Not sure whether NIS2 and the AI Act apply to you?
We will find out and get you ready

We approach cybersecurity practically. We map where the company is vulnerable, compare the current state against the requirements of NIS2 and the AI Act, set rules for both people and AI tools, and train your team. No scaremongering and no investment in technology you do not need.
  • We examine your infrastructure, processes, access rights and suppliers and work out where the biggest risk lies
  • We compare the current state against NIS2 and the AI Act and give you a list of specific steps
  • We set rules for working with data and AI tools and train your people

A no-obligation cyber readiness audit

Tell us which systems you use and which sector you operate in. Within 5 business days you will receive an overview of the weak points, the impact of NIS2 and the AI Act on your company and three priorities to start with.
No obligation. Written output within 5 business days. Prefer the phone: +420 555 333 158

Why deal with it right now

The new cybersecurity act transfers NIS2 obligations onto thousands of Czech companies that are not yet dealing with them. The AI Act concerns anyone whose company uses ChatGPT, Copilot or Gemini. And attackers are not waiting for you to get ready.

The obligations will hit smaller companies too

NIS2 does not only concern energy and banking. Through supply chains it reaches manufacturing, transport, IT services and healthcare as well. Many companies only find out from a questionnaire sent by a customer.

An attack today starts with a person

Phishing, fraudulent invoices and voice deepfakes are now produced by AI and look convincing. Without trained people, not even the best firewall will help.

AI tools carry company data away

Employees paste contracts, code and customer data into public chatbots. AI Act additionally requires informed staff and an overview of the systems in use.
0
years of experience with IT and data
0
years of experience training people
0
areas we examine in the audit
0 days
for the written output and quote

Does this sound familiar?

This is what we hear most often at first meetings.

You do not know whether NIS2 affects you

A customer asks you for a security questionnaire and you do not know what you already have to comply with, what is just their wish and what is unnecessary.

Security is held in one person's head

You have no list of systems, access rights or suppliers. When the external administrator is unavailable, nobody knows what runs where and who holds the keys.

You have backups, but nobody has tried restoring them

A backup you have never tested is not a backup. You find that out at the worst possible moment.

People use AI however they are used to

Nobody has said what may and may not be put into ChatGPT. There are no internal rules, no staff briefing and no record of the tools in use.

They trust us

Continental  ·  Hyundai Motor  ·  Groupon  ·  Union of Towns and Municipalities of the Czech Republic  ·  Technology Agency of the Czech Republic  ·  Datasys  ·  Spokar  ·  Slovak Athletics Federation  ·  Energy Centre of the Ústí Region  ·  VŠÚO Holovousy

and dozens of other Mediatoring.com clients

What exactly we will do for you

The most common tasks companies approach us with. We choose according to risk and impact, not according to a supplier's price list.
Task What we will do for you Benefit
Cybersecurity audit We examine the infrastructure, configurations, access rights and processes You know where the real risks are and what to address first
NIS2 readiness We assess the scope of your obligations, missing documentation and risk management You have a plan for meeting the obligations and evidencing them
AI adoption in line with the AI Act A register of AI tools, internal rules, staff briefing and AI literacy You use AI without legal risk and without data leaks
Cyber Resilience Act readiness We determine whether your product falls under the CRA and go through the requirements and CE marking You can still sell hardware and software in the EU after December 2027
Vulnerability reporting under the CRA We set up reporting of exploited vulnerabilities and incidents within 24 hours You meet the deadlines that have applied since 11 September 2026
SBOM and product support We compile a component inventory and a security update plan You know what runs inside the product and how long you will patch it
Rules for working with AI tools We set out what may be entered into ChatGPT, Copilot or Gemini Company know-how stays inside the company
Staff training and phishing tests We train the team and test their reactions to fraudulent e-mails People spot an attack before they click on anything
Backups and business recovery We check the backups, set up and test a recovery plan You know how long recovery takes and what from
Suppliers and access management We go through permissions, accounts and third-party access Supply chain risk is under control
Incident response We prepare the procedure, roles, contacts and incident reporting Nobody has to improvise during an incident
This overview is illustrative. The specific scope always follows from the sector, the size of the company and the result of the initial audit.

4 steps to a resilient company

We have fine-tuned this process on audits and digitalisation projects. You know in advance what is produced at each stage and what we need from you.

Initial audit and scope of obligations

We go through systems, processes, access rights and suppliers. This includes an assessment of what NIS2 and the AI Act.

Priorities and action plan

We rank the risks by impact and by the cost of removing them. You get a plan that can be approved and budgeted for.

Deploying measures and rules

We set up the technical measures, documentation and rules for working with AI, and train your people. We build on what you already have.

Verification and maintenance

We test restoring from backups, repeat the training and keep an eye on changes in legislation. Security is not a one-off installation.

