A cybersecurity manager who leaves evidence behind
We take on the cybersecurity manager role for entities in scope of NIS2 — Directive (EU) 2022/2555, independent of your IT operations, and we produce evidence for every obligation that will hold up under supervision. No Word files and verbal assurances: every control, risk, incident and decision lives in a system whose records cannot be rewritten after the fact.
Management bodies are personally accountable
Management must approve the risk-management measures, oversee their implementation and undergo training. Accountability cannot be delegated to the IT department — and in most transpositions it cannot be insured away either.
Incident reporting deadlines
Early warning within 24 hours, notification within 72 hours, final report within one month (Art. 23). The clock starts when you become aware of the incident — not when someone gets around to it.
Upper limit of fines
For essential entities, at least up to €10 million or 2 % of total worldwide annual turnover, whichever is higher; for important entities at least €7 million or 1.4 % (Art. 34). Member states may go higher.
A named individual with a certificate, not „our team"
Regulators do not ask for a supplier — they ask for an assigned person who is independent of IT operations and development and who meets a demonstrable knowledge standard. That is why we give you a name and a certificate number at the outset, instead of a marketing line about an experienced team.
The certificate is issued by an accredited certification body under the certification scheme of the Slovak National Security Authority and is verifiable in that body's public register. You do not have to take our word for it — check it.
Every contract comes with a copy of the certificate, the appointment letter and a signed conflict-of-interest declaration. A named deputy is part of the service, so the role is never left vacant. Where a national transposition requires a specific statutory role or a locally licensed professional, we deliver that part together with local counsel and say so up front.
Branislav Anwarzai, MSc. Eng.
Cybersecurity Manager
How to verify it: the certification body publishes the register of certificate holders on its website. Search it for the certificate number above.
Three sentences nobody else in this market says
There is no shortage of outsourced cybersecurity managers. Their activity lists are nearly identical. The difference is what you are left holding after a year.
We are independent of your IT
We do not run your infrastructure, so we satisfy the independence expectation that runs through NIS2 transpositions. If your IT supplier holds the role, they are checking their own work — and that is a finding at audit.
The software is in the fee
You are not just buying consultant hours. The fee includes the Praetorix GRC platform, Vigil security monitoring and the lexpetra.pro legal layer. Competitors deliver documents — we deliver the system those documents live and are timestamped in.
Public pricing and measurable SLAs
Our prices are on this page, not „available on request after a free consultation". You know in advance what you get, by when and for how much — including a guarantee that you do not pay for delayed milestones.
Every obligation mapped to an article and to a concrete deliverable
This is the table your auditor will open. It shows which legal obligation we cover, what we actually do about it and what evidence is left behind.
| Legal obligation | What we do | Deliverable / evidence | Tool |
|---|---|---|---|
| Art. 20 governance and accountability of management bodies |
appointed cybersecurity manager and deputy, appointment letter, evidence of qualification, management training | appointment, CV, certificate, role and authority description, training records | Praetorix |
| Art. 21(2) risk-management measures (a) – (j) |
gap analysis → remediation plan → implementation management → periodic effectiveness review | control matrix with status, plan with owners and deadlines, quarterly effectiveness review | Praetorix |
| Risk analysis Art. 21(2)(a), ISO/IEC 27005 |
asset and threat identification, scoring, residual risk after exposure and control effectiveness, relationships between risks | risk register, heat map, attack chains, re-assessment due dates | Praetorix |
| Art. 21(2)(d) supply chain security |
supplier inventory, criticality classification, security clauses in contracts, DPAs, verification of compliance | supplier register, clause set, list of contracts to be amended | lexpetra.pro + Praetorix |
| Art. 23 incident reporting |
intake, classification, incident handling, drafting of notifications, communication with the CSIRT and competent authority | incident file with a timeline, submitted notifications, lessons learned | Vigil |
| Audit and self-assessment | self-assessment, preparation for an external audit, support throughout the audit | self-assessment report, corrective action plan, audit-ready package | Praetorix |
| Security documentation | creation and maintenance of the policy set — security policy, risk management, incidents, continuity, access, suppliers, cryptography, hygiene, training | 17+ documents, versioned and approved by management | Praetorix |
| Art. 21(2)(g) cyber hygiene and awareness |
training plan, e-learning, phishing simulations, evaluation | training records, simulation results, trend over time | Vigil |
| Continuous monitoring | log collection and correlation across key systems, detection, monthly report | monthly report with records whose integrity can be verified | Vigil |
| Art. 21(2)(b), (c) incident handling and business continuity |
incident response plan, backup and recovery review, crisis management, tabletop exercise | response plan, exercise record, recovery test results | Vigil |
A week-by-week plan with acceptance criteria
The market tells you „implementation takes 4 – 12 weeks". We tell you what you get in which week and how you will know it was actually finished.
