Skip to main content

Government-grade vCISO partner

KSĮ compliance without checkbox theatre - real security, clear priorities.

Virtual Chief Information Security Officer (vCISO), public-procurement expertise and technical delivery support. We help essential and important entities prepare for KSĮ / NIS2 without the bloat of theatre controls and checkbox carousels.

Communication: LT • EN • RU • PL · Preferred: form and email · Teams on request

KSĮ rollout timeline

Three dates worth marking down

Lithuania's Cybersecurity Law (NIS2 transposition) sets staged requirements. We tune the preparation pace to organisational maturity.

  1. 2025-04-17 Completed

    Entity register

    Cybersecurity entities added to the NKSC register.

  2. 2026-04-17 Up next

    Organisational KSRA requirements

    Organisational cybersecurity risk management measures enter into force. Entities that have not finished preparation must move fast on the remaining stages.

  3. 2027-04-17 Planned

    Technical KSRA + YSII / VII

    Mandatory compliance with technical requirements and with measures for critical information infrastructure and state information resources.

Source: NKSC and the implementing acts of Lithuania's Cybersecurity Law. YSII and VII entities are subject to special requirements. All referenced legal acts are listed on the Legal acts.

What sets us apart

Cheap tick-box services aren't our path

The market is full of formal check-ups with no real added value. Our stance - a strategic partner that helps the organisation reach maturity, not just print a report.

Not checkboxes - real numbers

We don't audit for a certificate on the wall. We deliver a real picture of the state, priorities and a clear remediation plan with deadlines.

IT foundation first - security alongside

Cybersecurity doesn't work without solid IT operations. We won't bury you in alerts without context and an action plan.

Public procurement expertise

10+ years of experience drafting and evaluating public procurement documents - transparent criteria without vendor lock-in.

A network, not a single person

If one link doesn't fit - we swap it. Partners: major LT vendors (Blue Bridge MSP, Avedus, Baltimax, NRD CS) + independent experts.

Pricing guide

A clear start, then a maturity path

We publish indicative starting prices so budget planning is easier. Final scope is agreed based on seat count, selected Microsoft 365 or Google Workspace plans, current infrastructure and the KSĮ / NIS2 maturity target.

Important boundaries

  • Listed prices are indicative and exclude VAT. Per-seat prices apply with a 12-month agreement.
  • Monthly scans apply only to websites and public resources managed through our Cloudflare configuration.
  • Internal network scans, deep pentesting, business-specific systems or legacy software are scoped separately.
Start Applies with a 12-month agreement

Technical security start

Baseline protection for workstations and public web resources when practical hygiene needs to be put in place without an oversized project.

  • Cloudflare DDoS/WAF protection for a website or public web resource.
  • Cloudflare Zero Trust access for sensitive web resources: admin panels, internal portals and staging environments.
  • Antivirus with XDR functionality for workstations and NKSC DNS firewall configuration for baseline malicious-site blocking.
  • Monthly vulnerability checks for resources managed under our Cloudflare configuration.

9 €/month excl. VAT / seat

Applies with a 12-month agreement

Extended Applies with a 12-month agreement

Extended workstation protection

A broader protection and administration scope for organisations that want to tighten identity, email, updates and data protection.

  • Microsoft 365 or Google Workspace security configuration based on the selected plan.
  • Email security: MFA, anti-phishing, SPF/DKIM/DMARC and security policies.
  • Software update control for managed software and centrally supported applications.
  • Backup, DLP, XDR and administration scope based on selected security modules.

23–49 €/month excl. VAT / seat

Applies with a 12-month agreement

Oversight Monthly partnership

vCISO / KSĮ oversight

An ongoing security governance function for management, the IT team and suppliers when tools alone are not enough.

