Opens in a new tab
Free AI visibility audit (regularly €1,160) – 75 of 100 places left 75 free AI audits left Book for free

Not sure whether NIS2 and the AI Act apply to you?
We will find out and get you ready

We approach cybersecurity practically. We map where the company is vulnerable, compare the current state against the requirements of NIS2 and the AI Act, set rules for both people and AI tools, and train your team. No scaremongering and no investment in technology you do not need.
  • We examine your infrastructure, processes, access rights and suppliers and work out where the biggest risk lies
  • We compare the current state against NIS2 and the AI Act and give you a list of specific steps
  • We set rules for working with data and AI tools and train your people

A no-obligation cyber readiness audit

Tell us which systems you use and which sector you operate in. Within 5 business days you will receive an overview of the weak points, the impact of NIS2 and the AI Act on your company and three priorities to start with.
No obligation. Written output within 5 business days. Prefer the phone: +420 555 333 158

Why deal with it right now

The new cybersecurity act transfers NIS2 obligations onto thousands of Czech companies that are not yet dealing with them. The AI Act concerns anyone whose company uses ChatGPT, Copilot or Gemini. And attackers are not waiting for you to get ready.

The obligations will hit smaller companies too

NIS2 does not only concern energy and banking. Through supply chains it reaches manufacturing, transport, IT services and healthcare as well. Many companies only find out from a questionnaire sent by a customer.

An attack today starts with a person

Phishing, fraudulent invoices and voice deepfakes are now produced by AI and look convincing. Without trained people, not even the best firewall will help.

AI tools carry company data away

Employees paste contracts, code and customer data into public chatbots. AI Act additionally requires informed staff and an overview of the systems in use.
0
years of experience with IT and data
0
years of experience training people
0
areas we examine in the audit
0 days
for the written output and quote

Does this sound familiar?

This is what we hear most often at first meetings.

You do not know whether NIS2 affects you

A customer asks you for a security questionnaire and you do not know what you already have to comply with, what is just their wish and what is unnecessary.

Security is held in one person's head

You have no list of systems, access rights or suppliers. When the external administrator is unavailable, nobody knows what runs where and who holds the keys.

You have backups, but nobody has tried restoring them

A backup you have never tested is not a backup. You find that out at the worst possible moment.

People use AI however they are used to

Nobody has said what may and may not be put into ChatGPT. There are no internal rules, no staff briefing and no record of the tools in use.

They trust us

Continental  ·  Hyundai Motor  ·  Groupon  ·  Union of Towns and Municipalities of the Czech Republic  ·  Technology Agency of the Czech Republic  ·  Datasys  ·  Spokar  ·  Slovak Athletics Federation  ·  Energy Centre of the Ústí Region  ·  VŠÚO Holovousy

and dozens of other Mediatoring.com clients

What exactly we will do for you

The most common tasks companies approach us with. We choose according to risk and impact, not according to a supplier's price list.
Task What we will do for you Benefit
Cybersecurity audit We examine the infrastructure, configurations, access rights and processes You know where the real risks are and what to address first
NIS2 readiness We assess the scope of your obligations, missing documentation and risk management You have a plan for meeting the obligations and evidencing them
AI adoption in line with the AI Act A register of AI tools, internal rules, staff briefing and AI literacy You use AI without legal risk and without data leaks
Cyber Resilience Act readiness We determine whether your product falls under the CRA and go through the requirements and CE marking You can still sell hardware and software in the EU after December 2027
Vulnerability reporting under the CRA We set up reporting of exploited vulnerabilities and incidents within 24 hours You meet the deadlines that have applied since 11 September 2026
SBOM and product support We compile a component inventory and a security update plan You know what runs inside the product and how long you will patch it
Rules for working with AI tools We set out what may be entered into ChatGPT, Copilot or Gemini Company know-how stays inside the company
Staff training and phishing tests We train the team and test their reactions to fraudulent e-mails People spot an attack before they click on anything
Backups and business recovery We check the backups, set up and test a recovery plan You know how long recovery takes and what from
Suppliers and access management We go through permissions, accounts and third-party access Supply chain risk is under control
Incident response We prepare the procedure, roles, contacts and incident reporting Nobody has to improvise during an incident
This overview is illustrative. The specific scope always follows from the sector, the size of the company and the result of the initial audit.