Appointment, access, kick-off
Appointment letter, evidence of the knowledge standard, split of responsibilities (RACI).
Acceptance: the appointment is signed by management.Inventory of assets, services and suppliers
Asset register and supplier register — without these neither risk analysis nor supply chain work is possible.
Acceptance: at least 95 % of critical systems are in the register.Gap analysis against Art. 21 and the local transposition
Control matrix with compliance status and the ten most serious gaps ranked by impact.
Acceptance: reviewed with management.Risk analysis
Risk register with residual scoring and a heat map, including relationships between risks (attack chains).
Acceptance: approved by management.Security documentation set
17+ policies and procedures, versioned, with an approval workflow.
Acceptance: approved and published.Monitoring onboarding
Logs from key systems, alerting and an audit log with guaranteed integrity.
Acceptance: first monthly report delivered.Supply chain
Security clauses under Art. 21(2)(d), list of contracts to be amended, GDPR data processing agreements.
Acceptance: handed over to legal or procurement.Incident process and drill
Incident response plan, CSIRT and authority contacts, a drill of the 24-hour and 72-hour notifications.
Acceptance: simulated incident handled successfully.Training and phishing simulation
Training records and a simulation evaluation with recommendations.
Acceptance: at least 80 % of staff trained.Self-assessment and remediation plan
Self-assessment report and a corrective action plan with deadlines and owners.
Acceptance: handed to management, ready for the authority.Milestone guarantee
If we fail to deliver the week 1 – 8 milestones within 90 days of signature, the monthly fees for the period of delay are not invoiced. This is not a gesture — it is the only way a promise about deadlines can be verified.
Three systems, one chain of evidence
These are not three products sitting side by side. A penetration test finding raises the exposure of an asset, that recalculates the risk, the risk calls for a control, the control becomes a contractual obligation on a supplier — and the whole path stays in the audit log.
- Registers of assets, threats, risks and controls, with an automatically generated Statement of Applicability.
- Residual risk = inherent × exposure × control effectiveness; relationships between risks reveal attack chains.
- Risk re-assessment due dates with „overdue / due soon" flags — this is the first question at audit.
- Change trail: who changed what and when on every risk and control — hash-chained with append-only protection, exportable to PDF.
- Group model for holdings: a consolidated view across entities with data isolation.
- Log collection and correlation, detection, alerting; monthly report with verifiable record integrity.
- Incident module with statutory deadlines — the system counts the 24-hour, 72-hour and one-month deadlines and escalates on its own.
- Tamper-evident audit log (anchored hash chain) — nobody can rewrite history retroactively, including us.
- Penetration test orchestration and finding management with automatic impact on risk scores.
- Client portal: your status, reports, DPAs and SLA performance in one place.
- Legislative change monitoring with impact analysis mapped to your specific controls.
- Security clauses for supplier contracts and GDPR data processing agreements.
- Review of existing supplier contracts and a list of those that need amending.
- Register of deadlines and obligations — registration, controls, self-assessment, audit — with advance reminders.
Our prices are published. The rest of the market's are not.
