# Pro CISO® > Pro CISO® is an ISO 27001 and ISO 9001 certified cybersecurity consultancy founded in Amsterdam. We provide AI Development, CISO-as-a-Service, a managed SOC Service, security assessments, and penetration testing for enterprises and mid-market organisations operating under EU regulatory frameworks. Pro CISO® was founded in 2020 and holds ISO/IEC 27001:2022 and ISO/IEC 9001:2015 certifications from SwissCert. We are a Microsoft AI Cloud Partner. Our proprietary CA/CR® (Continuous Assessment / Continuous Remediation) methodology underpins all engagements. Pro CISO® develops its own software platforms in-house using AI, and helps customers do the same. ## Services - [AI Development](https://prociso.com/services/ai-development): AI development, AI governance and enablement from a cybersecurity company that builds its own platforms with AI. Covers EU AI Act (Regulation (EU) 2024/1689) governance, AI governance and Secure Development with AI policies, training and workshops on which AI tools are effective for which business use case, and helping customers move from SaaS subscriptions to in-house applications they own completely. Delivery disciplines: structured Markdown documentation as the source of truth, secure GitHub repository setup, development/production segregation, human review and approval gates in the Secure SDLC, and long-term maintainability. Aligned to the EU AI Act, ISO/IEC 42001:2023, ISO/IEC 23894:2023, NIST AI RMF 1.0 (incl. the Generative AI Profile, NIST AI 600-1), the OWASP Top 10 for LLM Applications, NIST SSDF (SP 800-218 and SP 800-218A), the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and ISO/IEC 27001:2022 controls A.8.25-A.8.34. - [CISO-as-a-Service](https://prociso.com/services/ciso-as-a-service): A dedicated virtual CISO augmented by a pool of vertical cybersecurity experts. Covers full security programme management including ISO 27001, NIS2, DORA, NIST CSF and GDPR compliance. Fixed monthly retainer, no hidden day-rates. - [EU Regulations Assessments](https://prociso.com/services/eu-regulations-assessments): Fixed-price readiness assessments against the four EU regulations reshaping European business: GDPR (Regulation (EU) 2016/679), NIS2 (Directive (EU) 2022/2555), DORA (Regulation (EU) 2022/2554) and the EU AI Act (Regulation (EU) 2024/1689). Every regulation clause is covered and rewritten into simplified, plain-language controls. Executed completely online through the CA/CR® CISO Console (no spreadsheets / no XLS). Coverage: GDPR (10 domains / 33 controls), NIS2 (8 domains / 29 controls), DORA (6 domains / 28 controls), EU AI Act (8 domains / 28 controls). Light-weight and highly efficient because it runs on Pro CISO's own assessment engine. Results are delivered as a detailed report covering overall compliance posture, areas of weakness, implemented countermeasures and a prioritised remediation action plan. Fixed price of €4,500 per assessment. - [SOC Service](https://prociso.com/services/soc-service): Managed security operations built on four pillars. (1) M365 Security Posture: 100+ CIS benchmark controls, MFA coverage across every account, Conditional Access design and enforcement, licence-to-usage mapping and Shadow IT / SaaS discovery, delivered through our Microsoft CSP platform. Microsoft 365 is the front door attackers actually use - a single click on a phishing link, or an AI prompt-injection attack delivered by email, is enough to put someone inside the tenant, where they browse the organisation like an employee, identify the CFO, accounting team and purchase approvers, send internal phishing that passes every authentication check, and issue legitimate-looking invoices with altered payment details. (2) M365 Security Alerts: continuous Entra ID monitoring for risky sign-ins, impossible travel, password-spray patterns, MFA method registration, inbox rule creation and forwarding, suspicious OAuth consent grants and privileged role assignment. (3) Attack Surface Management on our own CA/CR® ReconX platform, across nine modules - Domain Mapping, Discovery, Vulnerability, Web Audit, Reputation, 3rd-Party Risk, Identity, Internal Posture and Reports - combining external scanning with internal vulnerability scanning and Linux server health checks through a signed host agent. (4) Alerting and Incident Response on our own CA/CR® ProDesk platform: alert ingestion from email, SIEM, EDR and PSA connectors, normalisation and severity scoring, rule-based filtering of known-benign patterns, human analyst triage, and SLA-tracked resolution with escalation. The service exists to correlate weak signals across all four pillars - an exposed credential found by ReconX alongside failed M365 sign-ins on the same account is an attacker mid-attempt, though each alert alone is routinely dismissed. From €5,900 per month. - [Security Assessments](https://prociso.com/services/security-assessments): Security Posture Assessment and Framework Compliance Readiness using the CA/CR® methodology. Digital CISO dashboard - no spreadsheets. Frameworks covered: ISO 27001, NIS2, DORA, NIST CSF, CIS Controls. Fixed-price engagements from €3,600. - [Pentest Fusion](https://prociso.com/services/penetration-testing): Integrated Threat Modelling and Penetration Testing. White-box, grey-box, black-box and red team engagements for software development teams and enterprise environments. Fixed-price quoted upfront. ## Products Pro CISO® designs, builds and operates its own platforms in-house - all developed with AI under the practices described in our AI Development service. - [CA/CR® CISO Console](https://cacr.prociso.com): Our flagship security posture management platform for CISOs and vCISOs. Multi-entity management for parent companies, subsidiaries and business units; standards and regulation mapping across ISO 