# The Security Company (TSC) — Full Site Content > Full-text snapshot of https://thesecurity.company for AI agents and non-JavaScript clients. > Short index: /llms.txt · Sitemap: /sitemap.xml > All content below is sourced from the live pages. Prices and claims are only those published on the site. ## Company facts - Legal/brand name: The Security Company ("TSC") - Positioning: senior-only cybersecurity services for growing companies — offensive testing, vCISO leadership, 24/7 managed defense and compliance outcomes (ISO 27001, SOC 2, NIS2, DORA, GDPR) - Address: Narva mnt 5, 10117 Tallinn, Estonia - Email: office@thesecurity.company (response within 24 hours) - Phone: +382 69 010 396 - Book an intro call (15–30 minutes, no obligation): https://cal.com/dzakula/quick-chat - Business hours: Mon–Fri 09:00–18:00 CET; incident response team available 24/7 - Founder & CEO: Branko Džakula — 15 years of global security experience, founder of Montenegro's first cybersecurity academy and of Skenify, co-founder of Secfix, former CISO - Team/track record figures published on the site: 35+ experts, 250+ clients, 450+ projects, 1800+ people trained - Certifications held by staff: CISM, OSWE, OSCE, OSCP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, DORA Lead Manager, NIS2 Lead Implementer, ISC2 - Company posture: ISO 27001:2022 certified, GDPR compliant (TSC does not claim SOC 2 certification for itself; SOC 2 is delivered as a service to clients) ## Commercial anchors - Subscriptions from €5/user/month (annual commitment, billed monthly; priced to team size, no hidden costs) - vCISO guidance is included in every TSC subscription — quarterly strategy review on Core, 2 hrs/month on Managed, 4 hrs/month on Complete; dedicated 10–20 hr retainers from €850/mo - Penetration testing includes free retesting for 6 months (fixes validated at no additional cost) - Pentest subscription plans save up to 30% compared to individual assessments - Everything else is quote-based, scoped to the engagement — https://thesecurity.company/contact --- ## / — Home Title: The Security Company — Expert Cybersecurity Services Description: Senior-only cybersecurity for growing companies: vCISO, penetration testing, 24/7 managed defense and compliance outcomes — ISO 27001, SOC 2, NIS2, DORA — in one subscription from €5/user/month. 360° Security as a Service. "Your security team — without the headcount, on one subscription, from day one." Offensive testing, vCISO leadership and 24/7 managed defense for growing companies — senior experts only, built to deliver ISO 27001, SOC 2, NIS2 and DORA outcomes. Trust strip: ISO 27001:2022 certified · GDPR compliant · 24/7 incident response. Trusted by growing companies across the EU and US (clients include Toptal, Fresenius, Air Serbia, Kpler). Everything Security, Under One Roof — six pillars: Offensive Security, Defensive Security, Security Management, Security Auditing, Security Academy, Security Research. All available under one monthly subscription. AI + Human Powered Security as a Service: identity threat detection, endpoint security, email protection, cloud data protection. Why choose us: we get to know the real you; we hit all the marks. Core values: Transparency, Quality, Continuous Improvement, Integrity. --- ## /services — Services Title: Cybersecurity Services — TSC Description: End-to-end cybersecurity: vCISO, pentesting, vulnerability assessments, phishing simulations, SOC-as-a-Service and security auditing. Comprehensive security solutions — from virtual CISO services to penetration testing, end-to-end cybersecurity that scales with your business. - vCISO (Security Management): risk assessment, security roadmap & governance, managed GRC, security operations support. Included in every TSC subscription — up to 4 hrs/month on Complete; dedicated 10–20 hr retainers from €850/mo. - Penetration Testing (Offensive Security): web app & API testing, network pentesting, cloud security reviews, mobile app testing. Pricing based on frequency — custom quote. - Vulnerability Assessments (Offensive Security): network scanning, web app assessment, cloud configuration analysis, risk prioritization. Pricing based on frequency and scope. - Phishing Simulations (Offensive Security): customized campaigns, multiple attack vectors, real-time reporting, automated training. Pricing varies by organization size and campaign frequency. - SOC-as-a-Service (Defensive Security): 24/7 threat monitoring & IR, managed EDR/XDR, threat intel & behavioral analytics, SIEM & log management. Subscriptions from €5/user/month. - Security Auditing (Security Management): ISO 27001 certification audits, SOC 2 Type I & II, DORA & NIS2 compliance, gap analysis & readiness. Scope-based pricing. - Security Research (Offensive Security): zero-day & vulnerability research, threat intelligence & actor profiling, OSINT & corporate espionage investigations, AI security research. Quote-based. Closing CTA: tell us where you are and where you need to be; we design a tailored security program around your risk profile and compliance goals — no bloat. --- ## /services/vciso — Virtual CISO Title: vCISO — Virtual CISO Services | TSC Description: Executive-level security leadership without the full-time cost. Strategic vCISO guidance for growing companies. Security guidance without the overhead: experienced security professionals without a full-time hire. No noise, no fluff — consistent support focused on what matters. How it works: 1) Start with risk. 2) Plan what's next. 3) Stick around and help. Coverage areas: compliance & risk, training, security reviews, governance, technical advice, documentation, incident support, custom needs. Pricing model — simple, honest, flexible: vCISO guidance is included in every TSC subscription (quarterly review on Core, 2 hrs/month on Managed, 4 hrs/month on Complete); dedicated retainers are €850/mo for 10 hrs and €1,500/mo for 20 hrs. Included: assessment & roadmap, continuous GRC monitoring, regular review meetings. Additional hours or custom plans on request. --- ## /services/penetration-testing — Penetration Testing Title: Penetration Testing Services | TSC Description: Find vulnerabilities before attackers do. Application, network and infrastructure penetration testing by certified experts. OSCP-certified experts run real-world attack simulations to find security gaps before attackers exploit them. Process: planning & scoping → information gathering & vulnerability detection → exploitation & analysis → reporting & remediation support. Coverage (all included): web app & API testing, network pentesting, cloud security reviews, mobile app testing, phishing simulations, source code review, continuous vulnerability scanning, free retesting for 6 months. Why TSC: manual expert testing; compliance-ready reporting (SOC 2, PCI-DSS, HIPAA, ISO 27001, NIST); detailed reports; 24/7 direct communication via Slack or MS Teams. Pricing: one-time assessment (scope-based quote, includes free retesting for 6 months) or subscription plans (quarterly/monthly assessments, continuous monitoring, priority support, dedicated advisor — save up to 30%). --- ## /services/vulnerability-assessment — Vulnerability Assessment Title: Vulnerability Assessment Services | TSC Description: Continuous and one-off vulnerability assessments to identify, prioritize and remediate security weaknesses. Comprehensive vulnerability scanning and assessment across the entire digital landscape. Process: discovery → scanning → analysis → remediation. Coverage: network security, web applications, cloud infrastructure, systems & endpoints. Pricing: included with a Skenify subscription — unlimited scans, continuous asset discovery, remediation guidance, risk prioritization, compliance mapping, expert support. Standalone assessments are quoted on request. --- ## /services/phishing-simulations — Phishing Simulations Title: Phishing Simulations & Awareness Training | TSC Description: Realistic phishing simulations across email, SMS and voice with automated just-in-time training. Measure and harden your human security layer. Strengthen the human firewall with realistic simulations and targeted awareness training. Process: campaign planning → multiple attack vectors → real-time monitoring → automated training → detailed reporting. Coverage: email, SMS and voice phishing, customized templates, real-time analytics, targeted executive campaigns, dedicated security consultant. Included with a Skenify subscription; standalone campaigns quoted on request. --- ## /services/security-operations-center — SOC-as-a-Service Title: SOC-as-a-Service — 24/7 Threat Monitoring | TSC Description: Enterprise-grade Security Operations Center delivered as a service. 24/7 monitoring, detection and incident response. AI + human powered monitoring, detection, response and protection. Centralize the entire cybersecurity program in one portal, powered by an elite team of security engineers and vCISO consultants. Nine capabilities: identity threat detection & response (ITDR), endpoint security (EDR & managed AV), email protection, cloud data protection (DLP), security awareness training, phishing simulations, secure browsing, external footprint (ASM), dark web monitoring. Implementation: integrate your environment → automatic configuration → protected in minutes. Pricing — see /pricing for the full published grid. Three per-user tiers, annual commitment billed monthly: - Core — €5/user/month (minimum 25 users, €125/mo floor): full security platform (external footprint + dark-web monitoring, email security, endpoint monitoring agent, cloud data protection, secure browsing, cloud directory posture), security awareness training + phishing simulations, monthly security report, EU/US/AU data residency, quarterly vCISO strategy review, Slack/Teams support (business hours). - Managed — €12/user/month (minimum 25 users, €300/mo floor) — recommended: everything in Core plus 24/7 Managed Detection & Response, SentinelOne EDR, automated remediations, remote incident response, vCISO advisory 2 hrs/month, 24/7 priority Slack/Teams support. - Complete — €19/user/month (minimum 50 users, €950/mo floor): everything in Managed plus Secfix compliance automation (ISO 