Information security
In this area, our focus is not only on complying with GDPR requirements, but also on comprehensively implementing an information security management system in accordance with ISO/IEC 27001:2022. This standard outlines the requirements for effectively managing and protecting information by implementing and maintaining an ISMS (Information Security Management System) .
Cybersecurity
Cybersecurity is closely linked to applicable legislation, specifically Act No. 69/2018 Coll. on Cybersecurity in Slovakia and Act No. 264/2025 Coll., on Cybersecurity in the Czech Republic.
In accordance with applicable cybersecurity legislation, we offer the following services:
Implementation of cybersecurity requirements
Security consulting
Cybersecurity audits
Legislative obligations relating to cybersecurity
Slovak Republic
In Slovakia, cybersecurity is governed by Act No. 69/2018 Coll. on Cybersecurity, as amended. The requirements of the NIS2 Directive were transposed into the Act primarily by Amendment No. 366/2024 Coll., effective from 1 January 2025.
- The Act is based primarily on the principle of self-identification of regulated entities.
- An entity that meets the conditions under Sections 17 or 18 of the Act, together with the relevant annexes, identifies itself as an operator of an essential service or an operator of a critical essential service.
- If an entity identifies itself as regulated, it must notify the Slovak National Security Authority (NBÚ) within the statutory period and is subsequently entered in the relevant register.
- Regulated entities must implement and maintain appropriate security measures and comply with cybersecurity incident reporting obligations.
Czech Republic
Since 1 November 2025, cybersecurity in the Czech Republic has been governed by Act No. 264/2025 Coll., on Cybersecurity, which implements the requirements of the NIS2 Directive.
- The Act uses regulated service provider as a key concept.
- Regulated service providers are classified, according to statutory criteria, under a regime of higher or lower obligations.
- The scope of security measures, risk management and other obligations depends on the applicable regime.
- Regulated entities are also subject to cybersecurity incident notification and reporting obligations.
European legislation
- Directive (EU) 2022/2555 (NIS2) – establishes measures for a high common level of cybersecurity across the EU and repealed the previous Directive (EU) 2016/1148 (NIS).
- Regulation (EU) 2019/881 (Cybersecurity Act) – strengthens the role of ENISA and establishes an EU framework for cybersecurity certification.
