MDR vs SIEM vs SOC: what is the difference and what does a company really need?
SIEM, SOC, MDR, XDR, comparing the jargon and a practical guide to what each company actually needs and where to start.
Practical guides, analyses and recommendations. Penetration testing, NIS2, SOC, incident response and security audits for Czech companies.
35 articles · updated April 2026
SIEM, SOC, MDR, XDR, comparing the jargon and a practical guide to what each company actually needs and where to start.
NÚKIB's powers, the NIS2 regulator's role, inspections and fines up to 250 mil. Kč. What this means for your company.
Who must register, how the process works, what deadlines apply and what penalties for non-registration are enforced by the National Office of Nuclear Safety and Radiation Protection (NÚKIB).
What NÚKIB offers, what Decree No. 409/2025 Coll. Requires, and when you need a commercial training programme.
NIS2 is an EU directive; NÚKIB is the Czech regulator. The relationship, timeline and what you specifically need to do.
CIA triad, ISMS, ISO 27001 vs. NIS2. A practical overview of what a security programme must cover.
BCP and DRP for cyber threats. RTO, RPO, NIS2 requirements and business continuity plan testing.
Prague, 50+ employees or €10m turnover, sector exemptions and how to verify registration obligations.
How dark web monitoring protects companies against the misuse of leaked login credentials and data.
Risk analysis methodology for NIS2 compliance in accordance with Decree No. 409/2025 Coll. Template available for download.
Recommended frequencies of penetration tests according to company type, NIS2 requirements and when to carry out ad-hoc testing.
NÚKIB as regulator, fines up to 250 mil. Kč and personal liability of management.
SSID segmentation, WPA3, 802.1X/RADIUS, rogue AP detection and Wi-Fi audit methodology.
Continuous awareness programme, micro-learning, gamification and training effectiveness measurement.
SolarWinds, XZ Utils and other examples. NIS2 and supply chain security.
Network isolation, forensic analysis, reporting to the National Cyber and Information Security Bureau (NÚKIB), and restoration from backup. A step-by-step approach without panic.
Where NIS2 and ISO 27001 overlap and where they differ. What will help your ISMS.
OWASP API Security Top 10, authentication, rate limiting and API security testing.
VPN versus ZTNA, MDM, BYOD policy and secure home office for corporate employees.
Types of audits, assessment phases, the final report and how to use the results in practice.
Governance, MFA, encryption, patch management, incident response, BCM, supply chain and training.
5-step NIS2 audit procedure. Scoping, asset inventory, risk analysis, gap analysis and action plan.
GDPR Article 32, data breach notification, cooperation between DPO and CISO, pseudonymisation and encryption.
OWASP Top 10, methodology for web application penetration tests, testing phases and contents of the final report.
The 3-2-1 rule, offline backups, recovery testing, RTO and RPO, and NIS2 requirements for BCM.
What a CISO does, why SMEs cannot afford a full-time CISO, and how the CISOaaS model works.
Statistics on exploits via unpatched CVEs, patching priorities, and automated versus manual patching.
Types of social engineering attacks (phishing, vishing, pretexting), psychological principles and employee training.
What a SOC does, types (internal, outsourced), MDR versus SOC and what to look for in a provider.
Misconfiguration, shared responsibility model, weak IAM, unencrypted data and missing monitoring.
What is Zero Trust, why traditional perimeters fail, the five pillars and how to implement it step by step.
6 phases of IR (from preparation to lessons learned), what to include, and the NIS2 obligation to report within 72 hours.
Statistics on compromised passwords, types of MFA (TOTP, hardware keys, passkeys), and recommendations.
Why phishing is the #1 attack vector, how simulations work and how to combine them with training.
How ransomware works, statistics, prevention (backups, patches, MFA, segmentation) and what to do in the event of an attack.
What is a pentest, its types (black/grey/white box), how it is conducted, what the company receives and how often to test.
Our experts will prepare a security audit tailored to your company. The first consultation is free of charge.
Get a free consultation →