Cybersecurity FAQ for Businesses – Frequently Asked Questions

Cybersecurity is not only about penetration testing or security audits. It also encompasses compliance with regulations, information protection, risk management, and building organizational resilience against cyber threats.
We have prepared answers to the questions most frequently asked by our clients before starting cooperation. Here you will find information regarding penetration testing, security audits, Red Teaming, vCISO services, NIS2, OSINT, OPSEC, and other IT security-related topics.

Select a topic of interest

Security audits

Penetration testing

Red Teaming and social engineering tests

OSINT

Security audits

Penetration testing

Red Teaming and social engineering tests

OSINT

Cybersecurity management

(vCISO)

NIS2 and regulatory compliance

OPSEC

How we protect organizations

In this section, we explain how CyberForces helps companies assess their security level, detect vulnerabilities, and evaluate resilience against cyberattacks. Here you will find answers to questions regarding security audits, penetration testing, Red Teaming, and social engineering tests.

Security audits

What is a security audit?

A security audit is an assessment of the level of protection of IT systems, applications, infrastructure, processes, and procedures used in a company. It helps identify weaknesses, determine risks, and plan actions that will enhance data security and business continuity. The scope of such an analysis may cover technical, organizational, and regulatory areas.

When is it worth conducting a security audit?

An audit is worth conducting before implementing new systems, after major changes in the IT environment, following an incident, or as part of periodic security control. It is also a good solution for companies preparing for NIS2, DORA, KRI, ISO 27001, or other standards related to information security management.

How is a security audit different from penetration testing?

An audit analyzes a broad level of security, covering system configuration, procedures, access management, documentation, and compliance with requirements. Penetration testing focuses on practical verification of specific vulnerabilities in an application, system, or infrastructure. In practice, an audit shows where weaknesses may exist, while a pentest checks whether they can be exploited.

What does a security audit cover?

The scope of an audit depends on the project objective, IT environment, and client needs. It may include analysis of infrastructure, applications, system configurations, security policies, access management, backups, incident response processes, and compliance with regulations. The result is a report with risks, recommendations, and priorities for remedial actions.

Penetration testing

What are penetration tests?

Penetration testing, also called pentests, is a controlled attempt to detect and exploit vulnerabilities in an application, system, API, infrastructure, or cloud environment. Their purpose is to verify whether security measures work in practice and whether a potential attacker could gain unauthorized access to data, user accounts, or company resources.

Why is it worth conducting a pentest?

A pentest allows you to verify which vulnerabilities can be exploited in practice and what impact they have on business security. This provides the company with specific information about weaknesses, repair priorities, and actions to mitigate risk. Testing is particularly worth conducting before application deployment, integration with an enterprise client, an audit, or meeting regulatory requirements.

When is it best to conduct penetration testing?

Penetration testing is best conducted before launching a new application, after significant system changes, after cloud migration, or periodically as part of security management. A pentest is also advisable after implementing new features, integrating with external services, or when a client, business partner, or regulator expects confirmation of the security level.

How is a penetration test different from a vulnerability scan?

Vulnerability scanning automatically detects known vulnerabilities in a system, application, or infrastructure. A pentest goes a step further by verifying whether detected weaknesses can be exploited in a controlled attack scenario. A scan provides a quick list of potential problems, while penetration testing shows their significance, impact on the company, and repair priority.

What are the different types of penetration testing?

The type of test depends on the project objective and the level of information provided to testers. In the black box model, testers have minimal knowledge of the system; in grey box, they receive partial information; and in white box, they work with fuller access to documentation, configuration, or code. Pentests may cover web applications, APIs, mobile, infrastructure, cloud, Active Directory, Wi-Fi, or IoT systems.

Are penetration tests safe to perform on production environments?

Yes, penetration testing can be safely conducted in a production environment if the rules, scope, and limitations of actions are established in advance. Before starting work, testing windows, emergency contact, excluded techniques, and the method of responding to unexpected situations are determined. Such preparation reduces the risk of disruptions to system operations.

How long does a pentest take?

The duration of a pentest depends on the scope, number of tested resources, application complexity, number of user roles, and the selected work model. A simple test may take several days, while an extensive project covering an application, API, infrastructure, or cloud requires more time. We establish the schedule individually after analyzing the environment and client expectations.

How much does a pentest cost?

The cost of a pentest depends on the scope, type of system, number of applications, endpoints, IP addresses, user roles, and expected completion date. Contact us – we will provide a quote!