27001, SOC 2, GDPR, NIS2, DORA, TISAX), annual internal compliance audit, annual manual penetration test (free retesting for 6 months), vCISO advisory 4 hrs/month, dedicated customer success manager. Volume discounts: 5% at 50–100 users, 10% at 101–500 users, custom pricing above 500 users. Fixed-price add-ons (any tier): vCISO Plus 10 hrs/mo dedicated €850/mo · vCISO Pro 20 hrs/mo dedicated €1,500/mo · Annual pentest €375/mo (€4,500/yr) · Quarterly pentest program €1,150/mo · Red team exercise (annual) €500/mo · Dedicated CSM €500/mo (included in Complete). --- ## /services/security-auditing — Security Auditing Title: Security Auditing — ISO 27001 & SOC 2 | TSC Description: Compliance-aligned security audits for ISO 27001, SOC 2 and more. Practical guidance, clear reports. Internal and external audits for your security compliance program, with certified auditors. Frameworks: ISO 27001, SOC 2 Type I & II, DORA & NIS2, GDPR. Services: gap analysis, control testing & validation, documentation review, certification support. Process: assessment planning → documentation review → control testing → certification support. Scope factors: organization size and complexity, number of systems in scope, framework requirements, maturity level. Quote-based. --- ## /services/security-research — Security Research Title: Security Research Services | TSC Description: Custom security research, threat intelligence and vulnerability discovery for organizations facing advanced threats. Services: security source code review, threat intelligence, corporate espionage investigation, OSINT investigations, AI security research, vulnerability research. Process: scope definition → deep research → documentation → reporting & support. Coverage: zero-day research, threat intelligence, investigation services, OSINT & intelligence. Quote-based, scoped to research objectives. --- ## /products — Products Title: Products — TSC Description: Skenify and Secfix — technology that automates, detects, protects and teaches. - Skenify: AI-powered security testing. AI agents simulate attacks and continuously detect vulnerabilities, 24/7. - Secfix: compliance automation platform. Multi-framework compliance with automated evidence collection — certified in weeks, not months. ## /skenify — Skenify Title: Skenify — AI Security Team Working 24/7 An AI team working 24/7 to simulate cyber attacks, detect vulnerabilities, discover assets and assess risks — specialized AI agents that work like a real security team. In-house product. Demo via https://cal.com/dzakula/quick-chat; trial at app.skenify.io. ## /secfix — Secfix Title: Secfix — Compliance Automation | TSC Compliance without the chaos, in weeks — ISO 27001, GDPR, NIS2, DORA, ISO 42001, TISAX. Secfix is our compliance-automation partner platform, delivered and supported in partnership with The Security Company. --- ## /case-studies — Case Studies Title: Case Studies — TSC Client success stories, results and outcomes. Quotes published with client permission. 1. Minax Inc. — /case-studies/azure-security-assessment-iso-27001-minax — SaaS / minerals & mining, Canada, 4 employees. Compliance advisory. Needed an Azure and Power Platform security assessment plus ISO 27001 readiness with no prior formal audit. Outcome: prepared for successful ISO 27001 certification and passed external customer assessments. "We needed a security partner who understood both the Azure ecosystem and the compliance landscape…" — CEO, Minax Inc. 2. Syntracts, Inc. — /case-studies/virtual-ciso-generative-ai-legal-syntracts — legal tech, US, 8 employees. vCISO. Generative-AI legal platform needing security leadership across on-prem and SaaS deployments. Outcome: security governance framework, threat models for both deployment models, confident enterprise engagement. "As a legal AI platform, our clients demand the highest standards of data protection…" — Co-founder, Syntracts, Inc. 3. FIRMSconsulting LLC — /case-studies/third-party-ai-security-audit-firmsconsulting — education/consulting, Los Angeles, <10 employees. Security audit of a third-party AI chatbot against SOC 2, HIPAA and GDPR expectations plus data-pipeline risk. Outcome: independent assessment, go/no-go recommendation, privacy risk findings. "We needed to ensure our AI-powered knowledge platform met the same security and privacy standards…" — Managing Partner, FIRMSconsulting LLC. 4. Milk and Honey Films, Inc. — /case-studies/post-breach-security-hardening-milk-honey-films — film & TV, US, 20 employees. Incident response during an active breach: invoice fraud, email server compromise, ransom threat. Outcome: breach contained, infrastructure hardened, staff trained, ongoing monitoring. "We were actively under attack — invoices were being intercepted, payments redirected…" — Managing Director, Milk and Honey Films, Inc. 5. Humata.ai (Tilda Technologies, Inc.) — /case-studies/soc2-type-ii-completion-humata-ai — AI/technology, US, 6 employees. SOC 2 Type II stalled at 60% with no in-house compliance expertise. Outcome: driven to full audit-readiness, IT controls configured, TSC acted as primary auditor contact. "We