Prices are final — we are not VAT registered; they assume a 12-month term. The onboarding package is a one-off fee covering the effort of the first 6 – 10 weeks, during which the documentation, the risk analysis and the monitoring onboarding are produced.
Start
- 8 manager hours per month
- Praetorix GRC — 1 entity
- Vigil Starter
- Legislative monitoring
- Annual self-assessment
- Annual training (online)
- Quarterly management reporting
- Representation before the authority and CSIRT
Standard
- 20 manager hours per month
- Praetorix GRC + extended registers
- Vigil Standard
- Contract clauses + DPAs
- Annual self-assessment
- Training 2×/year + phishing 2×
- Monthly reporting + quarterly for management
- Representation before the authority and CSIRT
Essential Entity
- 40 manager hours per month + on-call
- Praetorix GRC + group reporting
- Vigil Enterprise
- Supplier contract review
- Self-assessment + audit preparation
- Training 4×/year + phishing 4× + tabletop exercise
- Monthly reporting and on demand
- Representation before the authority, on-site during incidents
Group / On-prem
- Manager capacity per agreed SLA
- Praetorix — group model, on-prem
- Vigil Enterprise / on-prem
- Full legal layer
- Self-assessment per entity
- Training per plan
- Monthly reporting
- Representation before the authority and CSIRT
Add-on services
Audit by a certified auditor
Delivered by a partner cybersecurity auditor.
Penetration testing
Findings feed asset exposure and recalculate the risk register.
Phishing campaign
Simulation with evaluation and training recommendations.
Management training
Half a day — management accountability under NIS2 Art. 20.
GDPR / DPO package
Data protection officer alongside the cybersecurity manager role.
Incident response retainer
Outside the Essential Entity plan, where it is already included.
Discounts: 24-month term −8 % · annual prepayment −5 % · second and each further entity in a group −30 %. · All prices are final — we are not VAT registered. The stated scope assumes the client's cooperation in providing access to documents and systems.
Four ways to fill the cybersecurity manager role
All four are lawful. Not all four survive an audit, and not all four are cheaper than they first appear.
| In-house | Typical outsourced | IT supplier | Praetorix | |
|---|---|---|---|---|
| Annual cost | €40 – 72k | €10 – 30k | „included in support" | €8.3 – 34.8k |
| Independence from IT operations | often not | yes | no — conflict of interest | yes |
| Availability from signature | 3 – 6 months' hiring | 2 – 4 weeks | immediate | within 5 working days |
| Cover during leave and sickness | none | rarely | yes | named deputy included |
| GRC platform included | no | no | no | yes — Praetorix |
| Monitoring and integrity-proof audit log | no | no | partly (SOC) | yes — Vigil |
| Legal layer and contract clauses | no | no | no | yes — lexpetra.pro |
| Public price list | — | no | no | yes |
| Measurable SLA and milestone guarantee | — | rarely | rarely | yes |
What we guarantee in writing
The following points go into the contract exactly as they are written here.
Availability and response
Start: business days 08:00 – 17:00. Standard: 24/7 by phone during an incident. Essential Entity: 24/7 with a one-hour response. We draft the early warning within 12 hours of incident classification — the law allows 24, and that margin is yours.
Reporting
Monthly report by the fifth working day of the following month. Quarterly management report within 10 working days of quarter end. The report also covers what was missed — not only what went well.
Data protection
Processing on our infrastructure inside the European Union, or on-premise at your site. Data processing agreement under Art. 28 GDPR. We do not send the content of your documents to external AI services. An NDA is signed before first access to your data.
Exit without lock-in
On request, a complete data export — registers, documentation, audit log — within 10 working days, in open formats. The documentation remains yours after the engagement ends.
Milestone guarantee
If the first eight weeks' milestones are not delivered within 90 days, we do not invoice the monthly fees for the period of delay.
Continuity of the role
A named deputy is part of the service. The role is not left vacant during leave or sickness — which is the single most common finding with in-house appointments.
