Clear scope, fixed deliverables,
senior delivery.

Every engagement is led personally by a security architect with 15+ years across firewall, network, cloud and OT/ICS environments in pharma, semiconductors, energy and manufacturing. You know before we start what you get and when.

BlueCyber cybersecurity services
what we offer

Five ways to work with us

Four fixed-scope engagements and a security architect on retainer, each with a defined duration and clear deliverables. We publish no price list: every environment is different, so you get a fixed written proposal after a short scoping call.

What each service includes

Durations, deliverables and what you keep at the end.

Firewall Rule-Base Audit

For organisations whose firewall policies have grown over years and nobody is sure what is still needed.

  • Duration: 1 to 2 weeks
  • Platforms: Palo Alto, Fortinet, Cisco, Check Point
  • You get: a full review of rules and objects (unused, shadowed, overly permissive, undocumented), findings ranked by risk, a cleanup plan you can execute change by change, and a management summary.
Book a 30-minute scoping call

Network and OT Segmentation Assessment

For plants, utilities and regulated sites where office IT and production or SCADA networks are not properly separated.

  • Duration: 2 to 3 weeks
  • Framework: IEC 62443, NIST SP 800-82
  • You get: a map of how your assets actually communicate, a zone and conduit model, the firewall rules that enforce it without stopping production, and a phased remediation roadmap.
Book a 30-minute scoping call

Cloud Network Security Review

For teams running workloads or remote access in AWS, Prisma Access or Zscaler who want an independent view of the design.

  • Duration: 1 to 2 weeks
  • You get: architecture and policy findings, misconfigurations ranked by risk, and a target design with concrete configuration changes.
Book a 30-minute scoping call

NIS2 Technical Measures Check

For organisations in scope of NIS2 (Czech Act 264/2025, Romanian OUG 155/2024) that need to know where their network and access controls stand before an audit.

  • Duration: about 2 weeks
  • You get: a gap list against the technical measures (segmentation, access control, logging, remote access, backup), evidence of what already meets them, and a prioritised fix plan.

This prepares you for the audit; it is not the formal audit itself.

Book a 30-minute scoping call

Security Architect on Retainer

For organisations that need senior security architecture regularly, but not a full-time hire.

  • Commitment: a fixed minimum of hours per month, on a 12-month term
  • Includes: design reviews, change and firewall policy approvals, vendor and project support, a quarterly review with management, and an agreed response time
  • Flexible: unused hours roll over for one month; extra hours at the agreed rate
Book a 30-minute scoping call

Recent work

We work with pharma, semiconductor and energy clients and other regulated organisations. Client names stay confidential; these examples show the kind of work we deliver.

Firewall Rule-Base Audit

Firewall rule-base audit for a multinational benefits provider

A complex, distributed multi-site firewall estate, and a need for an honest picture of what was really in place. We reviewed configurations, rule sets, access controls and logging against current security standards.

  • Full firewall estate assessed
  • Findings classified by risk
  • Prioritised remediation plan ready for implementation

Firewall cleanup

Cleanup of 50,000 unused objects across a Panorama estate

Years of migrations had left a Palo Alto Panorama configuration with around 50,000 address objects that nothing used anymore. We identified what was truly unused across device groups, validated the FQDN objects and removed the clutter in controlled batches, with a recovery path for every change.

  • Around 50,000 unused objects identified
  • FQDN objects validated
  • Removed in reversible batches

How an engagement works

  1. Scoping call (30 minutes, free): we agree the goal, systems in scope and timeline.
  2. Written proposal: fixed scope, duration, deliverables and price.
  3. Delivery: remote and on-site as needed, with a short weekly update.
  4. Handover: findings walkthrough with your team and a written report you keep.

Delivered by BlueCyber s.r.o. in Czechia and by BlueCyber Solutions SRL in Romania, in English, Czech or Romanian.

Not sure which service fits?

Tell us what you are dealing with in a 30-minute scoping call. If none of these services fits, we will say so.

Book a 30-minute scoping call