~/opensecurity $ whoami

opensecurity.cz

Independent cybersecurity consulting — vendor-neutral and open-source first. One accountable expert across architecture, incident response and governance.

Open source, open mind.

Available — incident response 24/7
// services

What I do

Full-lifecycle security — from designing defensible architecture to responding when something breaks, and proving compliance along the way.

architecture/

Security architecture

Zero-trust blueprints and hardening guides for on-prem and cloud environments, built around real adversary TTPs rather than checkbox compliance. Covers network, identity and workload layers.

  • Architecture review & threat modelling
  • Network segmentation & micro-segmentation design
  • Identity & access architecture (IAM/PAM/SSO)
  • Infrastructure hardening (OS, cloud, containers)
  • Security reference architecture documentation
incident/

Emergency incident handling

24/7 rapid DFIR at any stage — from first call to full recovery. Hands-on containment, eradication and root-cause analysis, with court-ready documentation and a lessons-learned report.

  • Initial triage, scoping & severity assessment
  • Containment, isolation & evidence preservation
  • Malware analysis & attacker eviction
  • Recovery planning & restoration guidance
  • Post-incident report with timeline & IOCs
forensics/

Forensic analysis

Rigorous evidence collection, preservation and analysis across host, network and cloud. Findings are documented to stand up to legal, regulatory and insurance scrutiny.

  • Disk, memory & volatile data acquisition
  • Malware reverse engineering & behavioural analysis
  • Network packet capture & traffic analysis
  • Cloud trail & log forensics (AWS, Azure, GCP)
  • Expert witness report preparation
grc/

Governance & compliance

ISO 27001, NIS2, DORA and CIS Controls — pragmatic GRC that maps controls to real risk. Gap analysis, policy development and audit preparation without bureaucracy for its own sake.

  • Gap analysis against ISO 27001 / NIS2 / DORA
  • Risk register & risk treatment plan
  • Security policy & procedure framework
  • ISMS design, implementation & internal audit
  • Certification audit preparation & support
red-blue/

Offensive & defensive

Adversary-minded assessments paired with the blue-team work needed to actually close what they find. External, internal and application testing, plus purple-team exercises to sharpen detection.

  • External & internal network penetration testing
  • Web application & API security testing
  • Red team operations (TIBER-EU aligned)
  • Purple team & detection engineering
  • Remediation validation & re-test
threat-mgmt/

Vulnerability & threat mgmt

Continuous vulnerability management prioritised by exploitability and business impact, not raw CVSS score. Integrates threat intelligence so remediation effort goes where risk is highest.

  • Vulnerability scanning programme design & tooling
  • Risk-based prioritisation (EPSS, exploit availability)
  • Threat intelligence integration & contextualisation
  • Patch management process & SLA definition
  • Executive risk dashboard & reporting
soc/

SOC build-out

Design and stand up a Security Operations Centre from scratch — or mature an existing one. Open-source SIEM, detection engineering and playbook development, with training for the team that inherits it.

  • SOC operating model & staffing design
  • SIEM deployment & log source onboarding
  • Detection rule & use-case engineering (MITRE ATT&CK)
  • Incident response playbook development
  • SOC analyst training & tabletop exercises
devsecops/

DevSecOps

Security embedded in the CI/CD pipeline so vulnerabilities are caught before deployment. SAST, DAST, SCA, container scanning and IaC security — secure by default, not bolted on at the end.

  • Pipeline security integration (GitLab, GitHub Actions)
  • SAST / SCA / secrets detection tooling
  • Container & image security scanning
  • Infrastructure-as-Code security (Terraform, Ansible)
  • Developer security training & threat modelling
program/

Security program

End-to-end security strategy aligned to your business and risk appetite — from maturity baseline through multi-year roadmap to executive reporting. Coherent, measurable and maintainable.

  • Security maturity assessment (CMMI / BSIMM)
  • Security strategy & multi-year roadmap
  • Budget planning & business-case development
  • KPI / KRI framework & metrics programme
  • Board & executive reporting
// approach

Why independent

No badges to sell, no quotas to hit. The work serves your risk — nothing else.

01

Vendor-neutral

No reseller margins, no product quotas. Recommendations serve your risk profile, not a vendor's sales target.

02

Open-source first

Proven open tools wherever they meet the control objective. Commercial only where it measurably wins.

03

One accountable expert

You work directly with the person doing the work — no handoffs, no junior bait-and-switch.

04

Discretion by default

PGP-encrypted communication, tightly scoped engagements and an NDA before anything sensitive is shared.

// about

The practice

opensecurity.cz is the independent practice of Ondra Burian — a cybersecurity consultant working across security architecture, incident response and governance for on-premises and cloud environments.

The aim is simple: build systems that are defensible, respond decisively when it matters, and leave every client more capable than before. Open standards over lock-in. Clarity over jargon.

$ cat ./frameworks
std  ISO/IEC 27001 · 27005
reg  NIS2 · DORA
cis  CIS Controls v8
ttp  MITRE ATT&CK
$
// contact

Get in touch

Facing an incident, planning an assessment, or just want a second, independent opinion? Reach out directly.

Encrypted mail welcome — verify the public key by its fingerprint before sending anything sensitive. Typical response within one business day; faster for active incidents.

loc Praha, CZ
pgp D288 9273 08D7 BEB0 5C14 7BF1 A6B9 E554 9EE6 88B2
Send encrypted mail →