Book a consultation
NIS2 enforcement is live across the EU

End-to-end compliance and cybersecurity for EU organizations, delivered by consultants who've actually run security operations.

Button Text
Button Text

NIS2 compliance, practical and
defensible

Compliance overview
Example Client
Regulatory scope
100 %
Gap analysis
78 %
Remediation
54 %
Audit prep
24 %
Certified · CISM · CISSP · ISO 27001 Lead Auditor
INTERACTIVE - 30 SECONDS

Are you in scope for NIS2 / ZoKB?

Most Czech and EU SMEs aren't sure. Answer three questions for an instant, indicative read on your likely status, and what it puts on the line.

Indicative only, not legal advice. We confirm your exact obligations in a free consultation.
01 / YOUR SECTOR
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
02 / HEADCOUNT
1-49
50-249
250+
03 / ANNUAL TURNOVER
≤ €10M
€10-50M
> €50M
INDICATIVE RESULT
Likely an ESSENTIAL entity

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

the fines line
TRUSTED ACROSS REGULATED SECTORS
Financial services
/
Financial services
/
Energy & utilities
/
Healthcare
/
Telecommunications
/
Digital infrastructure
01 - THE CHALLENGE

Cyber compliance has outpaced most organizations’ playbooks

€10M

Maximum NIS2 fines for essential entities, or 2% of global turnover

24h

Mandatory early-warning window for significant incidents

18

Sectors now in scope, from healthcare to digital infrastructure

If you’re in scope, that means overlapping obligations, hard deadlines, and, for the first time, personal liability landing on your management. Spreadsheets and good intentions won’t survive an inspection

02 - WHAT WE COVER

Every framework you're accountable to

01
NIS2 Directive
EU baseline
02
National Cybersecurity Act (ZoKB / ZKB)
CZ transposition
03
ISO/IEC 27001
ISMS certification
04
DORA
Financial sector
05
Related regulatory and audit requirements
Sector-specific
03 - METHODOLOGY

Five steps from scoping to audit-ready

A clear path, with a concrete deliverable in your hands at every stage

01

Regulatory scoping

Are you in scope, and at which obligation tier?

DELIVERABLE
Defensible scope statement
02

Gap analysis

Your posture benchmarked against NIS2 and ZoKB

DELIVERABLE
Maturity baseline and gap report
03

Solution plan

A roadmap to close every gap, scoped and costed

DELIVERABLE
Costed roadmap and budget
04

Deployment

ISMS, controls, incident response and continuity, live

DELIVERABLE
Production-ready controls
05

Audit readiness

Ready for NÚKIB inspection, audits and ISO 27001

DELIVERABLE
Inspection-ready governance
04 - TECHNICAL SERVICES

Eight services, one partner

NIS2 Gap Analysis

Readiness mapped to the directive, with a prioritized remediation roadmap

Risk, Governance and Compliance

Operable policies and controls, aligned to ISO 27001, NIS2, DORA, GDPR

SOC-as-a-Service (24/7)

Analyst-led monitoring and triage across endpoint, network, cloud and identity

IR, Detection and Threat Hunting

Incident response, custom detections, threat hunting and purple teaming

Virtual CISO (vCISO)

Fractional security leadership, from board reporting to team mentoring

Penetration Testing

Real-world attack simulation with proof, impact rating and free retest

SIEM Engineering and Maintenance

Sentinel, Splunk or Elastic, architected, tuned and cost-optimized

XDR Service

Correlated detection and response across endpoint, identity, cloud and email

05 - CISO AS A SERVICE

No internal team? We become yours

A fractional Cybersecurity Manager who owns governance, risk, and NIS2 oversight on your behalf: accountable, embedded, and reporting to your board

Security governance
Risk management
Executive-level communication
Board and regulator reporting
06 - ABOUT US

Practitioner-led consulting

AVA Cyber was founded in 2026 by cybersecurity professionals with deep experience across security operations, incident response, compliance, and governance. Working alongside organizations navigating complex security requirements, we kept seeing the same gap: regulatory guidance on one side, practical implementation on the other, and very little bridging the two.

Our approach is built on operational experience. We have worked inside Security Operations Centres, managed real-world incidents, and supported organizations through audits and compliance assessments. That grounding lets us give advice that is not only aligned with NIS2, ISO 27001, and related frameworks, but also practical, proportionate, and tied to business objectives.

Today, AVA Cyber helps organizations strengthen their cyber resilience by combining technical expertise with regulatory knowledge. We believe compliance should be the outcome of effective security, not the objective itself.

The company is led by Ivanka Židková and Valentina Klemperová. As one of the few women-led cybersecurity consultancies in the Czech Republic, we are proud to contribute to a more diverse industry while holding to the highest standards of technical excellence.

Ivanka Židková

Chief Executive Officer

Leads AVA Cyber’s strategy and client engagements, keeping compliance work grounded in real business outcomes.

LinkedIn →

Ing. Valentina Klemperová, MBA

Head of GRC · CISSP · CISM · ISO 27001 Auditor · DPO

People-focused GRC leader who builds and scales governance, risk, and information-security functions, pairing strategic leadership with hands-on execution.

LinkedIn →
IR
SOC
PT
+5

Specialist consultant network

Incident response · SOC · Pen testing

A trusted bench of consultants across incident response, SOC, penetration testing, and governance, brought in to match each engagement.

BACKGROUNDS
Financial services
Telecommunications
Utilities and manufacturing
Enterprise IT
CERTIFICATIONS
CISM
CISSP
ISO 27001 Lead Auditor
Advanced IR & SOC
BASE
Prague, CZ
Serving the EU (EN & CZ)
On-site or remote delivery
FAQ

Questions buyers ask first

Does NIS2 / ZoKB actually apply to my company?
+

It depends on your sector, headcount, and turnover. Our 30-second scope check tells you if you are likely in scope as an essential or important entity. To see where you stand across governance, risk, and incident handling, try our NIS2 Readiness Check for a full score and area breakdown.

We’re a Czech SME. When do we actually have to comply?
+

NIS2 is transposed into Czech law through the new Cybersecurity Act (ZoKB). In-scope organizations have registration duties and then phased deadlines to put security measures and incident reporting in place. We map your specific obligations and dates to your situation, so you know exactly what is due when.

What does it cost, and how long does it take?
+

For a typical SME, 3-6 months from scoping to audit-ready, depending on your starting maturity. The free readiness consultation gives you an organization-specific timeline and budget before you commit to anything.

We have no security team. Can you just run it for us?
+

Yes. Through Cybersecurity Manager as a Service we act as your fractional CISO, owning governance, risk, and NIS2 oversight on your behalf and reporting to your management. Many SMEs use us instead of hiring a full-time security lead.

What do we actually walk away with?
+

Concrete artifacts at every stage: a scope statement, a gap report, a costed remediation roadmap, implemented controls with evidence, and inspection-ready documentation, not a slide deck.

Can you support a NÚKIB inspection or ISO 27001 audit?
+

Yes, audit readiness is core to what we do. We prepare your evidence, governance, and people for regulatory inspections, external audits, and certification, and we stay with you through them.

Start with a NIS2 Readiness Consultation

A short engagement with no commitment. Leave with a clear view of your regulatory exposure, immediate risks, and a realistic timeline.

Book a consultation
Evaluate regulatory exposure
Identify immediate risks
Outline next steps
Estimate effort and timeline
07 - CONTACT

Interested in how we can help your business?

Drop us a note, and we will be in touch.

* required fields
Thanks, message received.
We will get back to you within one business day.
Something went wrong. Please try again, or email us at info@ava-cyber.com