Defense in Depth
Layered controls at every boundary. L2/L3 segmentation, identity-bound device trust and per-application MFA. One failure stops at the layer it happens in.
Zero Trust segmentation, IAM on Keycloak, EntraID or AD, and a PKI you can still operate in ten years. Governance mapped to NIST CSF, ISO 27001 and SABSA.
Architecture decisions compound. Segmentation, identity-first design and a PKI built to last a decade all pull in the same direction.
Layered controls at every boundary. L2/L3 segmentation, identity-bound device trust and per-application MFA. One failure stops at the layer it happens in.
Modern identity and access management with zero trust principles
Architecture that grows with your business while maintaining security
Passwordless authentication and risk-based MFA. Users sign in faster and IT handles fewer password resets.
Architecture, identity and PKI work, from the design through to running it
Every design decision is mapped to NIST CSF, ISO 27001, CIS Controls or SABSA. The mapping is written down while the design happens, so it is auditable from day one.
Risk-based posture across the five core functions: identify, protect, detect, respond and recover.
Global certification baseline for information-security management systems and continuous-improvement controls.
Reference architecture for identity-centric, deny-by-default access enforcement across every resource.
Business-driven security-architecture methodology spanning context, conceptual, logical, physical, and component layers.
Enterprise-architecture framework with scope, governance, and the Architecture Development Method (ADM).
Application-security testing guides and verification standards. ASVS for requirements, the Top 10 for prevalence, SAMM for maturity.
Straight answers to what clients ask us most.
Zero Trust is a security model in which network location grants no trust. Access to each resource is authorised separately, on a per-session basis, by a policy that takes in identity, device posture and the context of the request. NIST published the reference architecture in August 2020 as SP 800-207. It sets out seven tenets and three logical components. The policy engine makes the decision, the policy administrator carries it out, and the policy enforcement point actually passes or blocks the traffic. In practice the VPN and the internal network stop being the trust boundary, and verified identity and device state take over that role. The document is free to download at csrc.nist.gov.
Identity and access management (IAM) covers the lifecycle of an account from creation to removal, and the rules by which access is granted. It includes single sign-on, multi-factor authentication, joiner-mover-leaver processes with automated offboarding, PAM for privileged accounts and risk-based conditional access. The NIS2 Directive names multi-factor authentication outright in Article 21(2)(j), which makes it a statutory requirement. For factors we recommend FIDO2 or WebAuthn, because the key is bound to the origin and a phishing page cannot use it. SMS codes and push prompts have no such property. We work with Microsoft Entra ID, Keycloak and classic Active Directory. The directive text is on EUR-Lex.
PKI is the system that issues, renews and revokes the certificates behind TLS, mTLS, device authentication and code signing. Manual management is running out of road because certificate lifetimes keep shrinking. In April 2025 the CA/Browser Forum adopted a schedule under which the maximum validity of a public TLS certificate is 200 days from 15 March 2026, 100 days from March 2027 and 47 days from March 2029. By 2029 a single service needs roughly eight renewals a year. Without automation through ACME or cert-manager that ends in a production outage. For a private CA, protecting the root key in an HSM belongs to the same job. Ballot SC-081v3 is published at cabforum.org.
A move to Zero Trust is not a project with a deadline, it is a roadmap. We start with an audit and a target-state design, which takes 4 to 8 weeks. Then we go layer by layer through identity, device posture, microsegmentation, data and applications. First measurable results usually land inside three months, full coverage in 12 to 24 months.
Yes, and it is visible in the text. Article 21(2) of NIS2 lists ten measures and most of them are architectural. Access control and asset management sit in point (i), cryptography in point (h), supply chain security in point (d) and multi-factor authentication in point (j). In the Czech Republic the same content is spelled out in the decrees to Act No. 264/2025 Coll., separately for the higher and lower obligation regimes. We therefore structure the architecture deliverable around those measures, so an auditor finds a concrete design decision against each one. The directive is on EUR-Lex, the Czech legislation on zakonyprolidi.cz.
Don't bolt security on as an afterthought. Our architects design segmentation, identity and PKI into the build itself.
One operating model across every discipline. See how the rest of the Kybit portfolio fits alongside this service.
We watch your systems around the clock and stop an attack before it turns into downtime or a data breach. Evidence for NIS2, DORA and ZoKB audits arrives finished, ready to hand to the auditor.
Designing, building, and automating modern IT infrastructure using IaC (Terraform, Ansible).
We deploy and tune SIEM, XDR and SOAR. Detection content ships as code, mapped to MITRE ATT&CK and reviewed quarterly.
Finding vulnerabilities before attackers do via Penetration Testing, Vulnerability Management, and Audits.
Expert-level support for your SOC, including Threat Hunting, Incident Response and CTI.
Embed our certified IT and Cybersecurity experts directly into your team for your long-term projects.