Security that protects without slowing you down

Pragmatic & built around your reality. Security and compliance consulting for startups, SMEs, and blockchain projects across the EU and UK.

Who I work with

Startups

Building their first security program, preparing for investor due diligence, or approaching certification

SMEs

Navigating NIS2, DORA, or the UK Cyber Security and Resilience Bill for the first time

Crypto projects

Preparing for MiCA, securing digital assets, or coordinating smart contract audits

Investors and acquirers

Evaluating a target's security posture before making a decision

Services

Frameworks and regulation

ISO 27001 NIST CSF CIS Controls NCSC CAF NIS2 DORA UK CSR Bill MiCA GDPR EU AI Act [coming soon]

Cybersecurity and compliance consulting for startups and SMEs

Security governance

Whether you're building your first security program or strengthening an existing one, I help you put the right foundations in place and prepare your team for what comes next.

  • Security posture assessment and gap analysis
  • Risk assessment, treatment, and risk register
  • Security program, policy, and governance development
  • Vendor and third-party risk management
  • Incident response planning and tabletop exercises
  • Security awareness and training
  • Security questionnaire support
  • Internal audit and certification preparation [coming soon]

Security due diligence

Independent security assessment for investment, acquisition, or partnership decisions. I evaluate the target's security maturity, risk exposure, and compliance posture so you know exactly what you're inheriting - delivered as a structured report.

What I assess:

  • Security program maturity
  • Incident history
  • Third-party dependencies
  • Data handling practices
  • Regulatory compliance

Regulatory compliance

A wave of new EU and UK regulation is creating security obligations that affect a growing range of organisations. I help you understand whether and how these regulations apply to you, assess what gaps exist, and build a practical path to meeting your obligations.

  • NIS2 compliance readiness
  • DORA readiness and ICT risk management
  • UK Cyber Security and Resilience Bill readiness
  • EU AI Act and ISO 42001 compliance [coming soon]

Ongoing advisory

You don't always need a full-time security hire - but you do need someone who knows your organisation. I work as a fractional security lead or standing advisor, a few days per month.

  • Ongoing risk management
  • Policy updates
  • Audit support
  • Security questions between larger engagements

For blockchain projects

Everything from my general practice - security governance, risk management, and compliance - combined with hands-on experience securing blockchain infrastructure and protecting high-value digital assets. If you're building in Web3, you're working with someone who understands both the technology and the EU regulatory landscape around it.

Regulatory compliance

MiCA is reshaping how crypto-asset service providers operate in the EU. I help projects understand where they stand, what category they fall into, and what operational foundations need to be in place before the legal application process begins.

  • MiCA applicability, licensing pathway, and operational readiness
  • Whitepaper compliance risk review

Security operations

Blockchain projects face security challenges that don't map neatly onto traditional frameworks. I help build the operational structures that account for them.

  • Smart contract audit coordination and governance
  • Key management and custody policy
  • Crypto-specific incident response planning
Nikola Schovanec, founder of CyberSchovka

About

Security, for me, started through the wires, not the paperwork. My early career was spent running security infrastructure for a global telco - hundreds of devices, real traffic, real consequences - before moving into technical presales, leading teams of security engineers, and the hands-on sysadmin work in between. That foundation is the reason I can tell the difference between a control that works and one that just looks reassuring on paper.

Since then I've built security in places that couldn't be more different. At an automotive group, that meant training mechanics and managers across every dealership - people who had never thought about information security and didn't particularly want to. At a blockchain startup, it meant being the person responsible when there were hundreds of millions in assets on the line and no playbook to follow. The common thread: security only works when it's built for the people who actually have to live with it.

These days a couple of things spark my interest: the wave of new EU and UK regulation that most companies aren't ready for, and AI governance - because organisations are adopting AI far faster than they're thinking about how to control it. I tend to show up early to these things. I was working in crypto security when the rules were still being made up; AI feels like the same moment.

Some of the work I'm proudest of never paid anything: teaching security basics through nonprofits, helping graduates figure out their next step, talks on everything from the dark web to the fundamentals.

Good security is invisible when it's working. My job is to build the kind that protects you without getting in your way.

Working remotely across the EU and UK markets.