Security assessments
Penetration testing of web applications, APIs, cloud environments and internal networks. You get reproducible steps, a risk rating tied to your business, and a retest once the fixes land.
Wrocław · serving clients across the EU
CyberESQ pairs security engineers with regulatory advisors, so the fixes we recommend and the evidence your auditor asks for come from the same team. We work with financial services, healthcare, logistics and SaaS companies operating under EU rules.
Six services, each one scoped as a standalone engagement. Most clients start with an assessment and keep us on for the remediation.
Penetration testing of web applications, APIs, cloud environments and internal networks. You get reproducible steps, a risk rating tied to your business, and a retest once the fixes land.
A gap analysis against the obligations that actually apply to your entity class, followed by a remediation plan your board can approve and your regulator can follow.
We build the management system with your teams rather than handing over a folder of templates: scope, risk method, Annex A controls, internal audit and the certification audit itself.
Records of processing, lawful basis review, DPIAs, international transfer assessments and vendor contracts — written in language your commercial teams can work with.
Containment, forensic analysis and the regulatory notifications that follow. Retainer clients get a named responder and an agreed escalation path before anything goes wrong.
Security leadership by the day for companies that need the function but not yet the headcount: policy ownership, budget input, supplier reviews and reporting to the board.
We are a small advisory firm in Wrocław, registered as CYBERESQ Sp. z o.o. and working under Polish and EU law.
The firm was built around a frustration our founders kept running into: technical security reports that no lawyer could act on, and compliance documents that no engineer believed. We keep both disciplines in the same room and on the same engagement, which is why our reports name a control, a clause and an owner on the same line.
Our work sits across two registered activities — IT services (PKD 62.09) and management consulting (PKD 70) — because that is genuinely how the work splits. Some weeks we are reading packet captures; other weeks we are sitting in a board meeting explaining what a supervisory authority will expect to see.
Four things clients tell us are different here. They are also the four things we will hold ourselves to in writing.
No hand-off between a testing vendor and a compliance consultancy, and no gap where responsibility disappears.
You approve a written scope with a fixed fee before work starts. Changes are quoted, not absorbed into an invoice.
Findings are mapped to the specific clause or control they satisfy, so your next audit is a review rather than a rebuild.
Named contacts based in Wrocław, reachable during CET business hours, writing in Polish or English.
Forty-five minutes on your systems, obligations and deadlines. No charge.
Scope, method, deliverables, fee and dates — usually within three working days.
Testing and document review, with interim findings raised as soon as we see them.
A technical report, a board summary, and a session with the teams who own the fixes.
We verify the remediation and reissue the report so it reflects where you actually stand.
Tell us what you are working towards and we will reply with the next step, or say plainly if it is not something we should take on.