SPC Servis PC Brno

Company security, backups, access rights, AI code and NIS2

IT audit, NIS2 compliance and AI code review in Brno

An audit is not a document for the drawer. It is a check of whether your company can demonstrate security and restore operations — after an attack, an outage or at the request of a customer. We examine accounts, passwords, MFA, backups, the network, access rights, server/AD, the impact of the new Cybersecurity Act (NIS2) and the risks in code or AI-generated changes. You will receive a written report with priorities, and we can fix critical issues right away.

  • Output = a written report with priorities and concrete steps, not just a list of findings
  • Passwords, MFA, backups and a restore test, network, access rights, server/AD and code
  • NIS2 (Act No. 264/2025 Coll.) — we assess what you are missing to achieve compliance
  • AI code audit: security, dependencies, leaked secrets, licensing risks
  • Suitable for contracts, supplier assessments and internal security
  • Audit and subsequent remediation from a single provider
  • Local, Brno and surrounding areas — ITHOPE since 2008

Common situations

Do you know if your backups will save you?

A backup nobody has tried to restore is just a good feeling. We verify with a real restore test — for companies under the higher NIS2 regime, this is a legal requirement from November 2025.

Access rights remain after employees leave

Shared accounts, passwords saved in the browser, a former colleague who still has access. We review who has access to what and what to deactivate.

NIS2 and you do not know if it applies to you

The new Cybersecurity Act does not apply to everyone — it depends on the regulated service, size and significance. We verify the regime and tell you exactly what you must meet.

A contract requires you to demonstrate security

A supplier questionnaire, a customer requirement, an insurer or a tender often asks for answers about MFA, backups, incidents, authorizations and suppliers. We prepare facts, not generic promises.

AI wrote the code, but nobody reviewed it

AI can speed up development, but it can also add errors, vulnerable dependencies, accidental secret leaks or a licensing problem. We perform a read-only repository check and rank the risks by impact.

Nobody is watching security

An outdated system, disabled MFA, RDP exposed to the internet, an antivirus you have no overview of. We find these things before an attacker does.

What we actually do

Accounts, passwords and devices

  • passwords and access management
  • MFA / two-factor for critical accounts
  • antivirus and Defender
  • OS and software updates
  • disk encryption (BitLocker)
  • standardized workstation configuration

Network, access rights and server

  • Wi-Fi, LAN, VLAN and segmentation
  • firewall and open ports (RDP exposed to the internet is a critical risk)
  • access rights and shared folders
  • domain controller / Active Directory
  • VPN and remote access
  • logs and monitoring

Backups and restore (core of NIS2)

  • 3-2-1 scheme
  • offline / immutable copies against ransomware
  • versioning
  • real restore test
  • recovery procedure documentation

NIS2 / Cybersecurity Act

  • assessment of regulated service and regime (NÚKIB calculator)
  • gap analysis against Decrees 409/410/2025 Coll.
  • incident playbook and reporting deadlines (24 hours / 72 hours / 30 days)
  • risk management and responsibilities
  • documentation for audit

AI code and application audit

  • read-only repository check
  • secrets and sensitive data in code
  • vulnerable dependencies and lockfile
  • authentication, authorization and inputs
  • safe use of AI tools in the company
  • practical fix list for developers

Documentation for contracts

  • customer security questionnaires
  • overview of measures and responsibilities
  • risk list and remediation plan
  • evidence of MFA, backups and restore
  • recommendations for contractual requirements
  • clear summary for company management

Indicative prices

How much does an IT audit and AI code audit cost

Business pricing →

The price depends on the scope: a quick security questionnaire for a contract is different from an audit of an entire small business with a network, server and backups. For each variant, we specify in writing beforehand what we check, what the output will contain and how much the subsequent remediation will cost.

Task Price
Initial consultation and scope
We briefly discuss the company and what the audit will cover. We provide the price in writing upfront.
free
Contract documentation / security questionnaire
Quick review of answers, MFA, backups, incidents and basic state. Suitable before sending a questionnaire to a customer.
from 1,794 CZK
Backup and restore audit
Review of backup scheme, ransomware risks and a test restore of selected data.
from 2,392 CZK
Small business security audit (up to ~10 devices)
On site + remote. Output = a written report with priorities.
from 3,588 CZK
IT audit with network and server / AD
Based on the number of devices and network complexity.
individual
AI code audit / smaller application
Read-only check of repository, dependencies, secrets, inputs and risks from AI-generated changes. This is not a full penetration test.
from 4,784 CZK
NIS2 gap analysis + documentation
Regime assessment, what is missing for compliance, incident playbook and priority list. Legal interpretation of contracts is handled by an attorney.
from 5,980 CZK
Remediation of identified risks
MFA, backups, access rights, open ports, basic hardening, handover to developer or your IT.
from 598 CZK/30 min

Price, scope and output

What companies address before ordering an IT audit

Before an audit, it is usually not just about technology. You need to know the price, the scope of the check, what the output will be, how long it will take, whether NIS2 applies to you and whether AI-generated code can also be audited.