4 steps to a resilient company

We have fine-tuned this process on audits and digitalisation projects. You know in advance what is produced at each stage and what we need from you.

Initial audit and scope of obligations

We go through systems, processes, access rights and suppliers. This includes an assessment of what NIS2 and the AI Act.

Priorities and action plan

We rank the risks by impact and by the cost of removing them. You get a plan that can be approved and budgeted for.

Deploying measures and rules

We set up the technical measures, documentation and rules for working with AI, and train your people. We build on what you already have.

Verification and maintenance

We test restoring from backups, repeat the training and keep an eye on changes in legislation. Security is not a one-off installation.

How the cooperation works

No commitments at the start. First we find out whether there is any point in changing anything at all.
15 minutes

Introductory call

We discuss which sector you operate in, which systems you use and what your customers or the authorities require from you.
within 5 days

Initial audit and output

We examine the systems and processes. You receive a written overview of the weak points, the impact of NIS2 and the AI Act, and three priorities. With no obligation.
within 30 days

First measures in operation

We deploy the measures with the greatest impact: access rights, backups, rules for AI and staff training.
ongoing

Supervision and development

We test recovery, repeat the training and respond to new threats and to changes in legislation.

How much it costs

The price is based on the size of the company, the number of systems and the scope of the obligations. The initial consultation is free of charge and we agree the scope before work starts.

Initial audit and NIS2 assessment

An examination of the infrastructure, processes and suppliers plus a written output. One-off, based on the number of systems and locations.

Deploying measures and rules

Documentation, configuration, backups, rules for AI and team training. We price by stages that can be approved separately.

Ongoing supervision and training

A monthly flat fee for supervision, backup tests, phishing tests and updating the rules in line with new legislation.

How NIS2, the AI Act and safe use of artificial intelligence fit together

The new cybersecurity act and the European NIS2 directive push companies to have their systems documented, their risks managed, their backups under control and clear roles during an incident. Through supply chains, the obligations are passed on to companies that do not fall within the scope themselves. The AI Act adds informed staff, a register of the tools in use and responsibility for what happens to the data. In practice it comes down to one and the same thing: knowing where your data is, who has access to it and what may be done with it. That is why we deal with security and AI adoption together. Where data must not leave the company, we deploy models on your own server. Where the cloud is sufficient, we set the rules and brief your people. We choose in a technology-neutral way based on what you need, not on what the supplier has in stock.
I want a free consultationTake a look at our projects

Frequently asked questions and answers about cybersecurity

The new rules affect a much wider range of sectors than before – from manufacturing and transport to the food industry. If you have more than 50 employees or a turnover of over EUR 10 million and you operate in a regulated sector, you probably fall under the act. We will help you determine this precisely.

In addition to the risk of fines, you run the danger of deploying systems that will later be prohibited or will require costly modifications. Setting the rules for AI correctly right at the start will save you costs in the future.

Not at all. We look at the business as a whole. We assess the digital maturity of your production processes, your logistics and the way you work with people. The aim is to find the places where technology genuinely earns money or saves time.

The new legislation (and the Czech Cybersecurity Act) targets top management directly. Responsibility can no longer be delegated solely to the IT department or an external administrator. Statutory bodies have a duty to educate themselves in the field of cybersecurity and to oversee the implementation of measures. In the event of gross negligence, senior staff may even face a temporary ban on holding office.

From the point of view of security and the AI Act this is highly risky. Free versions (e.g. standard ChatGPT without an Enterprise licence) may use the data entered to train the model further. If your employee enters sensitive data, trade secrets or clients’ personal data there, it becomes part of the public cloud. We will help you set up secure systems and procedures that lock your know-how inside the company.

Not at all. NIS2 is not about buying the most expensive technology but about setting up processes and sensible risk management. It is often enough to configure existing systems correctly, introduce two-factor authentication (MFA), manage access rights better and train people regularly. Our audit identifies what genuinely needs to be adjusted and what is working well.

