mobile Pentest
  • Social Engineering
  • Bug Bounty & Retainer
  • Digital Risk Radar
  • Dark Web Monitoring
02 / 04

Zero Trust
Architecture

Design, implement and operate “never trust, always verify” architectures. Identity-first, segmented, verified and measured. Vendor-agnostic, with the market's leading platforms.

  • IAM & PAM
  • Microsegmentation
  • SASE & ZTNA
  • EDR / XDR
  • Cloud Posture (CSPM/CIEM)
  • Design & Governance
03 / 04

GRC &
Compliance

Every technical finding translated into regulatory frameworks (ENS, ISO 27001, PCI DSS, GDPR) and into concrete business decisions. Governance and security direction as a service, without unnecessary paperwork.

  • Compliance mapping (ENS · ISO 27001)
  • PCI DSS & GDPR
  • vCISO retainer
  • Governance & roadmap
  • Risk-to-business translation
  • Audit readiness
04 / 04

Data &
Automation

Protect the data wherever it lives, with DLP, IRM and DSPM on SealPath, arexdata and Microsoft Purview. Then automate the operation: AI-assisted triage, continuous hardening, unattended certificate rotation.

  • DLP
  • IRM (SealPath)
  • DSPM (arexdata)
  • Microsoft Purview
  • AI-assisted triage
  • SOAR orchestration
  • Continuous hardening (CIS)
  • Certificate automation

Cybersecurity for SMBs.
Enterprise craft, right-sized.

Attacks are automated and company size is no protection. You don't need a security department to be well defended: you need senior judgment, a few hours a month.

Challenge 01

Your big customers demand it

Vendor security questionnaires, ISO 27001, supply-chain clauses… more and more contracts hinge on proving your security. We get you through them without stalling your business.

Challenge 02

No security team? You don't need one.

A senior vCISO a few hours a month: clear priorities, sound decisions and someone to call when something looks wrong. No impossible hires, no CISO on the payroll.

Challenge 03

SMB budget, senior work

Tiered pentesting at a fixed price, from a Lite scan to deep manual testing. You know what you pay, what you get and when. No surprises, no fine print.

Challenge 04

Ransomware doesn't check your size

If you're exposed, you get found. We watch your external footprint (domains, leaked credentials, dark web) and close what matters most first.

Book a 45-min call → Straight answers · fixed prices · no strings

Regulated. Complex.
No room for error.

We work where cyber failures are expensive, visible and regulated. Every engagement maps to the threat model and compliance obligations of your sector.

SEC/FIN.01

Financial Services

Retail, commercial and investment banking, insurance, fintech. DORA, EBA ICT, PSD2, PCI-DSS scope reduction.

DORAEBAPCI-DSS
SEC/ENE.02

Energy & Utilities

Generation, distribution, O&G. OT/IT convergence, NIS2 essential entity compliance, SCADA hardening.

NIS2IEC-62443OT
SEC/DEF.03

Defense & Aerospace

Supply-chain assurance, ENS Alta hardening, segmentation and air-gapped / OT environments for critical defense and aerospace systems.

ENS AltaSupply-chainAir-gap
SEC/HLT.04

Healthcare & Pharma

Patient data protection, medical device security, clinical systems hardening, GDPR Art. 9 special category data.

HIPAAMDRGDPR-9
SEC/PUB.05

Public Sector

Central and regional administration, critical digital services, transparent procurement, ENS CCN-STIC.

ENSCCN-STICeIDAS
SEC/RET.06

Retail & E-commerce

Omnichannel architecture, card data scope reduction, fraud prevention, bot management, account takeover defense.

PCI-DSSBot-MgmtFraud

Same rigor.
Less overhead.
Clear terms.

We drafted those proposals for years. We know which line items you actually need and which ones you can cut.

Criteria
SlapSec
Big Four
Boutique
Senior-only, same lead end to end
Team-based
Varies
Fixed-price proposals
Varies
Common
Proposal in days, not weeks
Longer cycle
Varies
Vendor-independent advice
Alliance-led
Common
Zero subcontracting
Varies
Varies
Typical day rate
€·€
Typically higher
Varies
Main deliverable
Working fixes
Report and slides
Report

A result you can defend
to your board.

Offensive engagements stay confidential by design. This is the build we can show in public: one project, real numbers.

