Do you know if your backups will save you?
A backup nobody has tried to restore is just a good feeling. We verify with a real restore test — for companies under the higher NIS2 regime, this is a legal requirement from November 2025.
Company security, backups, access rights, AI code and NIS2
An audit is not a document for the drawer. It is a check of whether your company can demonstrate security and restore operations — after an attack, an outage or at the request of a customer. We examine accounts, passwords, MFA, backups, the network, access rights, server/AD, the impact of the new Cybersecurity Act (NIS2) and the risks in code or AI-generated changes. You will receive a written report with priorities, and we can fix critical issues right away.
A backup nobody has tried to restore is just a good feeling. We verify with a real restore test — for companies under the higher NIS2 regime, this is a legal requirement from November 2025.
Shared accounts, passwords saved in the browser, a former colleague who still has access. We review who has access to what and what to deactivate.
The new Cybersecurity Act does not apply to everyone — it depends on the regulated service, size and significance. We verify the regime and tell you exactly what you must meet.
A supplier questionnaire, a customer requirement, an insurer or a tender often asks for answers about MFA, backups, incidents, authorizations and suppliers. We prepare facts, not generic promises.
AI can speed up development, but it can also add errors, vulnerable dependencies, accidental secret leaks or a licensing problem. We perform a read-only repository check and rank the risks by impact.
An outdated system, disabled MFA, RDP exposed to the internet, an antivirus you have no overview of. We find these things before an attacker does.
Indicative prices
The price depends on the scope: a quick security questionnaire for a contract is different from an audit of an entire small business with a network, server and backups. For each variant, we specify in writing beforehand what we check, what the output will contain and how much the subsequent remediation will cost.
| Task | Price |
|---|---|
| Initial consultation and scope We briefly discuss the company and what the audit will cover. We provide the price in writing upfront. | free |
| Contract documentation / security questionnaire Quick review of answers, MFA, backups, incidents and basic state. Suitable before sending a questionnaire to a customer. | from 1,794 CZK |
| Backup and restore audit Review of backup scheme, ransomware risks and a test restore of selected data. | from 2,392 CZK |
| Small business security audit (up to ~10 devices) On site + remote. Output = a written report with priorities. | from 3,588 CZK |
| IT audit with network and server / AD Based on the number of devices and network complexity. | individual |
| AI code audit / smaller application Read-only check of repository, dependencies, secrets, inputs and risks from AI-generated changes. This is not a full penetration test. | from 4,784 CZK |
| NIS2 gap analysis + documentation Regime assessment, what is missing for compliance, incident playbook and priority list. Legal interpretation of contracts is handled by an attorney. | from 5,980 CZK |
| Remediation of identified risks MFA, backups, access rights, open ports, basic hardening, handover to developer or your IT. | from 598 CZK/30 min |
Price, scope and output
Before an audit, it is usually not just about technology. You need to know the price, the scope of the check, what the output will be, how long it will take, whether NIS2 applies to you and whether AI-generated code can also be audited.
We provide concrete starting prices for the questionnaire, backup audit, small business, AI code audit and NIS2 gap. For larger environments, we set the price based on scope so it is a fair price, not a desktop estimate.
The output is a written report: status, risks, priorities, recommended procedure, indicative remediation effort and a summary for management, the customer and internal IT.
Before a contract, after a customer request, when an employee leaves, before deploying a new application, after an incident, before taking out cyber risk insurance or when nobody has checked the backups for a long time.
A list of devices, administrative access, information about backups, the network, cloud accounts, read-only repository access and the requirements of the customer or tender.
An AI code audit does not look for architectural beauty, but for risk: secrets in the repository, vulnerable packages, inputs without validation, incorrect permissions, unclear licenses and changes without tests.
Not every company falls under NIS2. We first verify the regulated service and regime, then we address practical measures: access rights, backups, incidents, responsibilities and documentation.
You will receive a written report ranked by risk, clear and understandable — not a marketing PDF leaflet or scare tactics to sell you a box.
We can fix critical issues (MFA, backups, access rights, network segmentation, open RDP) right after the audit. You get a remediation plan and you are not left alone with it.
We can prepare documentation for a customer security questionnaire or a tender: what you already have, where the gap is and what the remediation plan looks like.
We treat AI as a useful tool, but not a guarantee of correctness. With code we mainly check security, dependencies, secrets in the repository, inputs and permissions.
We verify the regime in the NÚKIB calculator, go through Decrees 409/410/2025 Coll. and place the main emphasis on backups and a restore test — this is no longer good practice, but a duty. We discuss the context in a separate article on the new NIS2 Cybersecurity Act.
ITHOPE s.r.o. has been managing servers, Active Directory, networks and backups for Brno companies since 2008. We conduct audits from practice and real incidents, not from a downloaded template.
Who this service is for
Small and medium-sized companies in Brno that sense they need to resolve "something around security" — accounting and law offices, medical practices, e-shops, manufacturing and engineering firms, suppliers to larger companies (which require security from their suppliers too) and anyone affected by the new Cybersecurity Act. For an ordinary household, Antivirus and protection are enough.
Not automatically. It depends on whether you provide a regulated service (Decree 408/2025 Coll.), your size and how significant an outage would be. We verify this with you using the NÚKIB calculator and tell you the regime (lower/higher) and what exactly you must meet. More in our article on NIS2.
A written report: what is in order, what is a risk, ranked by priority, and concrete remediation steps. Plus a consultation on it. No "we found holes, good luck".
Both. We can fix critical findings (MFA, backups, access rights, RDP exposed to the internet) right away. If you have your own IT, we hand them the report with priorities.
It is a read-only check of a repository and application focusing on risks that often appear during rapid development or AI-generated changes: secrets in code, vulnerable dependencies, incorrectly set permissions, unsanitized inputs, unclear licenses and missing basic tests. The output is a concrete list of fixes for developers.
Yes. We go through the customer or insurer questions, verify the real status and prepare answers including recommendations on what to fix immediately and what to put in the plan. We do not write fairy tales — we prefer a demonstrable status and a realistic remediation deadline.
A small firm typically takes 1 day on site plus remote verification, report within a few days. For a network and server/AD it depends on complexity — we tell you upfront.
The initial NÚKIB notification must be submitted within 24 hours of detection, a supplement for significant impact within 72 hours and the final report typically within 30 days. We prepare an incident playbook for you so you know who does what and when — and we help directly in a crisis.