Directly. The more digitally advanced a company is (using the cloud, IoT in production, automation), the larger the surface it offers for a potential attack. A digital maturity audit will show you not only how to innovate but also how to build those innovations on secure foundations (known as security-by-design). Security must not be “stuck on” at the end; it must be part of every new digital process.

Under NIS2 you are also responsible for how well your key suppliers are secured. If a hacker attacks your IT services provider or your accounting software, they can get through to you. We will help you set up control mechanisms and contractual conditions so that your partners are not the weakest link in your own security.

The AI Act is an EU regulation that regulates the development and use of AI. Although some obligations are being phased in gradually, it is essential to have the rules in place now (AI governance). If you are now deploying new systems without regard to the AI Act, you risk having to redesign them at great cost or switch them off in a year’s time.

This is one of the most common concerns. We deal with it by setting up processes, using corporate licences or using API interfaces with local models, where your data will not be used for further training. Our services also include setting up an internal policy for the safe use of AI.

The AI Act introduces an obligation of “AI literacy” for all organisations that use AI. If you now introduce processes without regard to this legislation, you run the risk that your solution will retrospectively be declared non-compliant. We will help you set up an ethical and legal framework right at the start, which is far cheaper than correcting mistakes later and facing the threat of heavy penalties.

Not from the text any more. Generative AI writes without errors, can imitate your jargon and a colleague’s signature and can even manage a voice recording. So rely on process, not on impressions: confirming changes to bank details through a second channel, two-factor login and the rule that nobody sends money or passwords on the basis of an e-mail or a phone call. That is why we add examples of AI-generated attacks to our training.

A list of approved tools, a clear definition of the data that must not be entered into them (personal data, contracts, source code, know-how), a rule on human checking of outputs and a responsible person people can turn to. Alongside that, instruction of employees and a record of who completed the training and when. We write the guideline on one or two pages so that people actually use it.

Two to three weeks for a smaller company, longer for a manufacturer with several sites. We need access to an overview of systems, suppliers and access rights, plus a few hours of your IT team’s time. The output is a written summary of weak points, the impact of NIS2 and the AI Act, and priorities according to impact and cost. It also covers which AI tools are already being used in the company.

At least twice a year and always after a major change to systems. What is tested is not just that a backup exists but that you can restore operations from it within a time the company can survive economically. The test should be recorded, with who carried it out and how long the restoration took. We take the same approach to the data and models on which the company’s AI tools run.

We recommend it even if the legislation did not require it. Without a list you do not know where company data is going and what an external service is storing about your company. The record is usually a simple table: tool, purpose, who uses it, what data goes into it and who is responsible for it. It helps with security questionnaires from customers and with meeting AI Act obligations.

Yes, if the data must not leave the company. We can deploy an open-source model on your server or in a private cloud and fine-tune it on your documents. The data then stays with you and what you mainly have to deal with is access rights and backups. For most companies, though, it is quicker to start with a cloud service with the rules set up, and to move to local operation only when there is a measurable reason.

Disconnect the affected systems, but do not switch them off (because of the evidence), convene the pre-assigned roles, secure backups off the network and start writing a timeline. Then deal with reporting and communication with partners. This cannot be improvised while everything is happening, which is why we prepare the procedure, contacts and roles in advance and rehearse them. During an incident we also disconnect AI tools until you know what had access to them.

Yes. Smaller models, particularly in computer vision and anomaly detection, run on an edge device right at the production line. The advantages are low latency, operation independent of the network and the fact that data does not leave the plant. Only results and metrics are then sent to head office, not raw images.

The agent is given only the permissions it needs for the task and accesses data through an interface with a limited scope. Every step is logged, so it can be traced afterwards what the agent read and what it wrote. For sensitive steps, approval remains with a human. We set this up together with your IT team and reflect it in your internal guideline.

Related services

AI governance

Rules, risks and AI Act compliance for the AI tools your people use.

Website management

The website runs, gets updated, backed up and monitored – with a fast response when something happens.

AI implementation and training

We teach your team to use AI so that something actually changes in the company.

Let's discuss your readiness for NIS2 and the AI Act

Tell us what you use in your company and what your customers or the authorities require from you. We will tell you whether an audit makes sense and what it would cover.
We will get back to you within one business day. Prefer the phone: +420 555 333 158