How the cooperation works

No commitments at the start. First we find out whether there is any point in changing anything at all.
15 minutes

Introductory call

We discuss which sector you operate in, which systems you use and what your customers or the authorities require from you.
within 5 days

Initial audit and output

We examine the systems and processes. You receive a written overview of the weak points, the impact of NIS2 and the AI Act, and three priorities. With no obligation.
within 30 days

First measures in operation

We deploy the measures with the greatest impact: access rights, backups, rules for AI and staff training.
ongoing

Supervision and development

We test recovery, repeat the training and respond to new threats and to changes in legislation.

How much it costs

The price is based on the size of the company, the number of systems and the scope of the obligations. The initial consultation is free of charge and we agree the scope before work starts.

Initial audit and NIS2 assessment

An examination of the infrastructure, processes and suppliers plus a written output. One-off, based on the number of systems and locations.

Deploying measures and rules

Documentation, configuration, backups, rules for AI and team training. We price by stages that can be approved separately.

Ongoing supervision and training

A monthly flat fee for supervision, backup tests, phishing tests and updating the rules in line with new legislation.

How NIS2, the AI Act and safe use of artificial intelligence fit together

The new cybersecurity act and the European NIS2 directive push companies to have their systems documented, their risks managed, their backups under control and clear roles during an incident. Through supply chains, the obligations are passed on to companies that do not fall within the scope themselves. The AI Act adds informed staff, a register of the tools in use and responsibility for what happens to the data. In practice it comes down to one and the same thing: knowing where your data is, who has access to it and what may be done with it. That is why we deal with security and AI adoption together. Where data must not leave the company, we deploy models on your own server. Where the cloud is sufficient, we set the rules and brief your people. We choose in a technology-neutral way based on what you need, not on what the supplier has in stock.
I want a free consultationTake a look at our projects

Frequently asked questions and answers about cybersecurity

Nová pravidla dopadají na mnohem širší okruh odvětví než dříve – od výroby a dopravy až po potravinářství. Pokud máte více než 50 zaměstnanců nebo obrat nad 10 mil. EUR a působíte v regulovaném sektoru, pravděpodobně pod zákon spadáte. Pomůžeme vám to přesně určit.

Kromě rizika pokut se vystavujete nebezpečí, že nasadíte systémy, které budou později zakázané nebo budou vyžadovat nákladné úpravy. Správné nastavení pravidel pro AI hned na začátku vám ušetří náklady v budoucnu.

Vůbec ne. Díváme se na podnik jako na celek. Hodnotíme digitální zralost vašich výrobních procesů, logistiky i práce s lidmi. Cílem je najít místa, kde technologie skutečně vydělají peníze nebo ušetří čas.

Nová legislativa (a český zákon o kybernetické bezpečnosti) míří přímo na vrcholové vedení. Odpovědnost už nelze delegovat pouze na IT oddělení nebo externího správce. Statutární orgány mají povinnost se v oblasti kybernetické bezpečnosti vzdělávat a dohlížet na implementaci opatření. V případě hrubého zanedbání hrozí vedoucím pracovníkům i dočasný zákaz výkonu funkce.

Z pohledu bezpečnosti a AI Actu je to vysoce rizikové. Bezplatné verze (např. standardní ChatGPT bez Enterprise licence) mohou využívat vložená data k dalšímu trénování modelu. Pokud tam váš zaměstnanec vloží citlivá data, obchodní tajemství nebo osobní údaje klientů, stávají se součástí veřejného cloudu. Pomůžeme vám nastavit bezpečné systémy a postupy, které vaše know-how uzamkne uvnitř firmy.

Ně netně. NIS2 není o nákupu nejdražších technologií, ale o nastavení procesů a rozumném řízení rizik. Často stačí správně nakonfigurovat stávající systémy, zavést dvoufázové ověřování (MFA), lépe řídit přístupová práva a pravidelně školit lidi. Náš audit identifikuje, co je skutečně nutné upravit a co funguje dobře.

Přímo. Čím je firma digitálně vyspělejší (využívá cloud, IoT ve výrobě, automatizaci), tím větší plochu pro potenciální útok nabízí. Digitální audit zralosti vám neukáže jen to, jak inovovat, ale také jak tyto inovace postavit na bezpečných základech (tzv. security-by-design). Bezpečnost nesmí být „přilepena“ nakonec, musí být součástí každého nového digitálního procesu.

Podle NIS2 odpovídáte i za to, jak jsou zabezpečeni vaši klíčoví dodavatelé. Pokud hacker napadne vašeho dodavatele IT služeb nebo účetního softwaru, může se skrze ně dostat k vám. Pomůžeme vám nastavit kontrolní mechanismy a smluvní podmínky tak, aby vaši partneři nebyli nejslabším článkem vaší vlastní bezpečnosti.

