ClearSecurity VISION
EN / RO

Services

Built for your reality.

No generic checklists. We build security programs that match your industry, risk profile, and team capabilities.

01 — What we do

Three ways in. Full practice underneath.

01

Virtual CISO (vCISO)

Senior security leadership, on demand. We embed as your external CISO — building your program, advising leadership and owning accountability for risk decisions.

  • Security strategy & roadmap
  • Board reporting & risk advisory
  • NIS2 / GDPR / ISO 27001, 9001, 42001 compliance
  • Vendor & supply chain risk
Learn more →

02

Security Assessment

A structured assessment of your assets, processes and security policies — where you stand, what's missing, what's worth improving — with a risk-prioritised action plan.

  • Asset inventory & process review
  • Gap analysis on policies & controls
  • Concrete improvements & efficiencies
  • Risk-prioritised hardening plan
Learn more →

03

Security Awareness Training

Role-based security training from front-line to C-suite, phishing simulations, and measurable security culture programs that actually change behaviour.

  • Role-based training, front-line to board
  • Phishing simulations calibrated to your organization
  • Security culture programs
  • Measurement: click, reporting & progress rates
Learn more →

02 — In practice

What a real engagement looks like.

Every engagement starts with mapping reality — controls, gaps, owners. Then we get to work.

clearsecurity — assessment
$ csv assess --scope "acme-org" --framework nis2
Mapping 14 controls across 5 domains…
✓ Governance ……… 8/10
✓ Incident response … 6/10
⚠ Supply chain ……… 3/10 — 4 gaps found
$ csv report --format board-ready
→ delivered. Next: remediation plan, owner-assigned.

03 — FAQ

Frequently asked questions.

If you don't find your answer here, write to us directly.

What types of organizations do you work with?

We work with organizations of all sizes — from teams of a few people to large multinationals — across industries: manufacturing, financial services, healthcare, retail, the public sector. The key criterion is neither size nor industry: it is that leadership genuinely wants to understand risk — not just tick a compliance box.

How long does a security assessment take?

It depends on the scope and the size of your organization — a team of 30 moves at a different pace than one of 300. As an order of magnitude: a targeted assessment is measured in weeks, an end-to-end ISO 27001 project in months. What always holds: you get a clear estimate after the initial call, before you commit to anything.

Do we need existing certifications to work with you?

No. We work with organizations at any maturity level — including those starting from scratch. We can build your security foundation from zero, or optimize what you already have. ISO certification is a goal we reach together, not a starting requirement.

What is the difference between a pentest and a vulnerability assessment?

A vulnerability assessment identifies and classifies known vulnerabilities using automated tools — it is fast and gives you a clear map of your attack surface (all the points where someone could get in). A pentest goes further: a consultant actively tries to exploit those vulnerabilities, simulating a real attacker. A pentest answers "can someone actually get in?" — not just "do vulnerabilities exist?". Both are part of our security assessment practice.

How do you handle sensitive data during an engagement?

Every engagement begins with a confidentiality agreement (NDA). Data collected is processed solely for the purpose of the engagement, never stored long-term without explicit agreement, and deleted or returned on completion. We apply the same standards we recommend to our clients.

Can you help after an incident has already occurred?

Yes. We provide incident response support — both in the acute phase (containment, investigation) and afterwards (root cause analysis, remediation, communications). If you have an active incident, contact us directly and flag it as urgent.

What should we expect in terms of cost?

We don’t publish fixed rates, because every engagement is different. What we can promise: after the initial call you get a clear written proposal with scope, deliverables, timeline and price — no hidden costs. Engagements start from a few hundred euros for targeted assessments, up to multi-year programs for organizations with complex needs.

Ready to start?

One conversation. No discovery-call script, no sales deck. You talk to the people who do the work.

Start a conversation