DESECONSI

Defence and security consultants, strategic intelligence

ENSK

Security that holds up under pressure.

When adopting AI, before an auditor, during an incident, in an investigation.

DESECON SI is a Bratislava consultancy for artificial intelligence, cyber security and strategic intelligence. We help companies adopt AI safely, lead security as your CISO, prepare organisations for ISO/IEC 27001 and SOC 2, and establish the facts in due diligence, investigations and fraud cases.

Service catalogue

Every engagement is put together from the services below. When you get in touch, quoting the codes is enough.

Artificial intelligence

Strategy, design, implementation and security of AI in your company.

  • AI-01
    AI management and company transformation

    AI strategy and governance for management: acceptable use policy, inventory of AI tools, roles and responsibilities, staff training and a roadmap for changing how the company works.

    References: ISO/IEC 42001EU AI Act

  • AI-02
    AI solution design

    Architecture of an AI solution before anything is built: use case and model choice, data flows, hosting and data residency, integration with your systems, running costs and security by design.

  • AI-03
    AI implementation

    Taking AI from pilot to production: integrating models, assistants and agents with your systems and data, in the cloud or on premises, with success criteria agreed up front.

  • AI-04
    LLM and AI security

    Threat modelling and testing of AI systems: prompt injection, data leakage, model and supply chain risks, access control for agents and tools, monitoring in production.

    References: OWASP LLM Top 10MITRE ATLAS

Cyber security

Governance, standards, incident response and hands-on security engineering.

Leadership

  • CS-01
    CISO as a Service

    An experienced security lead for your organisation on a part-time basis. Security strategy, risk register, policies, supplier oversight and regular reporting to management and regulators.

    References: NIS2

Standards and assessments

  • CS-02
    ISO/IEC 27001 readiness

    Gap analysis, ISMS design, risk assessment, Statement of Applicability, documentation and an internal audit ahead of certification.

    References: ISO/IEC 27001ISO/IEC 27002

  • CS-03
    SOC 2 readiness

    Scoping against the Trust Services Criteria, control design, evidence collection and a readiness review before the Type I or Type II audit.

    References: AICPA TSC

  • CS-04
    Business continuity (BCM, BCP)

    Business impact analysis, continuity and recovery plans, and exercises that show whether the plans actually work.

    References: ISO 22301

  • CS-05
    Secure development lifecycle (SSDLC)

    Setting up and reviewing how you build software securely: security requirements, threat modelling, code review and pipeline controls, release criteria.

    References: OWASP SAMMNIST SSDF

  • CS-06
    SOC maturity assessment

    Independent review of your security operations centre, in-house or outsourced: people, processes, technology and detection coverage, with a prioritised improvement plan.

    References: SOC-CMMMITRE ATT&CK

  • CS-07
    Incident process assessment

    Review of how incidents are detected, escalated, handled and reported, including regulatory notification deadlines, tested on a realistic scenario.

    References: NIST SP 800-61ISO/IEC 27035

Response and engineering

  • CS-08
    Incident response

    Support while an incident is under way: containment, coordination with IT and suppliers, evidence preservation, communication and a closing report.

  • CS-09
    Security architecture and implementation

    Design and delivery of security controls: identity and access, network segmentation, logging and monitoring, hardening of systems.

Strategic intelligence

Facts about people, companies and events, gathered lawfully and documented with care.

  • SI-01
    Due diligence

    Background and integrity checks on business partners, investors, acquisition targets and key people, using registers, open sources and interviews.

  • SI-02
    Investigations

    Internal and commissioned investigations of suspected misconduct, information leaks and conflicts of interest, with findings documented for management, auditors or legal counsel.

  • SI-03
    Fraud control

    Fraud risk assessment, design of preventive and detective controls, and investigation of suspected fraud.

How an engagement runs

  1. Assess

    We establish the current state, the risks that matter and what is required of you.

  2. Build

    We design and put in place what is missing, working alongside your team.

  3. Verify

    We test that it works and hand over evidence you can show an auditor, a regulator or your board.

Contact

Tell us briefly what you need and which services from the catalogue you are interested in. We are happy to sign a non-disclosure agreement before you share details.

Write to info@desecon.eu

Company details

Company
DESECON SI s. r. o.
Registered office
Špitálska 2203/53
811 01 Bratislava – Staré Mesto
Company ID (IČO)
57 835 438
Registration
Commercial Register of the Municipal Court Bratislava III, section Sro, file no. 204309/B