Security that holds up under pressure.
When adopting AI, before an auditor, during an incident, in an investigation.
DESECON SI is a Bratislava consultancy for artificial intelligence, cyber security and strategic intelligence. We help companies adopt AI safely, lead security as your CISO, prepare organisations for ISO/IEC 27001 and SOC 2, and establish the facts in due diligence, investigations and fraud cases.
Service catalogue
Every engagement is put together from the services below. When you get in touch, quoting the codes is enough.
Artificial intelligence
Strategy, design, implementation and security of AI in your company.
- AI-01
AI management and company transformation
AI strategy and governance for management: acceptable use policy, inventory of AI tools, roles and responsibilities, staff training and a roadmap for changing how the company works.
References: ISO/IEC 42001EU AI Act
- AI-02
AI solution design
Architecture of an AI solution before anything is built: use case and model choice, data flows, hosting and data residency, integration with your systems, running costs and security by design.
- AI-03
AI implementation
Taking AI from pilot to production: integrating models, assistants and agents with your systems and data, in the cloud or on premises, with success criteria agreed up front.
- AI-04
LLM and AI security
Threat modelling and testing of AI systems: prompt injection, data leakage, model and supply chain risks, access control for agents and tools, monitoring in production.
References: OWASP LLM Top 10MITRE ATLAS
Cyber security
Governance, standards, incident response and hands-on security engineering.
Leadership
- CS-01
CISO as a Service
An experienced security lead for your organisation on a part-time basis. Security strategy, risk register, policies, supplier oversight and regular reporting to management and regulators.
References: NIS2
Standards and assessments
- CS-02
ISO/IEC 27001 readiness
Gap analysis, ISMS design, risk assessment, Statement of Applicability, documentation and an internal audit ahead of certification.
References: ISO/IEC 27001ISO/IEC 27002
- CS-03
SOC 2 readiness
Scoping against the Trust Services Criteria, control design, evidence collection and a readiness review before the Type I or Type II audit.
References: AICPA TSC
- CS-04
Business continuity (BCM, BCP)
Business impact analysis, continuity and recovery plans, and exercises that show whether the plans actually work.
References: ISO 22301
- CS-05
Secure development lifecycle (SSDLC)
Setting up and reviewing how you build software securely: security requirements, threat modelling, code review and pipeline controls, release criteria.
References: OWASP SAMMNIST SSDF
- CS-06
SOC maturity assessment
Independent review of your security operations centre, in-house or outsourced: people, processes, technology and detection coverage, with a prioritised improvement plan.
References: SOC-CMMMITRE ATT&CK
- CS-07
Incident process assessment
Review of how incidents are detected, escalated, handled and reported, including regulatory notification deadlines, tested on a realistic scenario.
References: NIST SP 800-61ISO/IEC 27035
Response and engineering
- CS-08
Incident response
Support while an incident is under way: containment, coordination with IT and suppliers, evidence preservation, communication and a closing report.
- CS-09
Security architecture and implementation
Design and delivery of security controls: identity and access, network segmentation, logging and monitoring, hardening of systems.
Strategic intelligence
Facts about people, companies and events, gathered lawfully and documented with care.
- SI-01
Due diligence
Background and integrity checks on business partners, investors, acquisition targets and key people, using registers, open sources and interviews.
- SI-02
Investigations
Internal and commissioned investigations of suspected misconduct, information leaks and conflicts of interest, with findings documented for management, auditors or legal counsel.
- SI-03
Fraud control
Fraud risk assessment, design of preventive and detective controls, and investigation of suspected fraud.
How an engagement runs
-
Assess
We establish the current state, the risks that matter and what is required of you.
-
Build
We design and put in place what is missing, working alongside your team.
-
Verify
We test that it works and hand over evidence you can show an auditor, a regulator or your board.
Contact
Tell us briefly what you need and which services from the catalogue you are interested in. We are happy to sign a non-disclosure agreement before you share details.
Write to info@desecon.eu
Company details
- Company
- DESECON SI s. r. o.
- Registered office
- Špitálska 2203/53
811 01 Bratislava – Staré Mesto - Company ID (IČO)
- 57 835 438
- Registration
- Commercial Register of the Municipal Court Bratislava III, section Sro, file no. 204309/B