Penetration testing · NIS2 compliance · AI red teaming

Find your weak points before someone else does.

Penetration testing, configuration audits and AI red teaming - delivered to recognised methodologies, with manually validated findings and reporting ready for NIS2/KSC audits.

$identify red_panda.svg[ok]
CISSP OSCP · OSWP eWPTX ISO 27001 Clearances RP / NATO / EU HTB - AI red teaming
8+years in cybersecurity
20+services in the catalogue
5industry certifications
100%of engagements end with a retest
// services

Three pillars, one specialisation

From a one-off test to a continuous oversight programme - the catalogue spans more than twenty services across four areas.

// 04 - specialisation

AI / LLM red teaming

Robustness testing for models, agents and AI integrations: prompt injection, jailbreaks, data exfiltration through tools, security of MCP servers and RAG pipelines. Research background: a doctorate in progress on adversarial ML.

Prompt injection Jailbreaks MCP servers Agents & tool use RAG Adversarial ML
// compliance

Ready before the audit

The KSC (NIS2) Act has been in force since 3 April 2026. Self-identification duties and deadlines apply regardless of notification - and vulnerability identification is one of the required risk-management measures (Art. 21).

// 01 - registration
3.10.2026
Entry in the register of essential and important entities.
// 02 - implementation
3.04.2027
Risk-management measures (Art. 21) - including vulnerability management.
// 03 - audit
3.04.2028
First mandatory security audit and the start of full supervision.
NIS2 KSC DORA ISO 27001 OWASP CIS Benchmarks
// why securember

Eight years in offensive IT. On your side.

Hundreds of systems tested - from web applications and APIs, through on-prem and multi-cloud infrastructure, to AI models. Every engagement is delivered personally by a certified specialist (CISSP, OSCP, eWPTX) holding Polish, NATO and EU security clearances, with a doctorate in progress on adversarial ML - no subcontractors, no middlemen. The same person who runs the test signs the report and can defend it in front of auditors and the board.

A practitioner, not a robot

Testing is led by a certified specialist - vulnerabilities chained into attack paths, not a scanner printout.

Manual validation

Every finding confirmed by hand. Reports free of false-positive noise.

Audit-ready reporting

CVSS prioritisation, a management summary and mapping to Art. 21 measures.

Research background

A doctorate in progress on adversarial ML and a specialisation in AI system security.

CISSP OSCP · OSWP ISO 27001 eWPTX HTB - AI red teaming Multi-cloud red teaming Doctorate in progress - adversarial ML Clearances RP / NATO / EU 8 years in cybersecurity
// contact

Initial consultation

An initial consultation establishes the scope of work, priorities and next steps.

// standard on every engagement
  • [x]Scope and authorisation agreed in writing
  • [x]Manual validation of every finding
  • [x]Report: CVSS, management summary, Art. 21 mapping
  • [x]Retest after remediation
  • [x]NDA and encrypted data handling
Direct contact
$ gpg --import securember.asc

For confidential correspondence, please use the public PGP key.

Download PGP key
Key fingerprint: BEEC FF3C 70DC 9314 7D15  24A3 0F12 DFE5 D484 1786