Cybersecurity services · since 2009
Virtual CISO, NIS2 compliance, offensive security and digital forensics for organisations that would rather not learn from an incident. Hands-on, certified, accountable.
What we do
Most firms sell one of these. We run all five, which is what a security programme actually needs.
Fractional security leadership for companies without a full-time CISO: strategy, budget, board reporting and day-to-day ownership of the security programme.
Readiness assessment, gap analysis and implementation roadmap for essential and important entities, aligned with the national transposition and ENISA guidance.
Penetration testing, red-team exercises and infrastructure assessments carried out by a practitioner trained at Black Hat, not by a scanner report.
Court-grade evidence handling, host and mobile examination, incident investigation and containment when something has already gone wrong.
ISMS design and implementation, policy frameworks and Data Protection Officer services that hold up under audit.
Firewall, segmentation and secure-network design, from Fortinet Security Fabric deployments to protocol-level traffic analysis.
Who you work with
Thirty years in IT, seventeen of them building The Hard Way.
Georgios Pagkos has run The Hard Way since 2009, after a decade running networks, hosting infrastructure and systems integration. Since then he has served as Chief Information Security Officer, on staff or as a vCISO, for manufacturers in the pharmaceutical, agrochemical, food and HVAC sectors, including companies now in scope of NIS2.
His practice is unusual in covering the full arc of a security incident: he leads the programmes that prevent it, performs the offensive testing that finds the gaps first, and holds the forensic certifications (CFCE, EnCE, CHFI, Cellebrite) to investigate it properly when it happens. He is a member of OWASP, IACIS, HTCIA, ISACA and (ISC)², holds a BSc (Hons) in Computing and IT from The Open University and is completing an MSc in Cybersecurity.
Credentials
Every certification below is listed with its issuing body. Verification IDs available on request.
How an engagement runs
The same three phases whether the trigger is NIS2, an audit finding or a breach.
Readiness assessment against NIS2 / ISO 27001, technical testing of the estate, and a prioritised risk register the board can read.
Remediation roadmap, policies and controls, architecture changes, supplier requirements. Delivered with your IT team or your integrator.
Ongoing vCISO retainer: governance, incident readiness, management reporting, audits and regulator liaison.
Contact
No sales layer. Enquiries are answered by the person who does the work.