Independent cybersecurity consultancy · expertise since 2001

Cybersecurity
that genuinely protects.

Security Operations Center (4crypto is the direct operator and owner of the SOC 24/7 infrastructure), IT audits, penetration testing, KSC, NIS2, KRI, GDPR, hardening and ISMS - for local government bodies, medical facilities, R&D sector and industry. No box-ticking bureaucracy. Just practical security.

25+years of experience
79+public & B2B clients
12service areas
100%PL/EU compliance

Comprehensive protection from the technical layer to documentation

We combine hands-on hardening, penetration testing and vulnerability analysis with pragmatic policies and ISMS frameworks that will genuinely be used within your organisation.

24/7/365 Live 100% dane w Polsce KSC · NIS2 · KRI · GDPR · DORA · eIDAS · AI Act

SOC 24/7 - Security Operations Center
in a Polish data centre

Continuous security monitoring of your infrastructure - 24 hours a day, 7 days a week, 365 days a year. Incident detection, event correlation, threat hunting and response carried out by a Polish team of analysts.

All data is processed exclusively within the territory of the Republic of Poland - at the PNT Data Centre located in the Science and Technology Park in Opole. No transfer outside the EU, no transfer outside Poland, no subcontractors from the USA or Asia. Full digital sovereignty, zero compliance concerns.

PNT Data Center Science and Technology Park in Opole Sp. z o.o. · Poland · EU
24/7monitoring
<5 minresponse time
100%dane w PL
DETECTremediate · reinforce

IT Security Audits

Comprehensive assessment of infrastructure, policies and compliance with KSC / NIS2 / KRI / GDPR. Report with risk levels and a concrete remediation plan - not a list of buzzwords.

Penetration Testing & Vuln Scanning

Manual penetration tests based on OWASP, PTES and NIST SP 800-115 + automated vulnerability scanning (CVE/CVSS). We simulate real attack chains, not just run a scanner.

System Hardening

Hardening of Linux RHEL/Debian servers, Active Directory, firewalls: FortiGate, Cisco Systems, Palo Alto Networks, Stormshield. SSH, IPsec, TLS 1.3, MFA - defence-in-depth compliant with NIS2.

KSC · NIS2 · KRI · GDPR · DORA · eIDAS · AI Act

Full compliance pathway: incident handling, reporting to CSIRT, documentation meeting statutory requirements. Preparation for the stringent demands of the AI Act and DORA.

Email Audit & Phishing

SPF, DKIM, DMARC, BIMI, TLS, MFA, anti-spam filters.

ISMS / ISP - documentation that lives

Information Security Management System compliant with ISO/IEC 27001 and Information Security Policy per KRI § 19. No operational paralysis, no 300-page documents destined for a drawer - real procedures embedded in the daily functioning of your office or organisation.

Security Awareness - onsite & online training

Practical training for management, staff and IT teams. Phishing, ransomware, social engineering, incident management. Fulfilment of KSC, NIS2, KRI § 19, GDPR Art. 24 obligations - with attendance documentation.

SOC 24/7 Calculator

Estimate your monthly monitoring cost. Market-rate pricing for local authorities and SMEs. All data processed exclusively in the Polish data centre at the Science and Technology Park in Opole. Indicative calculator - final offer following a brief infrastructure audit.

Configure Your SOC

Adjust the sliders and select additional options - the price updates in real time.

Workstations and other endpoint devices30
3065100+
Servers (physical + virtual)2
2915+
SLA Response Time1h 15min
1h 15min45 min5 min
// Estimated net price
1,920 PLN
per month · 12-month contract · net · PLN
SOC base subscription (30 endpoints)1,650 PLN
Servers (2 × 135 PLN)270 PLN
SLA multiplier (1h 15min)×1.00
Intrusion responseincluded
Annual KSC/KRI audit-
On-site intervention-
ISMS maintenance-
SOAR/SIEM softwareincluded
Total net / month1,920 PLN

This calculator is for informational purposes only and does not constitute an offer within the meaning of contract law. The figures are indicative - the final price depends on the results of a complimentary infrastructure audit. 4crypto Sp. z o.o. reserves the right to amend pricing without notice.
* 9,900 PLN - standard price for a KSC/KRI audit carried out outside the SOC subscription.

4 steps to genuine security

No week-long onboarding or 40-page proposals. Just specifics, a schedule, and a report.

01

Reconnaissance & Audit

We gather information about the infrastructure, map processes, verify compliance and conduct technical tests. Everything in accordance with industry standards.

02

Report & Remediation Plan

You receive a report with risk categorisation, vulnerability descriptions and a concrete, prioritised remediation plan - comprehensible for the board and technical for the IT team.

03

Implementation & Support

We help implement the recommendations: Linux/Windows hardening, policies, training, retest after remediation. We provide ongoing support and security maturity monitoring.

04

SOC 24/7 - from here on, we watch

The hard part starts after the rollout: somebody has to watch the alerts every night. You hand that to a team that does it every day - we take over detection, alert triage and first response, 24/7/365, in a Polish data centre. What is left for you is the report and the quiet.

Standards and regulations we support

From Polish regulations to international standards and EU directives.

