Cybersecurity consulting
Cybersecurity consulting services from the team that secures your AI
KDS started as a cybersecurity consultancy, and we still protect the rest of your business: cloud, networks, applications and people. You work with senior engineers who find the weaknesses that matter, explain them in plain language and help you fix them.
What you get
- Security assessments and penetration testing
- Part-time security leadership (virtual CISO)
- Incident response plans and drills
- NIS2 and Cyber Resilience Act preparation
Cybersecurity consulting sized for your company
Growing companies need senior security expertise long before they can justify a full security team. We fill that gap. We assess where you stand, fix the highest risks first and give you a roadmap your budget can support.
Our AI security work adds a second benefit. When your teams start using AI tools and agents, the engineers who already know your infrastructure test and secure them too.
Cybersecurity consulting services
Pick one service or combine them into a security program.
Security assessments
We review your cloud, network, identity and endpoint setup against established frameworks and rank the gaps by risk and by the effort to fix them.
Penetration testing
We test your web applications, APIs, cloud and internal network the way an attacker would, report each finding with evidence and a fix, and retest after you apply it.
Virtual CISO
A senior security leader works with your team part-time. They own the security roadmap, answer customer security questionnaires and report to your leadership.
Incident response planning
We write your incident response plan, define who does what and run tabletop exercises, so your team knows its role before a real incident.
NIS2 and Cyber Resilience Act preparation
We map your obligations under the EU's NIS2 Directive and Cyber Resilience Act, close the gaps and prepare the evidence regulators and customers ask for.
Security awareness training
Short, practical sessions on phishing, social engineering and safe AI use, built around the tools your staff use.
How we work with your team
Security work touches sensitive systems, so we agree on the rules before we start.
- A written scope and rules of engagement before any test.
- An NDA before you share details.
- Findings ranked by business risk, each with a clear fix.
- Plain-language summaries for leadership.
- A retest to confirm each fix.
From audit to launch in four stages
- 01 · 1–2 weeks
Opportunity and risk audit
We interview your team, map the workflows and rank AI opportunities by payback and risk.
You get: Ranked use cases, ROI model, risk map
- 02 · 4–6 weeks
Pilot with clear success criteria
One agent and one workflow, connected to your real systems and measured against the goal we agreed on. Then you decide whether to continue.
You get: Working agent, results report, go/no-go decision
- 03 · 2–4 weeks
Secure launch
We harden, attack-test and monitor the agent and train your staff before it talks to a single customer.
You get: Security report, operating guides, launch
- 04 · Ongoing
Run and improve
We track quality, cost per workflow and new risks, and keep improving the agent. Short contracts, no lock-in.
You get: Monthly performance and cost report
Cybersecurity consulting FAQ
What does a virtual CISO do?
A virtual CISO is a part-time chief information security officer. They set your security strategy, manage risks, answer customer and auditor questions and guide your team, at a lower cost than a full-time hire.
How often should we run a penetration test?
At least once a year and after major changes, such as a new application, a cloud migration or a large new integration. Some regulations and customer contracts set their own schedule.
Do we need to comply with NIS2?
NIS2 applies, through each EU country's national law, to medium and large organizations in the sectors it lists, and to some providers regardless of size, such as DNS and trust service providers. It can also reach you through customers who must secure their supply chain. We check whether and how it applies to you.
What does the Cyber Resilience Act require?
The Cyber Resilience Act sets cybersecurity rules for products with digital elements sold in the EU, mainly for their manufacturers. Reporting of actively exploited vulnerabilities and severe incidents has applied since September 11, 2026. Most other requirements apply from December 11, 2027.
Do you work with companies outside the United States?
Yes. We work with clients worldwide, except in countries and regions under U.S. sanctions, and deliver our services remotely.
Related services and use cases

Use case
Back-office automation
AI back-office automation that reads invoices, contracts and emails, matches them to your ERP and sends exceptions to a person for approval.
See how back-office automation worksService
AI security and red teaming
AI security consulting for AI agents and LLM apps: red teaming, prompt injection testing, shadow AI discovery and EU AI Act and ISO/IEC 42001 readiness.
Explore AI security consultingService
AI automation and integration
AI automation services that connect AI to your CRM, ERP, help desk and inboxes. We map your processes, find the payback and build secure workflows.
Explore AI automation services
Free 30-minute assessment
Find the one workflow worth automating first.
Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.
- A senior engineer replies within one business day
- We can sign an NDA before you share details
- No fixed packages, every quote tailored to you