Wrocław · serving clients across the EU

Security work that survives an audit.

CyberESQ pairs security engineers with regulatory advisors, so the fixes we recommend and the evidence your auditor asks for come from the same team. We work with financial services, healthcare, logistics and SaaS companies operating under EU rules.

Focus
NIS2, DORA, ISO 27001, GDPR
Engagements
Fixed scope, fixed fee
Working hours
Central European Time

What we do

Six services, each one scoped as a standalone engagement. Most clients start with an assessment and keep us on for the remediation.

Security assessments

Penetration testing of web applications, APIs, cloud environments and internal networks. You get reproducible steps, a risk rating tied to your business, and a retest once the fixes land.

NIS2 and DORA readiness

A gap analysis against the obligations that actually apply to your entity class, followed by a remediation plan your board can approve and your regulator can follow.

ISO 27001 implementation

We build the management system with your teams rather than handing over a folder of templates: scope, risk method, Annex A controls, internal audit and the certification audit itself.

Data protection and GDPR

Records of processing, lawful basis review, DPIAs, international transfer assessments and vendor contracts — written in language your commercial teams can work with.

Incident response

Containment, forensic analysis and the regulatory notifications that follow. Retainer clients get a named responder and an agreed escalation path before anything goes wrong.

Virtual CISO

Security leadership by the day for companies that need the function but not yet the headcount: policy ownership, budget input, supplier reviews and reporting to the board.

About CyberESQ

We are a small advisory firm in Wrocław, registered as CYBERESQ Sp. z o.o. and working under Polish and EU law.

The firm was built around a frustration our founders kept running into: technical security reports that no lawyer could act on, and compliance documents that no engineer believed. We keep both disciplines in the same room and on the same engagement, which is why our reports name a control, a clause and an owner on the same line.

Our work sits across two registered activities — IT services (PKD 62.09) and management consulting (PKD 70) — because that is genuinely how the work splits. Some weeks we are reading packet captures; other weeks we are sitting in a board meeting explaining what a supervisory authority will expect to see.

  • Independent: we do not resell security products or take vendor commission.
  • Senior-led: the people who scope your engagement are the people who deliver it.
  • Documented: every recommendation arrives with the evidence behind it.
A finding, the clause that requires it, and who signs it off.

Why companies keep us on

Four things clients tell us are different here. They are also the four things we will hold ourselves to in writing.

One team for the fix and the paperwork

No hand-off between a testing vendor and a compliance consultancy, and no gap where responsibility disappears.

Scope and fee agreed up front

You approve a written scope with a fixed fee before work starts. Changes are quoted, not absorbed into an invoice.

Evidence an auditor accepts

Findings are mapped to the specific clause or control they satisfy, so your next audit is a review rather than a rebuild.

Plain answers, in your timezone

Named contacts based in Wrocław, reachable during CET business hours, writing in Polish or English.

How an engagement runs

  1. 1

    Scoping call

    Forty-five minutes on your systems, obligations and deadlines. No charge.

  2. 2

    Written proposal

    Scope, method, deliverables, fee and dates — usually within three working days.

  3. 3

    Assessment

    Testing and document review, with interim findings raised as soon as we see them.

  4. 4

    Report and walkthrough

    A technical report, a board summary, and a session with the teams who own the fixes.

  5. 5

    Retest

    We verify the remediation and reissue the report so it reflects where you actually stand.

Request a review

Tell us what you are working towards and we will reply with the next step, or say plainly if it is not something we should take on.

This form opens your email client with the details filled in. Nothing is stored on this website.