Web & apps
Every vulnerability on the surface is a way in. OWASP Top 10, security headers and CSP, TLS configuration and the third-party supply chain.
Every claim about AI is backed by a test. Every risk by a concrete analysis.
Knowledge for free. We publish guides and checklists without a paywall or registration.
No sponsor, no conflict. We do not accept money from companies we evaluate.
Built on real audit findings, not slides from the internet.
Safe AI use in non-technical teamsPractical habits for safe AI use in marketing, HR, operations and finance.
AI and cybersecurity for leadershipA strategic framework for risks and their management by organisational leadership.
Data governance and the AI Act in practiceGDPR and the AI Act as an operational framework, including ready-to-use internal AI rules.
Secure LLM deployment in internal processesA threat model and security standard for deploying LLMs in internal processes.
AI red team, simulated attackA structured attack against a production deployment, with remediation measures and outcome verification.
Quarterly audit + continuityA quarterly audit, monthly briefing and continuity of prevention for regulated organisations.
We turn the programme into rules and habits that the organisation uses after the final workshop.
Non-technical teams practise safe prompting and handling sensitive data. Leadership addresses accountability and decision-making. Technical roles receive a process for threat modelling, testing and secure LLM deployment.
The output includes internal rules for AI use, attendance records and recommendations based on role and context of use. The organisation can then document how it ensures staff AI literacy under Article 4.
Follow-up coaching verifies what the team actually uses, where the rules fall short and what needs to change. The annual programme adds a quarterly audit and repeat training after changes to tools, people or processes.
It applies to every company that uses AI. The obligations target employers, not just developers.
Unacceptable-risk practices are banned and organisations must ensure AI literacy of staff working with AI (Article 4).
Obligations for providers of general-purpose AI models and the penalty framework take effect.
Transparency rules, including labelling requirements for selected AI content, and other generally applicable parts of the regulation take effect.
Following the political agreement on the AI Omnibus, obligations apply to stand-alone high-risk systems including biometrics, education and employment.
Obligations apply to high-risk AI embedded in regulated products such as robotics and industrial machinery.
We map how the team actually uses AI and where risks arise. Scope and pricing follow an initial consultation.
We build the training around real examples from your operations. From Foundation to Expert, in person and online.
After training, we measure what has taken hold. Follow-up coaching and internal AI rules that the team actually uses.
Websites, AI systems and data. Every finding includes evidence, severity and a remediation plan. Our training is built on these audits.
Every vulnerability on the surface is a way in. OWASP Top 10, security headers and CSP, TLS configuration and the third-party supply chain.
Prompt injection and jailbreak testing, RAG system security, risks in agentic loops, deepfakes and identity protection.
Injection vectors, authentication and access control, encryption at rest and in transit, and exposure of access credentials.
We found a WordPress plugin nobody had updated in two years. It provided access to customer orders, names, addresses and email addresses, without a single password.
The company’s internal system was accessible from the internet to anyone who knew the address. No restriction, no second factor. An open door to sensitive data for an attacker.
The domain had no email protection configured. Anyone could send an invoice in the company’s name with a changed account number, and the recipient would not spot the forgery.
Built on an auditable methodology. Every finding has evidence and a deadline, every fix is verified. No finding is closed blindly.
We do not accept money from companies we evaluate. We use the same methodology in our own audits that we teach. The institute is led by founder and director Zbyšek Chudoba.
CZECH ONLY
Articles and Czech-market pages (municipalities, the NIS2 self-test) are published in Czech only; see the blog.
Tell us what you need to cover, whether that is training for your team or an audit. We reply within two working days with a proposed next step. The first consultation is non binding and we price the work only once the scope is clear.