AI Act je nařízení EU, které reguluje vývoj a používání AI. I když některé povinnosti nabíhají postupně, je klíčové mít už nyní nastavená pravidla (AI Governance). Pokud nyní nasazujete nové systémy bez ohledu na AI Act, riskujete, že je za rok budete muset nákladně předělávat nebo vypnout.

Toto je jedna z nejčastějších obav. Řešíme to nastavením procesů, firemními licencemi nebo využitím API rozhraní s lokálními modely, kde vaše data nebudou použita k dalšímu trénování. Součástí našich služeb je i nastavení interní politiky bezpečného používání AI.

AI Act zavádí povinnost „AI gramotnosti“ pro všechny organizace, které AI používají. Pokud nyní zavedete procesy bez ohledu na tuto legislativu, vystavujete se riziku, že vaše řešení bude zpětně prohlášeno za nevyhovující. Pomůžeme vám nastavit etický a právní rámec hned na začátku, což je mnohem levnější než pozdější náprava chyb a hrozba vysokých sankcí.

Podle textu už ne. Generativní AI píše bez chyb, umí váš žargon i podpis kolegy a zvládne i hlasovou nahrávku. Spolehněte se proto na proces, ne na dojem: potvrzování změn bankovních údajů druhým kanálem, dvoufaktorové přihlášení a pravidlo, že nikdo neposílá peníze ani hesla na základě e-mailu nebo telefonátu. Do školení proto přidáváme ukázky útoků vyrobených AI.

Seznam schválených nástrojů, jasné vymezení dat, která se do nich nesmí vkládat (osobní údaje, smlouvy, zdrojový kód, know-how), pravidlo pro kontrolu výstupů člověkem a odpovědnou osobu, na kterou se lidé obrátí. K tomu poučení zaměstnanců a evidence, kdo a kdy školení prošel. Směrnici píšeme na jednu až dvě stránky, aby ji lidé opravdu použili.

U menší firmy dva až tři týdny, u výroby s více lokalitami déle. Potřebujeme přístup k přehledu systémů, dodavatelů a přístupových práv a pár hodin času vašeho IT. Výstupem je písemný přehled slabých míst, dopad NIS2 a AI Actu a priority podle dopadu a nákladů. Součástí je i to, jaké AI nástroje se ve firmě už používají.

Minimálně dvakrát ročně a vždy po větší změně systémů. Netestuje se jen to, že záloha existuje, ale že z ní obnovíte provoz v čase, který firma ekonomicky ustojí. Test má mít zápis, kdo ho dělal a jak dlouho obnova trvala. Stejně přistupujeme k datům a modelům, na kterých běží AI nástroje ve firmě.

Doporučujeme to, i kdyby to legislativa nežádala. Bez seznamu nevíte, kam odcházejí firemní data a co si o vaší firmě ukládá cizí služba. Evidence bývá jednoduchá tabulka: nástroj, účel, kdo ho používá, jaká data do něj jdou a kdo za něj odpovídá. Pomáhá při bezpečnostních dotaznících od odběratelů i při plnění povinností AI Actu.

Ano, pokud data nesmí opustit firmu. Open-source model umíme nasadit na váš server nebo do privátního cloudu a dotrénovat na vašich dokumentech. Data pak zůstávají u vás a řešíte hlavně přístupová práva a zálohy. Pro většinu firem je ale rychlejší začít cloudovou službou s nastavenými pravidly a k lokálnímu provozu jít, až když má měřitelný důvod.

Odpojit zasažené systémy, nevypínat je (kvůli důkazům), svolat předem určené role, zajistit zálohy mimo síť a začít psát časovou osu. Pak řešit hlášení a komunikaci s partnery. Tohle se nedá vymýšlet za provozu, proto postup, kontakty a role připravujeme dopředu a nacvičujeme. AI nástroje během incidentu odpojujeme také, dokud nevíte, co k nim mělo přístup.

Ano. Menší modely, zejména u počítačového vidění a detekce anomálií, běží na edge zařízení přímo u linky. Výhodou je nízká odezva, provoz nezávislý na síti a fakt, že data neopouštějí halu. Do centrály se pak posílají jen výsledky a metriky, ne surové snímky.

Agent dostává jen ta oprávnění, která k úloze potřebuje, a přistupuje k datům přes rozhraní s omezeným rozsahem. Každý krok se loguje, takže je zpětně dohledatelné, co agent četl a co zapsal. U citlivých kroků zůstává schválení na člověku. Tohle nastavujeme společně s vaším IT a promítáme do interní směrnice.

Let's discuss your readiness for NIS2 and the AI Act

Tell us what you use in your company and what your customers or the authorities require from you. We will tell you whether an audit makes sense and what it would cover.
We will get back to you within one business day. Prefer the phone: +420 555 333 158