  • Monthly review of risks, work items and incidents.
  • Management reporting and a priority plan for the IT team.
  • Review of supplier, contract and public-procurement security criteria.
  • Maintenance of KSĮ / NIS2 evidence and responsibility mapping.

from 990 €/month excl. VAT

Monthly partnership

Project Fixed-scope stage

KSĮ / NIS2 sprint

A fast compliance and technical-maturity stage when leadership needs a clear plan through 2027.

  • Gap analysis against KSĮ / NIS2, CIS and the practical IT operating context.
  • Remediation roadmap with priorities, deadlines and responsibilities.
  • Initial set of documents, policies and audit evidence.
  • Recommendations for public procurement and supplier control.

from 2,900 € excl. VAT

Fixed-scope stage

How we work

A clear process without unnecessary stages, so management and the IT team can make decisions easily.

01

Situation diagnosis

We assess the current state of IT operations, responsibilities and critical gaps.

02

Priorities plan

We deliver a clear action plan with deadlines, resources and risks.

03

Delivery

We work alongside your team and partners so the plan turns into a working result.

04

Continuous maturity

We maintain compliance and review controls periodically against current practice.

Reference points

Frameworks we lean on

We don't treat any one framework as dogma. We pick a blend based on the organisation's maturity, sector regulation and real risk picture. Specific legal references are gathered on the Legal acts.

KSĮ

Lithuanian Cybersecurity Law

Lithuania's transposition of NIS2. Supervised by NKSC. The primary compliance framework for essential and important entities.

NIS2

EU Network and Information Systems Directive

Foundation of KSĮ. We use it as the reference point for risk management and management accountability.

CIS v8

Critical Security Controls

18 controls, 3 implementation groups (IG1–IG3). A practical map from baseline hygiene to maturity.

SIM3

Security Incident Management Maturity

44 parameters across four axes (organisation, people, tools, processes). We use it to assess SOC / CSIRT maturity.

ISO 27001

Information Security Management

The reference point for the certification journey, when formal recognition matters to the client.

MITRE ATT&CK

Adversary tactics & techniques

We use it to model adversary behaviour, assess the attack surface and identify detection gaps.

Who it's for

One document - different readers

We deliberately write so that within a single document the CEO and the sysadmin each find their relevant layer. No one has to translate security-speak.

  • CEO and the board - business risk and deadlines
  • IT lead - priorities and budget direction
  • CISO / security team - controls and evidence
  • Sysadmin / DevOps - a practical delivery plan

Priority sectors

Who we work with

We work with organisations that need a practical path to compliance and stable IT operations. We focus specifically on essential and important entities under KSĮ.

Public sectorHealthcareLogisticsEnergySMBInternational branches in Lithuania

Competency as a trust signal

We publish the team's competencies, not personal profiles. Focus on results, experience and technical accountability.

CISO and vCISO
IT support / RMM
DevOps and DevSecOps
SOC consulting
GRC and compliance
Incident management

Recommended training for the team: mokymai.nksc.lt

Technology ecosystem

CloudflareMicrosoftESETFortinetVMwareExtraHopCheck PointPDQ

IT maturity self-assessment

The refreshed self-assessment page helps you quickly gauge your state against KSĮ, CIS, SIM3 principles.

Open self-assessment

Let's start from where you are

The main contact channel is the inquiry form or direct email. After an initial assessment we continue by email or schedule a Teams call. A human reply - within one business day.

Email: info@saugok.it

Operating model: Lithuania (base), Baltic states and the EU (on request)

Data protection: HTTPS in transit, stored in EU / EEA infrastructure (Cloudflare)

Encryption: post-quantum TLS - we prepare for the quantum era ahead of time.

Note on confidentiality

Don't share sensitive information in the form (incident details, credentials). After initial contact we'll agree on a safer channel - signed email, NDA or encrypted transfer.

Service inquiry

The form is the main contact channel. Share context and we'll come back with a clear action plan.

Demo version - form submission is not yet wired up. After full activation we'll switch on Cloudflare Turnstile (visible only on abuse signals) and automated acknowledgement. For now please email us directly at info@saugok.it.