Not sure whether NIS2 and the AI Act apply to you?
We will find out and get you ready
- We examine your infrastructure, processes, access rights and suppliers and work out where the biggest risk lies
- We compare the current state against NIS2 and the AI Act and give you a list of specific steps
- We set rules for working with data and AI tools and train your people
A no-obligation cyber readiness audit
Why deal with it right now
The obligations will hit smaller companies too
An attack today starts with a person
AI tools carry company data away
Does this sound familiar?
You do not know whether NIS2 affects you
Security is held in one person's head
You have backups, but nobody has tried restoring them
People use AI however they are used to
They trust us
Continental · Hyundai Motor · Groupon · Union of Towns and Municipalities of the Czech Republic · Technology Agency of the Czech Republic · Datasys · Spokar · Slovak Athletics Federation · Energy Centre of the Ústí Region · VŠÚO Holovousy
What exactly we will do for you
| Task | What we will do for you | Benefit |
|---|---|---|
| Cybersecurity audit | We examine the infrastructure, configurations, access rights and processes | You know where the real risks are and what to address first |
| NIS2 readiness | We assess the scope of your obligations, missing documentation and risk management | You have a plan for meeting the obligations and evidencing them |
| AI adoption in line with the AI Act | A register of AI tools, internal rules, staff briefing and AI literacy | You use AI without legal risk and without data leaks |
| Cyber Resilience Act readiness | We determine whether your product falls under the CRA and go through the requirements and CE marking | You can still sell hardware and software in the EU after December 2027 |
| Vulnerability reporting under the CRA | We set up reporting of exploited vulnerabilities and incidents within 24 hours | You meet the deadlines that have applied since 11 September 2026 |
| SBOM and product support | We compile a component inventory and a security update plan | You know what runs inside the product and how long you will patch it |
| Rules for working with AI tools | We set out what may be entered into ChatGPT, Copilot or Gemini | Company know-how stays inside the company |
| Staff training and phishing tests | We train the team and test their reactions to fraudulent e-mails | People spot an attack before they click on anything |
| Backups and business recovery | We check the backups, set up and test a recovery plan | You know how long recovery takes and what from |
| Suppliers and access management | We go through permissions, accounts and third-party access | Supply chain risk is under control |
| Incident response | We prepare the procedure, roles, contacts and incident reporting | Nobody has to improvise during an incident |
4 steps to a resilient company
Initial audit and scope of obligations
Priorities and action plan
Deploying measures and rules
Verification and maintenance
How the cooperation works
Introductory call
Initial audit and output
First measures in operation
Supervision and development
How much it costs
Initial audit and NIS2 assessment
Deploying measures and rules
Ongoing supervision and training
How NIS2, the AI Act and safe use of artificial intelligence fit together
Frequently asked questions and answers about cybersecurity
Does NIS2 also apply to our medium-sized company?
The new rules affect a much wider range of sectors than before – from manufacturing and transport to the food industry. If you have more than 50 employees or a turnover of over EUR 10 million and you operate in a regulated sector, you probably fall under the act. We will help you determine this precisely.
What happens if we do not deal with the AI Act?
In addition to the risk of fines, you run the danger of deploying systems that will later be prohibited or will require costly modifications. Setting the rules for AI correctly right at the start will save you costs in the future.
Is your digital audit focused only on IT?
Not at all. We look at the business as a whole. We assess the digital maturity of your production processes, your logistics and the way you work with people. The aim is to find the places where technology genuinely earns money or saves time.
Who in the company bears responsibility for failing to meet NIS2 obligations?
The new legislation (and the Czech Cybersecurity Act) targets top management directly. Responsibility can no longer be delegated solely to the IT department or an external administrator. Statutory bodies have a duty to educate themselves in the field of cybersecurity and to oversee the implementation of measures. In the event of gross negligence, senior staff may even face a temporary ban on holding office.
Can we use free versions of AI tools for company purposes?
From the point of view of security and the AI Act this is highly risky. Free versions (e.g. standard ChatGPT without an Enterprise licence) may use the data entered to train the model further. If your employee enters sensitive data, trade secrets or clients’ personal data there, it becomes part of the public cloud. We will help you set up secure systems and procedures that lock your know-how inside the company.
Do we have to replace all our hardware and software because of NIS2?
Not at all. NIS2 is not about buying the most expensive technology but about setting up processes and sensible risk management. It is often enough to configure existing systems correctly, introduce two-factor authentication (MFA), manage access rights better and train people regularly. Our audit identifies what genuinely needs to be adjusted and what is working well.