KSC
Polish National Cybersecurity System Act
NIS2
Directive tightening cybersecurity requirements and management accountability
KRI
Regulation setting IT system requirements for public sector entities
GDPR
General Data Protection Regulation
DORA
Regulation on digital operational resilience for the financial sector
eIDAS 2.0
Regulation on electronic identification and trust services
AI Act
Legislation classifying AI systems by risk level and prohibiting the most dangerous practices.
ISO 27001
Information security management system
ISO 22301
Business continuity management system - keeping critical processes running during outages
NIST SP 800-115
Technical standard for conducting security testing and information system vulnerability assessments.

12 areas of cybersecurity

Each service comes with a defined scope, schedule and final report. Choose exactly what you need.

Article SOC 24/7

SOC - Security Operations Centre

Continuous 24/7/365 monitoring, incident detection and threat hunting. 100% of data in a Polish data centre at the Science and Technology Park in Opole. No transfer outside the EU.

Article Audit

IT Security Audit

Comprehensive assessment of infrastructure, policies and compliance with KSC, NIS2, KRI, GDPR, ISO 27001. Report with risk categorisation and a remediation plan.

Article Scanning

Vulnerability Scanning

Identification of known vulnerabilities in systems, applications and networks. CVE/CVSS compliant.

Article Pentest

Penetration Testing

Manual penetration tests in accordance with OWASP, PTES, NIST SP 800-115. Demonstration of the real impact of vulnerabilities.

Article Hardening

Device & System Hardening

Hardening of Linux/Windows server configurations, AD, firewalls, L2/L3 switches, NAS, IoT. Defence-in-depth per ISO 27001, KRI, KSC, NIS2.

Article Email

Email Security Audit

SPF, DKIM, DMARC, BIMI, TLS, MFA, anti-spam. Protection of Exchange/Postfix/M365 against phishing and spoofing.

Article Compliance

KRI Compliance Audit

Verification of local authority IT systems against the KRI Regulation.

Article Compliance

KSC & NIS2 Audit

Assessment of compliance with KSC Act and NIS2 Directive obligations. Policies, incidents, reporting to CSIRT.

Article Compliance

GDPR Compliance Audit

Full compliance analysis with Regulation 2016/679. Art. 5, 24, 30, 32, 33-34. Privacy Impact Assessment.

Article Documentation

Information Security Policy

ISP compliant with KRI § 19, GDPR Art. 24/32 and ISO 27001. Practical documentation, not bureaucracy.

Article Documentation

ISMS - Information Security Management System

ISMS tailored to the realities of local authorities and businesses whilst remaining compliant with ISO/IEC 27001. No operational paralysis, with real impact.

Article Training

Security Awareness - onsite & online

Practical applied cybersecurity training for management, staff and IT teams. Certificates confirming fulfilment of KSC / NIS2 / KRI / GDPR obligations.

Independent consultancy. Genuine expertise.

4crypto is the personal brand of Dr Adam Czubak - a Doctor of Engineering with over 25 years of experience in IT Security - supported by a team of experts: SOC analysts, penetration testers, auditors, network engineers, Linux/Windows systems engineers, hardening specialists, data protection officers and "legal hacker" lawyers. The name itself is short for 4cryptography and stems from his passion for cryptography. Adam oversees strategy and project supervision; the team handles daily 24/7 operations.

We work for local government bodies (JST), medical facilities, R&D initiatives, knowledge-intensive environments and manufacturing plants. We combine a strategic approach with hands-on technical expertise - from firewall configuration, through cryptography and hardening, to full compliance documentation for KSC, NIS2, KRI, GDPR, DORA, eIDAS and the AI Act.

More on competences, academic record and projects: expert profile of Adam Czubak, PhD.

  • We build future-proof solutions - not merely patching current vulnerabilities
  • Focus on next-generation cryptography: hybrid TLS 1.3 (X25519MLKEM768), SSH with sntrup761, ML-KEM, post-quantum readiness (PQC)
  • In-house R&D department - bespoke solutions: IDS, monitoring tools, automation
  • We favour open-source and European solutions - no vendor lock-in
  • Knowledge-intensive organisation - our strength lies in expertise, research and experience, not licences
dr inż. Adam Czubak
Adam Czubak, PhD Founder, CEO & CTO
Expert Team SOC analysts · penetration testers · auditors · network and Linux/Windows systems engineers
SOC at PNT Opole Entirely Polish team, 24/7/365
Pentesting & hardeningOWASP / PTES / NIST 800-115
KSC & NIS2 / KRI / GDPR / DORAFull PL+EU compliance pathway

Clients from public administration, healthcare, universities and industry

Competences backed by certifications

Personal certifications held by 4crypto team members - security, networks, systems and project management. Earned in the field over more than 25 years.

CISSP CEH - Certified Ethical Hacker 8570.01-M 4011 Recognition 4013 Recognition CCNP Security / CCSP CCNA Security ASA Specialist Firewall Security Specialist IOS Security Specialist IPS Specialist VPN Security Specialist CCSA NGX R65 27001 22301 CCNP Enterprise CCNA CCDA CCDP CCIP CCNA Voice CCSI #35146 CCAI JNCIS-ER LPIC-1 Certified Linux Professional Certified Linux Administrator SLES 11 Data Center Technical Specialist MCT - Certified Trainer MCITP Server Administrator MCTS Active Directory 2008 MCTS Network Infrastructure 2008 MTA Database Administration MTA Software Development (C#) PRINCE2 Foundation AgilePM Foundation

Let's talk about your organisation's security

A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.

4crypto.eu