The questions we get most often
We have an IT provider — can they take the role?+
They can, but they would be assessing their own work. Independence from IT operations runs through NIS2 supervisory practice, and in several member states — Slovakia and Czechia among them — it is written directly into the law. If your IT supplier holds the role, they approve their own controls, which is a finding that is hard to defend.
We work with your IT supplier, assign tasks and verify delivery. But we assess them independently, because we do not manage them and have no stake in their invoicing.
Who exactly will be our cybersecurity manager?+
Branislav Anwarzai, MSc. Eng., holder of Cybersecurity Manager certificate no. 0699/20/24/MKB/153/O-012 issued by TÜV SÜD Slovakia s.r.o. — a certification body accredited by the Slovak National Accreditation Service under 153/O-012 to ISO/IEC 17024, under the certification scheme of the National Security Authority of the Slovak Republic, version 1.2. Valid until 17 December 2027.
The certificate is verifiable in the public register of holders published on the certification body's website. A copy of the certificate, the appointment letter and a conflict-of-interest declaration are attached to the contract.
Does a Slovak certificate work in our country?+
NIS2 itself does not prescribe a specific certificate for the role — Art. 21 requires appropriate and proportionate measures, and national transpositions require demonstrable knowledge and independence from operations. We present the certificate as third-party-verifiable evidence of that knowledge standard, not as a local statutory licence.
Where your transposition does require a specific statutory role or a locally licensed professional — a security audit by a nationally qualified auditor, for example — we say so during the assessment and deliver that part with a local partner. We will not claim a qualification we do not hold.
It is expensive.+
An in-house cybersecurity manager costs €40,000 – 72,000 a year including employer contributions. Our Standard plan works out at €17,880 a year and the software is included. You also avoid 3 – 6 months of recruitment and the risk of the person leaving a year later, taking the know-how with them.
The other side of the equation: under Art. 34 of NIS2, essential entities face fines of at least up to €10 million or 2 % of worldwide turnover, important entities at least €7 million or 1.4 %.
We can do it ourselves, we have templates.+
Templates are not the problem — they can be bought. The problem is demonstrating performance: a risk analysis with re-assessment dates, training records, an incident timeline and, above all, evidence that records were not altered after the fact.
That is exactly what a template cannot give you. An auditor does not ask whether a document exists. They ask when it was created, who approved it and what has changed since.
Why not a large consultancy brand?+
You get the same articles for roughly three times the price, usually without a system for the outputs to live in, and with a junior consultant doing the daily work. We have a public price list, measurable SLAs and a milestone guarantee.
If you need a big brand name for your board, that is a legitimate reason to go elsewhere — and we will tell you so directly.
What are our deadlines?+
NIS2 sets the reporting deadlines directly: 24 hours for the early warning, 72 hours for the notification and one month for the final report (Art. 23).
Registration, implementation of measures and audit or self-assessment deadlines follow your member state's transposition and differ between countries. We determine the ones that apply to you during the initial assessment, in writing.
Can we see references?+
References are available on request. We deliberately do not publish them — in cybersecurity, a client list is itself sensitive information, and we name clients only with their explicit consent.
After the initial assessment we will put you in direct contact with a reference client from a comparable sector, so you can ask them rather than us.
What happens if we part ways?+
Within 10 working days you receive a complete export of all data — registers, documentation and the audit log — in open formats. The documentation is yours. No vendor lock-in and no exit fees.
Find out what the law actually requires of you
Fill in the form — we create a tracked ticket and get back to you within 24 hours. The first step is a 30-minute obligations assessment: whether you are in scope, as an essential or important entity, which deadlines are running and what is missing today.
- No obligation and no cost
- Tracked ticket with a reference number
- Assessment of classification and deadlines under NIS2
- If you are out of scope, we will say so
- References available on request
The role has to be filled in a way that holds up
Risk analysis and approval of documentation need calendar time on your side too — this is not work that can be squeezed into the final month before a deadline.