How is digital maturity related to cybersecurity?
Directly. The more digitally advanced a company is (using the cloud, IoT in production, automation), the larger the surface it offers for a potential attack. A digital maturity audit will show you not only how to innovate but also how to build those innovations on secure foundations (known as security-by-design). Security must not be “stuck on” at the end; it must be part of every new digital process.
How is supply chain vetting carried out?
Under NIS2 you are also responsible for how well your key suppliers are secured. If a hacker attacks your IT services provider or your accounting software, they can get through to you. We will help you set up control mechanisms and contractual conditions so that your partners are not the weakest link in your own security.
What is the AI Act and do we have to deal with it already?
The AI Act is an EU regulation that regulates the development and use of AI. Although some obligations are being phased in gradually, it is essential to have the rules in place now (AI governance). If you are now deploying new systems without regard to the AI Act, you risk having to redesign them at great cost or switch them off in a year’s time.
How will you make sure our data does not leak into ChatGPT?
This is one of the most common concerns. We deal with it by setting up processes, using corporate licences or using API interfaces with local models, where your data will not be used for further training. Our services also include setting up an internal policy for the safe use of AI.
Why should we deal with the AI Act now, when we are still only testing systems?
The AI Act introduces an obligation of “AI literacy” for all organisations that use AI. If you now introduce processes without regard to this legislation, you run the risk that your solution will retrospectively be declared non-compliant. We will help you set up an ethical and legal framework right at the start, which is far cheaper than correcting mistakes later and facing the threat of heavy penalties.
How do we recognise phishing written by AI?
Not from the text any more. Generative AI writes without errors, can imitate your jargon and a colleague’s signature and can even manage a voice recording. So rely on process, not on impressions: confirming changes to bank details through a second channel, two-factor login and the rule that nobody sends money or passwords on the basis of an e-mail or a phone call. That is why we add examples of AI-generated attacks to our training.
What should an internal guideline for the use of AI contain?
A list of approved tools, a clear definition of the data that must not be entered into them (personal data, contracts, source code, know-how), a rule on human checking of outputs and a responsible person people can turn to. Alongside that, instruction of employees and a record of who completed the training and when. We write the guideline on one or two pages so that people actually use it.
How long does an initial cybersecurity audit take?
Two to three weeks for a smaller company, longer for a manufacturer with several sites. We need access to an overview of systems, suppliers and access rights, plus a few hours of your IT team’s time. The output is a written summary of weak points, the impact of NIS2 and the AI Act, and priorities according to impact and cost. It also covers which AI tools are already being used in the company.
How often do backups and business recovery need to be tested?
At least twice a year and always after a major change to systems. What is tested is not just that a backup exists but that you can restore operations from it within a time the company can survive economically. The test should be recorded, with who carried it out and how long the restoration took. We take the same approach to the data and models on which the company’s AI tools run.
Do we have to keep a record of the AI tools our employees use?
We recommend it even if the legislation did not require it. Without a list you do not know where company data is going and what an external service is storing about your company. The record is usually a simple table: tool, purpose, who uses it, what data goes into it and who is responsible for it. It helps with security questionnaires from customers and with meeting AI Act obligations.
Will our own or a local AI model help us to control our data better?
Yes, if the data must not leave the company. We can deploy an open-source model on your server or in a private cloud and fine-tune it on your documents. The data then stays with you and what you mainly have to deal with is access rights and backups. For most companies, though, it is quicker to start with a cloud service with the rules set up, and to move to local operation only when there is a measurable reason.
What should be done in the first 24 hours after a cyber incident?
Disconnect the affected systems, but do not switch them off (because of the evidence), convene the pre-assigned roles, secure backups off the network and start writing a timeline. Then deal with reporting and communication with partners. This cannot be improvised while everything is happening, which is why we prepare the procedure, contacts and roles in advance and rehearse them. During an incident we also disconnect AI tools until you know what had access to them.
Can AI run directly at the machine without an internet connection?
Yes. Smaller models, particularly in computer vision and anomaly detection, run on an edge device right at the production line. The advantages are low latency, operation independent of the network and the fact that data does not leave the plant. Only results and metrics are then sent to head office, not raw images.
Can an AI agent work with our data securely?
The agent is given only the permissions it needs for the task and accesses data through an interface with a limited scope. Every step is logged, so it can be traced afterwards what the agent read and what it wrote. For sensitive steps, approval remains with a human. We set this up together with your IT team and reflect it in your internal guideline.