Through vetted partners
24/7 incident response, penetration testing and online training
Some work needs a round-the-clock team or specialised tooling. Vetted partners carry it out, while Dyasol scopes it, coordinates it, accepts the result and verifies the fixes. You have one point of contact and clearly divided responsibilities.
Scope, timings, price and each party’s responsibilities are confirmed in writing before work starts.
Discuss your caseThe benefit for your organisation
- If an incident happens at night, you know whom to call and who reports on time.
- Tests are commissioned with a clear scope and fixes are re-tested.
- You have one point of contact for technical work, decisions and reporting.
24/7 incident response
A readiness retainer: a round-the-clock line, technical containment and digital forensics from a partner; decisions and reporting with Dyasol.
by written quotationannual retainer
Details →Penetration testing
Web applications, APIs, internal and external networks, cloud, plus periodic vulnerability scanning. Re-testing of fixes.
by written quotationdepending on scope
Details →Online staff training
A platform with courses, completion tracking and a report for management. Complements live training.
by written quotationper employee
Details →How we work with partners
- The partner carries out the technical work. Dyasol sets the scope and rules, coordinates, accepts the result and verifies the fixes.
- Responsibilities, response times and price are written down before work starts. The partner’s response times are in the contract, not a general promise.
- Any commercial relationship between Dyasol and the partner is disclosed to you.
- If we need to verify work we took part in independently, we recommend another provider.
24/7 incident response
A significant incident has to be reported with an early warning within 24 hours and a notification within 72 hours under NIS2. The clock runs at night and at weekends too. With a readiness retainer you know in advance whom to call and who does what.
- The partner: a round-the-clock line, technical containment, evidence preservation and digital forensics.
- Dyasol: supports management decisions, judging whether the incident is significant, reports to the authorities and communication with those affected.
- Who receives the alert, who leads regulatory coordination outside business hours and within which times is set in the readiness contract before any incident.
- Before an incident: contacts and escalation, the access the partner will use, and a short exercise.
See also the incident exercise and the first 24 hours of an incident.
Penetration testing and vulnerability scanning
- NIS2 requires vulnerability handling and assessment of the effectiveness of measures (Art. 21(2)(e) and (f)). DORA requires a testing programme in which tests, including vulnerability assessments and penetration tests, are chosen according to risk and applicability (Art. 24–25).
- Dyasol: scope, safety rules, written authorisation from the system owner, acceptance of the report, prioritising fixes and re-testing.
- The partner: testing web applications, APIs, networks and cloud, and periodic scanning.
- DORA TLPT is required only of entities identified by the competent authority and has separate tester requirements. See the TLPT article.
Online staff training
National laws under NIS2 often require staff training to be offered and organised; in Bulgaria, Art. 21(3) of the Cybersecurity Act does. Online courses reach everyone, including new joiners, and record who completed what. We combine them with live training for management and key roles.
Boundaries
- We do not run simulated attacks on staff and do not assess individuals.
- Tests run only with written authorisation and within an agreed scope.
- Decisions and legal accountability remain with the organisation’s management.