were more than halfway through SOC 2 Type II but didn't have the compliance expertise to cross the finish line…" — Co-founder, Humata.ai. 6. Stellic Inc. — /case-studies/soc2-compliance-program-stellic — education SaaS, US, 30 employees, serving universities including UChicago and Ohio State. Needed a full SOC 2 program from scratch with no IT staff. Outcome: complete compliance program, gap analysis, training, internal audit framework, configured IT systems. "Our platform serves major universities handling sensitive student data…" — Head of Operations, Stellic Inc. --- ## Industries - /industries/fintech — Cybersecurity for fintech: DORA compliance, PCI DSS readiness, fraud prevention, secure transactions. Challenges: payment card fraud, API security vulnerabilities, third-party risk, ransomware. Regulations: DORA, NIS2, PCI DSS, GDPR, SOX, ISO 27001. - /industries/healthcare — Protecting healthcare: HIPAA compliance, patient data security, medical device protection, NIS2 readiness. Challenges: PHI protection, medical device security, ransomware targeting, legacy system vulnerabilities. Regulations: HIPAA, HITECH, NIS2, GDPR, ISO 27001, ISO 27799. - /industries/transport — Securing transport: NIS2 compliance, OT/IT security, supply chain protection, critical infrastructure defense. Challenges: OT/IT convergence, supply chain attacks, critical infrastructure targeting, connected vehicle security. Regulations: NIS2, CER Directive, GDPR, ISO 27001, IEC 62443, TSA directives. - /industries/education — Education security: FERPA compliance, student data protection, research security, campus cybersecurity. Challenges: student data protection, research data security, remote learning risks, phishing and social engineering. Regulations: FERPA, COPPA, GDPR, NIS2, ISO 27001, state privacy laws. --- ## /about — About Title: About TSC — Cybersecurity Experts Security expertise you can trust. Remote-first company built on 15 years of security experience, with a transparency-first culture. Values: Transparency (no bullshit), Quality (we work free until the standard is met), Continuous Improvement (1% better every day), Integrity. How we work: remote by design, strict vetting process, benefits shared with everyone (cost savings become higher pay and lower prices). Founder: Branko Džakula, Founder & CEO. Companies founded: Skenify, Secfix, Uniquely, iPets. ## /academy — Academy Title: TSC Academy — Cybersecurity Training Description: Hands-on cybersecurity training tracks with expert mentorship and real career outcomes. Paths: security analyst, penetration tester, SOC analyst, threat hunter. Hands-on training, mentorship and real-world experience. Enrollment via the on-page form. ## /partners — Partners Title: Partners — TSC Referral partner program: you introduce us to a lead, we close the deal, you get paid. What you get: 15% recurring commission, fast payout, referral kit, no certifications or quotas, dedicated support, monthly updates. What we expect: submit leads via the portal, leads new to TSC, basic cybersecurity understanding, professional relationship. Highlights: proven platform, EU/US data residency, recurring revenue. Partner Portal access within 2 business days of applying. Partner collateral one-pager: /partners/collateral ## /trust-center — Trust Center Title: Trust Center — TSC Foundations: security operations, GDPR compliance, ISO 27001:2022 certification, penetration testing, continuous monitoring, data encryption (AES-256 at rest, TLS 1.3 in transit). Data protection: data security, privacy controls, global compliance. Service delivery: secure development, access controls, operational monitoring. Enterprise security: advanced threat protection, compliance framework support (NIST, COBIT, ISO 27001), incident response. Available on request: security whitepaper, compliance reports, penetration test executive summaries. ## /blog — Blog Talks, interviews and articles from The Security Company's founder, plus TSC updates and advisories. The founder also publishes his full portfolio at https://dzakula.com. ## /contact — Contact Title: Contact The Security Company Book an intro call: https://cal.com/dzakula/quick-chat (15–30 minutes, no obligation). How an engagement starts: 1) Intro call — we listen first: your risks, goals and compliance deadlines. 2) Assessment & proposal — a scoped plan with clear pricing, within days. 3) Kickoff — your senior team starts, with a shared Slack or Teams channel from day one. Email: office@thesecurity.company (general inquiries, response within 24 hours). Callback requests via the on-page form. Business hours: Mon–Fri 09:00–18:00 CET; incident response available 24/7. ## Legal and policy pages - /terms — Terms and conditions, including data retention: client data deleted within 30 days of contract termination; penetration test and vulnerability reports retained up to 10 years unless deletion is requested. - /privacy — Privacy policy - /imprint — Imprint / company details - /accessibility — Accessibility statement - /security-disclosure — Responsible disclosure policy (see also /.well-known/security.txt)