Security that fits your budget and your calendar.
Real security posture improvement within your time and budget constraints. Even within a few person-days we can cover what has the biggest impact on risk. NIS2-aware, certified, available.
Free 30-min audit View services
Who we work with
We solve real problems, not checkboxes. We work best with these three types of clients.
IT manager at an SMB
You're alone or have 1–2 people. Security demands grow, capacity doesn't. We become an extension of your team — without you having to hire a full-time senior.
Owner without an IT team
Outsourced IT support doesn't cover security. You need a partner who tells you in plain language what to handle now, what can wait, and what isn't your problem.
Compliance officer
NIS2, ISO 27001, GDPR. You need the technical side actually delivered — not just on paper. We do implementation, not creative audits.
What we do
Five areas where we can move the needle. Even within a few person-days we can cover what has the biggest impact on risk.
GAP analysis & roadmap
Quick state assessment, risk prioritization, action plan with effort estimates.
Details →Monitoring & detection
SIEM/ELK integration, detection rule fine-tuning, alerts and reports that actually mean something.
Details →Vulnerability management
Internal and external scans, impact-based prioritization, mitigation plan and continuous reporting.
Details →vCISO
External CISO on a part-time basis. Strategic security leadership for companies that don't need a full-time hire.
Details →Awareness & training
Phishing campaigns, training, newsletters. The weakest link sits between the chair and the keyboard — we address it deliberately.
Details →Flagship: CISO-as-a-Service
We lead security for a company that needs more than outsourced IT support but can't afford or doesn't need a full-time CISO. Strategic guidance, prioritization, project leadership — currently driving an IAM transformation. Anonymized reference available on serious inquiry.
View all cases →Certifications and competencies
The people behind Sigilo have real experience from corporate environments. We're not freelancers who once read OWASP.
30 minutes is enough to see where to go.
Free initial call. No commitment, no presentations, no "we'll send a quote within a week". After 30 minutes you'll know whether it makes sense to continue — and if so, at what scope.