SOC.STATUS = OPERATIONAL NODE = PORTUGAL · UPLINK = EU-CORE CIPHER = NIS2 · DORA · GDPR · ISO/IEC 27001 // EMERGENCY_LINE >_
// SYS:ACTA.CORE  BUILD:2026.05.22  LAT:48.148°N  LON:17.107°E UPLINK > STABLE LATENCY > 14 ms SOC > ARMED
OFFENSIVE · DEFENSIVE · EU-RESIDENT

Get
hacked.

On your terms.

> Acta Security is an EU-based cybersecurity unit that breaks into your business before someone else does — then sticks around to make sure they can't. Operators on the keyboard. Not consultants on the slide deck.

RESPONSE_TIME
<24H
ENGAGEMENTS
240+
RENEWAL_RATE
9/10
DATA_RESIDENCY
EU & SOUTH AFRICA
// FRAMEWORKS
NIS2× DORA× GDPR× ISO/IEC 27001× TIBER-EU× OWASP ASVS× MITRE ATT&CK
/ 01_SERVICES

Six practices.
One mandate
keep you unhackable.

// Pick one engagement or compose a program. Every project is led by a senior operator and scoped to your real attack surface.

01 // OFFENSIVE

Break in first.

Penetration testing, red-team operations and adversary emulation against the parts of your business that actually matter. Goal-based. Not checklist-based.

WEB · API · MOBILECLOUD · K8SACTIVE DIRECTORYPHISHING / MFA BYPASS
02 // DEFENSIVE

Make sure they can't.

Posture assessments, SOC tuning, detection engineering and incident response. We harden what the offensive side found — and what your next attacker hasn't.

DETECTION ENG.SOC UPLIFTIR RETAINERPURPLE TEAM
03 // PRIVACY · COMPLIANCE

EU-grade by design.

GDPR, NIS2, DORA and ISO 27001 — written by people who also break systems for a living. Regulation translated into concrete engineering work. No policy theatre.

GDPR AUDITSNIS2 READINESSDORA PROGRAMSDPO-AS-A-SERVICE
04 // THREAT INTELLIGENCE

See them coming.

Continuous monitoring of surface, deep and dark web for credentials, brand abuse and chatter about your sector. Attribution-grade reporting. Not RSS scraping.

BRAND / EXEC EXPOSURECREDENTIAL LEAKSDARK-WEB HUMINTSECTOR TI FEEDS
05 // TRAINING

Human firewall.

Phishing simulations, secure-coding workshops, executive tabletop exercises and board briefings. Real attacks rehearsed in safe conditions — in your language.

PHISHING SIMSTABLETOP DRILLSSEC-DEV WORKSHOPSBOARD BRIEFINGS
06 // vCISO · ADVISORY

CISO on retainer.

Fractional and interim CISO leadership, security strategy, M&A diligence and board-level reporting. Embedded enough to own outcomes. Light enough to scale.

vCISOSECURITY STRATEGYM&A DILIGENCEBOARD REPORTING
// EMERGENCY RESPONSE

You're under attack.
We're already moving.

// If you suspect or confirm an active incident, connect via SimpleX Chat below. We answer within a few hours, typically under 1 hour — including weekends and holidays.

// How to connect

  1. Install SimpleX Chat — not Signal or Session.
  2. Open the link below in the app, or scan the QR code →
SIMPLEX https://simplex.actasecurity.eu/ir

// Auto-accept welcome message

ACTA IR // SEALED CHANNEL OPEN You are connected to Acta Security Incident Response. Briefly: organisation, what you suspect, when it started. An operator will respond within a few hours, typically under 1 hour.

// end-to-end encrypted · no phone number · no account

// routed through ACTA-operated relays in EU (smp.actasecurity.eu)

/ 02_APPROACH

Five phases.
Repeated until you're boring to attack.

// Every project follows the same backbone — scoped to your sector, regulator and risk appetite.

PHASE_01

Recon · scoping

We map your true attack surface — cloud, code, identity, third parties, people — and agree the rules of engagement with you. No surprises. No scope creep.

↳ 3–5 DAYS
PHASE_02

Offensive engagement

Senior operators execute the agreed playbook — pentest, red team or full adversary emulation — chaining real-world vectors against real business outcomes.

↳ 2–6 WEEKS
PHASE_03

Findings · debrief

Written and live debriefs for two audiences: engineers get reproducible exploit chains; the board gets a one-page risk picture in plain language.

↳ 1 WEEK
PHASE_04

Defensive uplift

We sit with your team and close the gaps — detection rules, hardened configs, IR playbooks. Where helpful, we go purple and run the attack against the new defences.

↳ 4–8 WEEKS
PHASE_05

Continuous assurance

Monthly threat-intel briefings, quarterly retesting, on-demand IR support. The goal isn't a clean report — it's a moving target.

↳ ONGOING
/ 03_OPS

Small team.
Already done it
usually to someone bigger.

// No subcontracting. No junior pyramid. The names on the proposal are the people on the keyboard.

240+
ENGAGEMENTS_DELIVERED
2H
MEDIAN_IR_RESPONSE
9/10
CLIENT_RENEWAL
EU & SOUTH AFRICA
DATA · OPERATORS
/ MANIFESTO

// A short list of things we believe — written down so we can be held to them.

We don't pad scope. We don't pad reports. We don't pad invoices.
A clean report is not the goal. A boring attack surface is.
Compliance is the floor, not the ceiling. NIS2 won't stop the breach — the work behind it might.
Your data stays in the EU. So do we. So does the chain of custody.
We tell you what we found, what we couldn't find, and what we didn't have time to look for. The third one matters most.
No subcontractors. No junior pyramid. The name on the proposal is the name on the keyboard.
When we're wrong, we say so — in writing, before you notice.
— Acta team PORTO / PORTUGAL / REMOTE EU & SOUTH AFRICA
/ 04_START

Don't wait for the
breach notification.

// Thirty minutes with a senior operator. No pitch deck, no NDA gymnastics — just a frank look at where you'd lose first, and what we'd do about it.

// CONTACT_FORM UPLINK SECURE
.--/ press transmit to send securely
// BOOK_ASSESSMENT 30 MIN · MEETERGO