How much will it cost

We provide concrete starting prices for the questionnaire, backup audit, small business, AI code audit and NIS2 gap. For larger environments, we set the price based on scope so it is a fair price, not a desktop estimate.

What exactly will I get

The output is a written report: status, risks, priorities, recommended procedure, indicative remediation effort and a summary for management, the customer and internal IT.

When does an audit make sense

Before a contract, after a customer request, when an employee leaves, before deploying a new application, after an incident, before taking out cyber risk insurance or when nobody has checked the backups for a long time.

What to prepare before the audit

A list of devices, administrative access, information about backups, the network, cloud accounts, read-only repository access and the requirements of the customer or tender.

How we handle AI code

An AI code audit does not look for architectural beauty, but for risk: secrets in the repository, vulnerable packages, inputs without validation, incorrect permissions, unclear licenses and changes without tests.

NIS2 without hype

Not every company falls under NIS2. We first verify the regulated service and regime, then we address practical measures: access rights, backups, incidents, responsibilities and documentation.

Why Servis PC Brno

In black and white, not fear-mongering

You will receive a written report ranked by risk, clear and understandable — not a marketing PDF leaflet or scare tactics to sell you a box.

We do not stop at a list of errors

We can fix critical issues (MFA, backups, access rights, network segmentation, open RDP) right after the audit. You get a remediation plan and you are not left alone with it.

Audit for contracts and suppliers

We can prepare documentation for a customer security questionnaire or a tender: what you already have, where the gap is and what the remediation plan looks like.

AI code without illusions

We treat AI as a useful tool, but not a guarantee of correctness. With code we mainly check security, dependencies, secrets in the repository, inputs and permissions.

NIS2 practical, not legalistic

We verify the regime in the NÚKIB calculator, go through Decrees 409/410/2025 Coll. and place the main emphasis on backups and a restore test — this is no longer good practice, but a duty. We discuss the context in a separate article on the new NIS2 Cybersecurity Act.

Real experience with business IT

ITHOPE s.r.o. has been managing servers, Active Directory, networks and backups for Brno companies since 2008. We conduct audits from practice and real incidents, not from a downloaded template.

What is included

  • Audit of accounts, passwords, MFA and updates
  • Backup check + real restore test
  • Review of network, access rights and server / AD
  • AI/code audit: dependencies, secrets, inputs and recurring security errors
  • NIS2 assessment (regulated service, regime, gap)
  • Written report with priorities and recommendations
  • Consultation on the report + remediation plan

Related services

Need a quick answer?

774 777 774

Po–Pá 10:00–16:00. Urgent data & ransomware: 775 556 063 24/7.

Who this service is for

Small and medium-sized companies in Brno that sense they need to resolve "something around security" — accounting and law offices, medical practices, e-shops, manufacturing and engineering firms, suppliers to larger companies (which require security from their suppliers too) and anyone affected by the new Cybersecurity Act. For an ordinary household, Antivirus and protection are enough.

Frequently asked questions

Does NIS2 apply to us at all? +

Not automatically. It depends on whether you provide a regulated service (Decree 408/2025 Coll.), your size and how significant an outage would be. We verify this with you using the NÚKIB calculator and tell you the regime (lower/higher) and what exactly you must meet. More in our article on NIS2.

What do we actually get from the audit? +

A written report: what is in order, what is a risk, ranked by priority, and concrete remediation steps. Plus a consultation on it. No "we found holes, good luck".

Do you only audit, or also fix? +

Both. We can fix critical findings (MFA, backups, access rights, RDP exposed to the internet) right away. If you have your own IT, we hand them the report with priorities.

What does an AI code audit mean? +

It is a read-only check of a repository and application focusing on risks that often appear during rapid development or AI-generated changes: secrets in code, vulnerable dependencies, incorrectly set permissions, unsanitized inputs, unclear licenses and missing basic tests. The output is a concrete list of fixes for developers.

Can you help with a security questionnaire for a contract? +

Yes. We go through the customer or insurer questions, verify the real status and prepare answers including recommendations on what to fix immediately and what to put in the plan. We do not write fairy tales — we prefer a demonstrable status and a realistic remediation deadline.

How long does an audit take? +

A small firm typically takes 1 day on site plus remote verification, report within a few days. For a network and server/AD it depends on complexity — we tell you upfront.

Do we have to report an incident ourselves, or do you do it for us? +

The initial NÚKIB notification must be submitted within 24 hours of detection, a supplement for significant impact within 72 hours and the final report typically within 30 days. We prepare an incident playbook for you so you know who does what and when — and we help directly in a crisis.

Call Contact