Company name | Description and specialisation | Service categories | Certifications | VAT register | REGON register |
|---|---|---|---|---|---|
| 1Security | Data access governance platform for Microsoft 365: permission monitoring, access change analytics, external sharing control and reporting that supports NIS2 compliance. | Infrastructure Security Cloud Security Data Protection | Loading... | Loading... | |
| Afine | Offensive security specialist delivering penetration testing, application and cloud security assessments and red teaming for large organisations in regulated sectors. | Penetration Testing & Audits Cloud Security | Loading... | Loading... | |
| Apius Technologies | Network integrator running a SOC and deploying network, endpoint, application, data and communication security, public cloud, container and SaaS security, DevSecOps, digital identity and OT cybersecurity, alongside its LAN, DC and SD-WAN business. | Infrastructure Security Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Arkanet | IT security integrator from Katowice: antivirus and EDR-XDR, email and cloud protection, encryption, MDM, PAM, DLP, SIEM and SOAR, vulnerability detection, backup, UTM and firewall network security, plus industrial OT protection. | Infrastructure Security Cloud Security Data Protection Monitoring & SOC OT/ICS Security Security Training & Awareness | Loading... | Loading... | |
| Deloitte | Cybersecurity practice within the Deloitte advisory firm: NIS2, DORA and GDPR compliance, SOC build and run, MXDR, threat intelligence, cloud and OT/ICS security, data protection and Zero Trust architecture. | Infrastructure Security GRC & Compliance Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Engave | IT integrator and operator of the sovereign Engave Cloud, providing cloud services, enterprise backup, ransomware protection and security audits that build digital resilience. | Cloud Security Data Protection | Loading... | Loading... | |
| EY | Cybersecurity unit of the EY advisory firm: penetration testing, red teaming, security architecture, IAM/PAM, SIEM and SOAR, cloud and data protection, CSIRT incident response, OT security, compliance advisory and training. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Future Processing | Software house whose security practice covers advisory and risk management, application and cloud security, penetration testing, managed security services and threat detection. | Penetration Testing & Audits GRC & Compliance Cloud Security Monitoring & SOC | Loading... | Loading... | |
| KPMG | Cybersecurity team of the KPMG audit and advisory firm: penetration testing, NIS2 and GDPR compliance, SOC and SIEM, identity and privileged access management, WAF and PKI, data leak protection, cloud security and awareness programmes. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security Data Protection Monitoring & SOC | Loading... | Loading... | |
| LogicalTrust | Wroclaw-based offensive security firm running web and mobile penetration tests, source code audits, red team exercises, social engineering tests, ransomware simulations and cloud, container, PCI DSS, DORA and NIS2 audits. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security OT/ICS Security | Loading... | Loading... | |
| MieczNet | Company from Czeladz specialising in computer network security: antivirus, firewalls, cloud and mail server protection, mobile device control, backup, encryption, data leak protection, VPN, vulnerability detection, audits and trainings. | Infrastructure Security Cloud Security Data Protection GRC & Compliance Security Training & Awareness Monitoring & SOC | Loading... | Loading... | |
| nFlo | Security and infrastructure firm delivering IT audits, penetration testing of applications and networks, ISO 27001 and GDPR programmes and cyber resilience strategies covering technology and staff training. | Cloud Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness | Loading... | Loading... | |
| NT Group Systemy Informatyczne | IT and cybersecurity provider delivering NIS2 and DORA audits, penetration testing, GRC and data protection. It designs and maintains infrastructure and cloud environments, and runs cybersecurity training and social-engineering assessments. | Infrastructure Security Cloud Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Data Protection | Loading... | Loading... | |
| Omnilogy | Observability and cybersecurity provider and Dynatrace partner, monitoring the performance and security of IT, cloud and container environments and surfacing vulnerabilities and threats. | Monitoring & SOC Cloud Security | Loading... | Loading... | |
| Passus | IT systems integrator delivering network, cloud and SIEM security solutions alongside its own Passus Ambience platform for threat analysis. | Infrastructure Security Cloud Security Monitoring & SOC | ISC | Loading... | Loading... |
| PwC | Cybersecurity practice of advisory firm PwC in Poland: penetration testing and red team, IT and OT security architecture reviews, NIS2 and GDPR compliance, managed SOC with 24/7 incident response, cloud security, DLP and training. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Silesian Solutions | IT company covering cybersecurity, artificial intelligence, websites, mobile applications and cloud solutions. | Cloud Security | Loading... | Loading... | |
| SPIREE | Team of IT security consultants delivering application, cloud and infrastructure penetration testing, security posture assessment and preparation for audits and certification. | Penetration Testing & Audits Cloud Security | Loading... | Loading... |
Cloud configuration review - scope and limits
Cloud security comes down to one question: who can reach which resource, and by what path. The control plane sits behind an API, so a single over-broad role or one storage bucket left open exposes data without anyone breaking in. A reviewer reads how accounts, roles and policies are configured, then sets that against the way the environment is actually used. What comes back is a ranked list of findings pinned to named resources, rather than a raw scanner export.
Scope splits into layers. Identity and permissions: roles, service accounts, access keys and multi-factor authentication anywhere administrative rights exist. Data: encryption at rest and in transit, secrets handling, backups and whether a restore has ever been attempted. Network and visibility: traffic rules, resources reachable from the internet, log collection and retention. Where containers run, the review adds image provenance, Kubernetes cluster settings, infrastructure as code templates and the permissions held by the deployment pipeline itself.
