opensecurity.cz
Independent cybersecurity consulting — vendor-neutral and open-source first. One accountable expert across architecture, incident response and governance.
Open source, open mind.
Available — incident response 24/7What I do
Full-lifecycle security — from designing defensible architecture to responding when something breaks, and proving compliance along the way.
Security architecture
Zero-trust blueprints and hardening guides for on-prem and cloud environments, built around real adversary TTPs rather than checkbox compliance. Covers network, identity and workload layers.
- Architecture review & threat modelling
- Network segmentation & micro-segmentation design
- Identity & access architecture (IAM/PAM/SSO)
- Infrastructure hardening (OS, cloud, containers)
- Security reference architecture documentation
Emergency incident handling
24/7 rapid DFIR at any stage — from first call to full recovery. Hands-on containment, eradication and root-cause analysis, with court-ready documentation and a lessons-learned report.
- Initial triage, scoping & severity assessment
- Containment, isolation & evidence preservation
- Malware analysis & attacker eviction
- Recovery planning & restoration guidance
- Post-incident report with timeline & IOCs
Forensic analysis
Rigorous evidence collection, preservation and analysis across host, network and cloud. Findings are documented to stand up to legal, regulatory and insurance scrutiny.
- Disk, memory & volatile data acquisition
- Malware reverse engineering & behavioural analysis
- Network packet capture & traffic analysis
- Cloud trail & log forensics (AWS, Azure, GCP)
- Expert witness report preparation
Governance & compliance
ISO 27001, NIS2, DORA and CIS Controls — pragmatic GRC that maps controls to real risk. Gap analysis, policy development and audit preparation without bureaucracy for its own sake.
- Gap analysis against ISO 27001 / NIS2 / DORA
- Risk register & risk treatment plan
- Security policy & procedure framework
- ISMS design, implementation & internal audit
- Certification audit preparation & support
Offensive & defensive
Adversary-minded assessments paired with the blue-team work needed to actually close what they find. External, internal and application testing, plus purple-team exercises to sharpen detection.
- External & internal network penetration testing
- Web application & API security testing
- Red team operations (TIBER-EU aligned)
- Purple team & detection engineering
- Remediation validation & re-test
Vulnerability & threat mgmt
Continuous vulnerability management prioritised by exploitability and business impact, not raw CVSS score. Integrates threat intelligence so remediation effort goes where risk is highest.
- Vulnerability scanning programme design & tooling
- Risk-based prioritisation (EPSS, exploit availability)
- Threat intelligence integration & contextualisation
- Patch management process & SLA definition
- Executive risk dashboard & reporting
SOC build-out
Design and stand up a Security Operations Centre from scratch — or mature an existing one. Open-source SIEM, detection engineering and playbook development, with training for the team that inherits it.
- SOC operating model & staffing design
- SIEM deployment & log source onboarding
- Detection rule & use-case engineering (MITRE ATT&CK)
- Incident response playbook development
- SOC analyst training & tabletop exercises
DevSecOps
Security embedded in the CI/CD pipeline so vulnerabilities are caught before deployment. SAST, DAST, SCA, container scanning and IaC security — secure by default, not bolted on at the end.
- Pipeline security integration (GitLab, GitHub Actions)
- SAST / SCA / secrets detection tooling
- Container & image security scanning
- Infrastructure-as-Code security (Terraform, Ansible)
- Developer security training & threat modelling
Security program
End-to-end security strategy aligned to your business and risk appetite — from maturity baseline through multi-year roadmap to executive reporting. Coherent, measurable and maintainable.
- Security maturity assessment (CMMI / BSIMM)
- Security strategy & multi-year roadmap
- Budget planning & business-case development
- KPI / KRI framework & metrics programme
- Board & executive reporting
Why independent
No badges to sell, no quotas to hit. The work serves your risk — nothing else.
Vendor-neutral
No reseller margins, no product quotas. Recommendations serve your risk profile, not a vendor's sales target.
Open-source first
Proven open tools wherever they meet the control objective. Commercial only where it measurably wins.
One accountable expert
You work directly with the person doing the work — no handoffs, no junior bait-and-switch.
Discretion by default
PGP-encrypted communication, tightly scoped engagements and an NDA before anything sensitive is shared.
The practice
opensecurity.cz is the independent practice of Ondra Burian — a cybersecurity consultant working across security architecture, incident response and governance for on-premises and cloud environments.
The aim is simple: build systems that are defensible, respond decisively when it matters, and leave every client more capable than before. Open standards over lock-in. Clarity over jargon.
Get in touch
Facing an incident, planning an assessment, or just want a second, independent opinion? Reach out directly.
Encrypted mail welcome — verify the public key by its fingerprint before sending anything sensitive. Typical response within one business day; faster for active incidents.