Site under construction · preview release Full site launching soon

Cybersecurity services · since 2009

Security leadership,
earned the hard way.

Virtual CISO, NIS2 compliance, offensive security and digital forensics for organisations that would rather not learn from an incident. Hands-on, certified, accountable.

What we do

Five disciplines. One accountable owner.

Most firms sell one of these. We run all five, which is what a security programme actually needs.

Who you work with

Georgios Pagkos

Thirty years in IT, seventeen of them building The Hard Way.

Georgios Pagkos has run The Hard Way since 2009, after a decade running networks, hosting infrastructure and systems integration. Since then he has served as Chief Information Security Officer, on staff or as a vCISO, for manufacturers in the pharmaceutical, agrochemical, food and HVAC sectors, including companies now in scope of NIS2.

His practice is unusual in covering the full arc of a security incident: he leads the programmes that prevent it, performs the offensive testing that finds the gaps first, and holds the forensic certifications (CFCE, EnCE, CHFI, Cellebrite) to investigate it properly when it happens. He is a member of OWASP, IACIS, HTCIA, ISACA and (ISC)², holds a BSc (Hons) in Computing and IT from The Open University and is completing an MSc in Cybersecurity.

2009 —
The Hard Way Limited
Cybersecurity services
2014 —
Mnorel Limited & Digital Investigations Ltd
Cybersecurity and forensic services
2016 —
CISO & DPO, agrochemical manufacturer
In-house security and data-protection leadership
2022 —
vCISO, three Greek manufacturers
Pharmaceutical, HVAC and food industry groups
2024 —
CISO & ISSO for NIS2, multinational agrochemical group
Operations in 7 European countries
2008–14
Managing Director, Redtek Co
Systems integration, networking, firewall deployments

Credentials

Verified, current, and mostly practical exams.

Every certification below is listed with its issuing body. Verification IDs available on request.

Security leadership & governance

CCISOCertified Chief Information Security Officer · EC-Council
CN2PCertified NIS2 Professional · ICTTF
ISO 27001 LILead Implementer · ICSI/CIL
DPOData Protection Officer Executive · TÜV Austria

Offensive security

OSCPOffensive Security Certified Professional
LPTLicensed Penetration Tester · EC-Council
CEH MasterCertified Ethical Hacker Master · EC-Council
ECSACertified Security Analyst · EC-Council
CPTCertified Penetration Tester · ICSI
CNDCertified Network Defender · EC-Council

Digital forensics & incident response

CFCECertified Forensic Computer Examiner · IACIS
EnCEEnCase Certified Examiner · OpenText
CFSRCertified Forensic Security Responder · OpenText
CHFIComputer Hacking Forensic Investigator · EC-Council
ECIHCertified Incident Handler · EC-Council
CDFECertified Digital Forensics Examiner · ICSI
CCME · CCPA · CCOCellebrite mobile forensics
3CE · 3CI · 3CIACyber Crime Examiner, Investigator, Intelligence Analyst · NW3C

Network & vendor

NSE 7Network Security Architect · Fortinet
FCPFortinet Certified Professional, Network Security
WCNAWireshark Certified Network Analyst
CNSSCertified Network Security Specialist · ICSI
CCNA · DevNetCisco Networking Academy

Continuing training

Black Hat6 courses · Las Vegas, London, Singapore · infrastructure hacking, red-team emulation, ICS/IIoT
OpenText EnCase9 DFIR courses
Belkasoft11 forensics courses · mobile, Windows, SQLite, YARA/Sigma
ISC2Official CISSP training · exam scheduled 2026
Member of OWASPIACISHTCIAHTCCISACA(ISC)²

How an engagement runs

Assess. Build. Operate.

The same three phases whether the trigger is NIS2, an audit finding or a breach.

PHASE 1

Assess

Readiness assessment against NIS2 / ISO 27001, technical testing of the estate, and a prioritised risk register the board can read.

PHASE 2

Build

Remediation roadmap, policies and controls, architecture changes, supplier requirements. Delivered with your IT team or your integrator.

PHASE 3

Operate

Ongoing vCISO retainer: governance, incident readiness, management reporting, audits and regulator liaison.

Contact

Talk to Georgios directly.

No sales layer. Enquiries are answered by the person who does the work.

Greek and English · replies within one business day

Notice This is a preview version of thehardway.io. Service pages, case studies and a full company profile are being prepared for the full launch, coming soon. The information on this page is current.