There are two engagement modes, and choosing between them before you request quotes saves a round of questions. A one-off review captures the state on a given day and suits a migration, a customer audit or the aftermath of an incident. Continuous posture monitoring, sold under the CSPM label, catches drift from agreed rules as the environment changes with every deployment. Many buyers combine the two: the review cleans up the starting state, monitoring keeps it from sliding back between infrastructure changes.
Signals that your cloud estate needs a review
- The environment was built fast under project pressure and nobody revisited the permissions granted just to get it running.
- The cloud bill grows alongside resources that no team claims as its own or is willing to switch off.
- A customer contract or an insurance policy asks you to demonstrate how the cloud estate is protected, in writing.
- Your team is moving releases into CI/CD and wants bad configuration stopped before production rather than after it.
- The estate already spans two cloud platforms, and access rules on each of them were set by different people.
What to require from a cloud security firm
- Ask which services the review covers and which ones the provider deliberately leaves outside it.
- Establish whether findings are judged against rules you adopted or only against the platform default benchmark.
- Ask who on the provider side verifies tool output before any of it reaches the report.
- Check how the provider works with infrastructure as code and whether fixes return to the repository.
- Agree on a re-check after remediation and on who confirms that a single finding is closed.
Cloud security - questions buyers ask
Answers for teams that are about to buy services from this category.
A cloud security review examines account configuration: identity and permissions, network rules, encryption, secrets, backups and event logging across AWS, Azure or GCP. Containers, Kubernetes clusters, the deployment pipeline and office suite tenants are agreed separately, because each carries a permission model of its own. Application code and business logic normally sit outside this service and call for different work.
Pricing follows how much there is to enumerate: accounts and subscriptions, running services, clusters and separate deployment pipelines. An estate stretched across two platforms costs more than one platform of the same size, because each has its own permission model and its own control names. Remediation help from the provider and a re-check after changes are usually quoted as separate lines.
Moving data to a cloud platform does not move the obligations onto the provider. The customer is usually the controller and the provider a processor, yet roles follow the service and the purpose - a provider processing for its own purposes acts as controller for that part. Roles are settled service by service and written into the processing agreement, and entities under NIS2 add supplier oversight on top.
Remediation is ordered by exposure rather than by the number of items: whatever is reachable from the internet and whatever grants administrative rights goes first. Each item needs a named owner, because a finding nobody answers for returns in the next review. Fixes applied by hand in the console have to move into the infrastructure code, or the next deployment undoes them.
Reading configuration does not change the state of an environment, so the review itself runs on read-only access. Risk arrives with remediation: narrowing a role or closing a network path can break an integration nobody documented. Role and traffic changes are therefore staged, tried outside production first, and watched through denied-request logs before the old rule is switched off.
A cloud configuration review answers how the environment is set up, not whether someone can break into it. The reviewer works from inside the account and sees policies, roles and service settings an attacker never sees, while a penetration test approaches from outside and proves impact. A second misreading concerns platform certifications: they cover the provider layer, not your configuration.
The contract should name the accounts and services under watch and the rule set used to judge configuration. It also needs the notification path for detected drift, a split between who may change something inside your accounts and who may only report it, and how access is withdrawn once the engagement ends. Add a clause keeping reports and monitoring data readable without provider tooling.
A configuration review works on metadata - resource names, policies, network rules and log entries - not on the contents of databases and storage. Read access to stored objects is a separate decision and is rarely needed for this work. Settle up front where collected findings are held, how long the provider keeps them, and whether accounts created for the review are removed afterwards.
Liability for a leak from a resource your organisation configured stays with your organisation, even though the hardware belongs to someone else. The platform owns the physical layer and virtualisation, which providers set out in their shared responsibility model. The auditor is bound by the contract, which normally promises diligence in carrying out the review rather than a guarantee that the environment is secure.
An offer written for a specific environment names your services and your way of working: the accounts, the platforms, whether containers are in use and how changes reach production. A generic one talks about good practice and compliance without touching anything you actually run. Ask for a redacted sample report and check whether its remediation steps can be executed as written on your platform.
Not sure which provider fits?
Describe what you need. An enquiry sent from here reaches us only. To reach a provider, send it from the profile of a cloud security company you pick.
You do not need to know the exact category. Describing the problem is enough.
Cybersecurity service categories
Browse the full list of cybersecurity specialisations available in the directory and find the right partner for your organisation.
Infrastructure security covers the rollout and day-to-day running of endpoint, identity and network defences: EDR, MFA, access control and segmentation. The directory lists providers who run such projects from inventory to handover.
A penetration test is an authorised attack on your own system that shows which flaws an intruder would actually use. Compare providers testing web and mobile apps, networks and source code.
GRC and compliance work turns security into a managed system: risk analysis, policies, continuity planning and the evidence an auditor asks for. Browse the providers who run those projects in Poland.
Security awareness programmes, phishing simulations and certification courses for IT staff - from spotting a fake payment request to exam preparation. Compare training providers delivering in Poland.
OT/ICS security protects the plant network, PLC controllers and SCADA stations from incidents that stop production. See providers who work on the shop floor without shutting the line down.
Cloud security means reviewing and tightening how AWS, Azure and GCP accounts are set up: identity, permissions, encryption, containers and deployment pipelines. Browse Polish firms that examine your estate and help close what they find.
Data protection means inventory and classification of data sets, encryption, DLP and key management in a cloud KMS or an HSM. Compare providers that map where your records sit and cut the risk of them leaving the company.
Continuous security monitoring and incident detection: SOC as a Service, MDR, SIEM rollouts and SOAR automation. Find Polish providers that watch your logs around the clock and escalate real attacks.