ONGYO Start a conversation

Independent security consultingCroatia / EU

Build trust into every layer.

Senior security leadership and hands-on assurance for startups, technology companies and regulated teams.

ONGYO / SECURITY SYSTEM AVAILABLE
RISK
TO
CONTROL
ASSESSBUILDOPERATE
20+years in information security
End-to-endsecurity, compliance and delivery
Cloud-nativeAWS, GCP and Kubernetes
Board-readyclear risk and assurance reporting

01 / CAPABILITIES

Security work that moves the business forward.

Focused engagements, embedded leadership or ongoing advisory support—from first assessment to operating evidence.

01

Security leadership

Fractional security leadership, strategy, risk ownership, board reporting and practical security programmes aligned with business goals.

  • Fractional CISO
  • Risk register
  • Security roadmap
02

ISO 27001 & SOC 2

Readiness, gap assessment, policy and control design, evidence preparation, remediation and support through external audits.

  • ISMS
  • SOC 2 Type 2
  • Audit support
03

Cloud & Kubernetes security

Architecture and posture reviews across AWS, GCP, Kubernetes and hybrid environments, including IAM, hardening, secrets and resilience.

  • AWS
  • GCP
  • Kubernetes
04

DevSecOps & supply chain

Secure CI/CD, SAST, SCA, DAST, container scanning, vulnerability management and SLSA-aligned software supply-chain controls.

  • SLSA
  • CI/CD
  • Terraform
05

Threat modelling & architecture

Risk-led reviews of products, platforms and critical changes, with clear findings, practical design guidance and prioritised remediation.

  • Threat modelling
  • Secure design
  • Code review
06

Incident readiness & resilience

Incident response planning, SIRT leadership, ransomware defence, backup strategy, business continuity and disaster-recovery exercises.

  • IR plans
  • Anti-ransomware
  • BC / DR
07

Security assurance

Technical, network and application assessments, vulnerability triage, vendor due diligence, regulated-customer assurance and IT audit.

  • Assessments
  • Third-party risk
  • IT audit
08

AI governance

Practical governance for AI-enabled products and workflows, including EU AI Act readiness, risk controls and secure AI-assisted delivery.

  • EU AI Act
  • AI risk
  • Governance
09

Blockchain infrastructure

Security and operational assurance for blockchain infrastructure, private networks, cloud deployments and delivery pipelines.

  • Infrastructure
  • Private networks
  • Web3 delivery

02 / APPROACH

Senior judgement. Practical delivery.

No theatre, oversized frameworks or opaque reports. The work is shaped around the risk, maturity and operating reality of your organisation.

  1. 01

    Assess

    Establish the current state, material risks and the shortest credible path forward.

  2. 02

    Build

    Design the policies, controls, architecture and delivery practices the business needs.

  3. 03

    Operate

    Provide senior ownership, remediation guidance and evidence through audits and change.

03 / NEXT STEP

Bring the hard security problem.

Share the context, the constraint and the decision you need to make. You will receive a direct response—not a sales sequence.

info@ongyo.net