27001, NIST CSF, PCI-DSS, CIS, NIS2, DORA, GDPR and the EU AI Act; assessment and remediation campaign engine; risk and incident registers with regulatory reporting flags; a policy library of 40+ templates across 19 security domains; third-party risk management; CISO dashboards; and audit-ready, version-controlled PDF reporting. - [CA/CR® ReconX](https://reconx.prociso.com): Attack Surface Management (external plus internal posture), multi-entity by design, organised into nine modules. Domain Mapping (WHOIS, registrar and expiry tracking, DNS resolved against authoritative nameservers, ASN attribution, Certificate Transparency, and SPF/DKIM/DMARC/DNSSEC/STARTTLS posture each with a "failing since" date); Discovery (host resolution, structural subdomain discovery, tiered port scanning, web application fingerprinting, with shared SaaS and CDN infrastructure excluded from the score); Vulnerability (template-driven active scanning enriched with CVSS, EPSS, CISA KEV, CWE and SSVC decision priority, with full finding lifecycle including regression detection); Web Audit (~44 checks covering security headers, CORS, cookie flags, exposed .git/.env/debug modes/source maps, leaked secrets and RFC 9116 security.txt, deduplicated by response rather than hostname); Reputation (blocklist and DNSBL monitoring across 16 sources with a test-point probe, look-alike and typosquat detection backed by Certificate Transparency, automated screenshots); 3rd-Party Risk (sandboxed independent vendor scorecards, host-weighted scoring, no grade published without evidence, staleness tracking); Identity (breach and combolist exposure, stealer-log intelligence with infected-host context, VIP correlation, severity dated from the compromise rather than discovery); Internal Posture (signed host agent providing distribution-aware patch status, failed services, resource thresholds, file integrity monitoring by hash and security log review, where an unavailable check is itself reported as a finding); and Reports (on-demand and scheduled PDF reporting per entity with time-limited external sharing). - [CA/CR® ProDesk](https://prodesk.prociso.com): Security alert and ticket management - the desk Pro CISO® analysts work in. Ingests alerts from email, SIEM, EDR and PSA connectors, and from any tool that can send an email alert; connecting a source takes minutes and needs no agent on the customer estate. Whatever the source, alerts arrive in one consistent shape: what happened, what it affects, how serious it is, and which location it belongs to. Alerts are normalised and severity-scored, known-benign patterns are closed by rule, repeats join one thread rather than becoming separate tickets, and what remains is triaged by an analyst into a ticket with an owner, a severity and an SLA clock. A single queue across all sites with each client's data strictly separated, response times reported against, a complete and exportable audit trail, and scheduled or on-demand reporting on volumes, response times and trend. ## Methodology The CA/CR® (Continuous Assessment / Continuous Remediation) framework is Pro CISO®'s proprietary cybersecurity management methodology. It integrates threat modelling, controls assurance, and continuous improvement into a single programme. All Pro CISO® engagements and the CA/CR® platforms are built on this methodology. ## Regulatory Expertise Pro CISO® specialises in EU cybersecurity and data protection regulation. Readiness against the four core EU regulations can be measured directly through our fixed-price [EU Regulations Assessments](https://prociso.com/services/eu-regulations-assessments) service (€4,500 per assessment): - **GDPR** (Regulation (EU) 2016/679 - General Data Protection Regulation): Data protection programme support aligned with security controls. Assessment coverage: 10 domains / 33 controls. - **NIS2** (Directive (EU) 2022/2555 - Network and Information Security Directive 2): Compliance readiness, gap assessments, and ongoing programme management for organisations in scope. Assessment coverage: 8 domains / 29 controls. - **DORA** (Regulation (EU) 2022/2554 - Digital Operational Resilience Act): ICT risk management, incident reporting, and third-party risk frameworks for financial entities. Assessment coverage: 6 domains / 28 controls. - **EU AI Act** (Regulation (EU) 2024/1689 - Artificial Intelligence Act): Readiness assessment plus security risk assessments for AI deployments including Microsoft Copilot and Claude Desktop enterprise environments. Assessment coverage: 8 domains / 28 controls. - **ISO/IEC 27001:2022**: Certification readiness, gap assessments, and maintained ISMS programmes. - **NIST CSF**: Framework implementation and continuous assessment. - **CIS Controls**: Benchmark hardening, particularly for Microsoft 365 environments. ## Publications and Insights Pro CISO® publishes whitepapers, service briefs, and thought leadership available at https://prociso.com/#insights. Titles include: - AI Security: Microsoft Copilot Enterprise Risk Assessment - AI Security: Claude Desktop Enterprise Risk Assessment - CA/CR® PenTest Fusion methodology brief - Cyber Resilience in a Remote Work Era - Cyber Sustainability: Securing Our Digital Future - Guide to Risk Management - Simplified Cybersecurity Management - Inside Ethical Hacking - Hack-Proof Your Team ## News - [Cybersecurity & AI News](https://prociso.com/news): Curated cybersecurity, AI, and EU regulatory news for CISOs. Updated hourly from reputable sources covering NIS2, DORA, GDPR, AI Act, and threat intelligence. ## Contact and Location - Website: https://prociso.com - Email: info@prociso.com - Phone: +31 20 211 7467 - Address: Amsterdam, The Netherlands - LinkedIn: https://www.linkedin.com/company/prociso - Security vulnerability reporting: https://prociso.com/security-reporting