Security Automation · Certificate Ops#CASE-SSL

Unattended SSL/TLS certificate rotation

The problem. Certificates expiring without warning caused service outages, incidents and urgent manual work. Hundreds of certs scattered across services, with no reliable inventory and no clear owner.

Our solution. A pipeline that discovers, inventories and rotates every certificate via ACME, deploys it to the services and verifies the result end to end. No manual intervention.

Discover Issue Rotate Deploy Verify
0Outages from expired certs
100%Inventory under control
100%Renewal automated

Hard numbers.
No fine print.

We only publish figures we can back up.

15+
Avg. years senior exp.
200+
Projects across our careers
2
Founders, ex-Big Four
0
Subcontracted staff

Four phases.
Clear scope.
In, solved, out.

How an engagement runs, from the first call to the handover.

PHASE 01

Honest
diagnosis

45-minute discovery call. If it isn't our terrain, we say so.

~72h
PHASE 02

Scope
& price

Fixed-price when possible. Clear deliverables, clear timeline. No open-ended time-and-materials billing. You know exactly what you're signing.

Fixed
PHASE 03

Senior
execution

Weekly working sessions, direct answers, findings shared as they land. Reports meant to be read, prioritized by business risk. No surprises at the final readout.

Sr. only
PHASE 04

Transfer
& exit

We leave internal capability behind. The goal isn't a 5-year retainer. It's your team owning what they should own. Clean handover.

Handover

The people on your
engagement are senior.

Every engagement is staffed in-house. The certifications below are the ones we hold between us. You meet the team that will do the work before you sign, not after.

CISSPCISMCISAOSCPOSEPOSWECRTPCRTOCRTLeMAPTCEHCCSPCCSKISO 27001 LAISO 27001 LIISO 22301 LAGIAC GCIHGIAC GPENGIAC GCFACISO-GSABSATOGAFPMPAZ-500AWS Sec SpecialtyGCP Pro Sec
Microsoft EntraOktaCyberArkSailPointZscalerPalo Alto NetworksCiscoFortinetCrowdStrikeMicrosoft DefenderSentinelOneWizPrisma CloudSealPatharexdataMicrosoft PurviewForcepointAWSAzureGCP
PTESOWASP Top 10OWASP ASVSMITRE ATT&CKNIST CSF 2.0NIST SP 800-53ISO 27001ISO 27701SOC 2PCI-DSS 4.0GDPRHIPAAENSENS AltaCCN-STIC

What CISOs ask
before signing.

The answers we give in every first call. If something's missing, tell us and we'll add it.

We came from there. We saw first-hand how large engagements get built: layers between the partner and the work, a lot of the output going into slides, day rates to match. We do the opposite: senior-only, one point of contact, technical deliverables. The methodology is the same (ISO, NIST, MITRE, TIBER-EU); the overhead isn't.
It depends on scope. Typical ranges are 2–6 weeks for a pentest, 6–12 weeks for a red team, 8–16 weeks for a Zero Trust rollout, 4–8 weeks for GRC / audit readiness (vCISO runs as a monthly retainer) and 4–10 weeks for data protection (DLP/DSPM). Our day rates are roughly half what we used to quote at the Big Four for comparable seniority. We quote fixed-price when the scope is clean, T&M when discovery is needed, and we tell you which upfront.
Yes. We work under MNDA / DPA / BAA as standard, and we are happy to sign yours once we have reviewed it. We can scope work under ENS Alta and CCN-STIC requirements, and support clearance and jurisdiction needs on a per-engagement basis. Tell us what your project requires.
Four tiers, matched to your maturity and budget: Lite (automated scan, broad and fast, results usually in a couple of days), Essential (automated + manual, OWASP Top 10), Advanced (deep manual testing, business-logic, exploit PoC, retest + workshop) and Pro (full red team, adversary simulation and social engineering).
That's most of what we do. We embed alongside your team, transfer knowledge, document the work, and hand over when they can run it without us. Extension-of-team is often cheaper than a traditional engagement and leaves the capability in-house.
We tell you. Always. If it's critical, we help you contain it straight away. If it's a new workstream, we scope it separately and you decide. We never hold a finding back to create a follow-on sale.

Got a problem
worth solving?

One 45-minute call, straight answers. If we're the right fit, a clear proposal follows fast. If we're not, we'll point you to whoever is.

New engagement