ONGYO Start a conversation

Independent security consultingCroatia / EU

Build trust into every layer.

Ongyo provides senior security leadership and hands-on cybersecurity assurance for startups, technology companies and regulated teams.

ONGYO / SECURITY SYSTEM AVAILABLE
RISK
TO
CONTROL
ASSESSBUILDOPERATE
20+years in information security
End-to-endsecurity, compliance and delivery
Cloud-nativeAWS, GCP and Kubernetes
Board-readyclear risk and assurance reporting

01 / CAPABILITIES

Security work that moves the business forward.

Focused engagements, embedded leadership or ongoing advisory support—from first assessment to operating evidence.

01

Security leadership

Fractional security leadership, strategy, risk ownership, board reporting and practical security programmes aligned with business goals.

  • Fractional CISO
  • Risk register
  • Security roadmap
02

ISO 27001 & SOC 2

Readiness, gap assessment, policy and control design, evidence preparation, remediation and support through external audits.

  • ISMS
  • SOC 2 Type 2
  • Audit support
03

Cloud & Kubernetes security

Architecture and posture reviews across AWS, GCP, Kubernetes and hybrid environments, including IAM, hardening, secrets and resilience.

  • AWS
  • GCP
  • Kubernetes
04

DevSecOps & supply chain

Secure CI/CD, SAST, SCA, DAST, container scanning, vulnerability management and SLSA-aligned software supply-chain controls.

  • SLSA
  • CI/CD
  • Terraform
05

Threat modelling & architecture

Risk-led reviews of products, platforms and critical changes, with clear findings, practical design guidance and prioritised remediation.

  • Threat modelling
  • Secure design
  • Code review
06

Incident readiness & resilience

Incident response planning, SIRT leadership, ransomware defence, backup strategy, business continuity and disaster-recovery exercises.

  • IR plans
  • Anti-ransomware
  • BC / DR
07

Security assurance

Technical, network and application assessments, vulnerability triage, vendor due diligence, regulated-customer assurance and IT audit.

  • Assessments
  • Third-party risk
  • IT audit
08

AI governance

Practical governance for AI-enabled products and workflows, including EU AI Act readiness, risk controls and secure AI-assisted delivery.

  • EU AI Act
  • AI risk
  • Governance
09

Blockchain infrastructure

Security and operational assurance for blockchain infrastructure, private networks, cloud deployments and delivery pipelines.

  • Infrastructure
  • Private networks
  • Web3 delivery
10

AI-assisted SaaS development

Architecture and delivery support for secure SaaS products built with AI-assisted development workflows, including identity, payment integration, digital-content access, privacy, cloud operations and controls for secure online sales.

  • AI-assisted delivery
  • SaaS architecture
  • Online sales

02 / WHO WE HELP

Cybersecurity consulting shaped around your operating reality.

Independent advice for organisations that need credible security decisions, practical controls and evidence that stands up to customer, board or regulatory scrutiny.

Technology companies

Secure products, cloud platforms and delivery pipelines without slowing engineering. Ongyo supports architecture decisions, Kubernetes and cloud security, DevSecOps, threat modelling and customer assurance.

Regulated organisations

Turn governance requirements into controls that work in practice. Engagements cover ISO 27001, SOC 2, risk management, audit evidence, resilience and clear reporting for leadership and oversight teams.

Growing security teams

Add experienced security leadership where it has the greatest impact. Fractional CISO and advisory support can establish priorities, strengthen delivery, prepare for incidents and build a defensible security roadmap.

03 / APPROACH

Senior judgement. Practical delivery.

No theatre, oversized frameworks or opaque reports. The work is shaped around the risk, maturity and operating reality of your organisation.

  1. 01

    Assess

    Establish the current state, material risks and the shortest credible path forward.

  2. 02

    Build

    Design the policies, controls, architecture and delivery practices the business needs.

  3. 03

    Operate

    Provide senior ownership, remediation guidance and evidence through audits and change.

04 / NEXT STEP

Bring the hard security problem.

Share the context, the constraint and the decision you need to make. You will receive a direct response—not a sales sequence.

info@ongyo.net