What does a penetration testing report include?

A penetration testing report contains a description of the scope of work, the methodology used, a list of detected vulnerabilities, risk assessment, proof of testing, and remedial recommendations. Depending on needs, it may also include an executive summary for management, detailed reproduction steps for technical teams, and priorities for implementing fixes.

Red Teaming

What is Red Teaming?

Red Teaming is a controlled attack simulation whose purpose is to verify the resilience of people, processes, technologies, and security procedures. Unlike classic technical testing, it encompasses a broader adversary action scenario. It may utilize OSINT, phishing, social engineering, vulnerabilities in systems, applications or infrastructure, and attempts to bypass organizational security measures.

How does Red Team differ from penetration testing?

Penetration testing typically focuses on a specified system, application, or infrastructure segment. Red Teaming assesses the broader resilience of a company against a realistic attack scenario, combining technical, social engineering, and organizational elements. The goal is not only to find vulnerabilities but also to verify whether the security team can detect an attack, respond, and mitigate its effects.

What are social engineering tests?

Social engineering tests verify how employees and procedures respond to attempts at manipulation, impersonation, or information extraction. They may include phishing campaigns, vishing, smishing, fake login pages, employee contact scenarios, or security awareness tests. Their purpose is to assess the company’s resilience against attacks exploiting the human factor.

What is phishing?

Phishing involves impersonating a trusted person, company, or system to induce the recipient to click a link, open an attachment, provide data, or perform a specific action. In security testing, a phishing campaign allows verification of employee awareness, the effectiveness of incident reporting procedures, and team readiness to respond to such attempts.

Can Red Team be combined with a pentest?

Yes, Red Teaming can be combined with penetration testing if the goal is a broader assessment of company resilience. A pentest allows detailed verification of selected applications, systems, or infrastructure, while Red Team shows how various attack techniques can be used in one scenario. This approach works well in more mature security environments.

How we manage security

vCISO

What is vCISO?

vCISO, or virtual Chief Information Security Officer, is an external expert performing an advisory or managerial function in the area of cybersecurity. They support the company in planning security strategy, risk assessment, policy creation, oversight of technical activities, and preparation for regulatory requirements such as NIS2, DORA, or ISO 27001.

Who is the vCISO service for?

The vCISO service is intended for companies that need expert support in cybersecurity but do not want to or cannot hire a full-time CISO. It works well in organizations developing security structures, preparing for an audit, implementing NIS2, expanding into new markets, or cooperating with enterprise clients.

What does cooperation with vCISO look like?

Cooperation with vCISO begins with an assessment of the current security level, business needs, and regulatory requirements. Next, the scope of support, action priorities, and work schedule are established. vCISO can operate strategically, in an advisory capacity, or operationally, supporting management, IT department, compliance, and those responsible for information security.

What responsibilities does vCISO assume?

vCISO can support the company in risk management, security policy creation, audit oversight, penetration testing planning, incident analysis, and preparing the organization for legal and industry requirements. The scope of responsibilities depends on client needs and may include both strategic consulting and ongoing coordination of security activities.

Does vCISO help implement NIS2?

Yes, vCISO can help an organization prepare for NIS2 requirements by assessing the current security level, identifying gaps, developing an action plan, and supporting the implementation of appropriate procedures. They can also coordinate work related to risk analysis, documentation, incident management, training, and periodic security assessment.

Does vCISO support during audits?

Yes, vCISO can support the organization before an audit, during it, and after completion of audit work. They help prepare documentation, organize processes, gather required information, and explain auditor findings to business and technical teams. After the audit, they can also help plan remedial actions and assign appropriate priorities.

How much does the vCISO service cost?

The cost of vCISO service depends on the scope of support, organization size, security maturity level, number of systems, and expected expert availability. Advisory services for a few hours per month are priced differently than ongoing cooperation covering strategy, audits, NIS2, risk analysis, and current security management. Therefore, the scope and cost are established individually.

How to meet regulatory requirements

In this section, we answer questions regarding NIS2, KSC, DORA, compliance audits, and actions that help organizations prepare for legal and industry requirements in the area of cybersecurity.

NIS2, KSC, DORA, and compliance audits

What is the NIS2 directive?

NIS2 is an EU directive whose purpose is to raise the level of cybersecurity in key economic sectors. It includes requirements regarding risk management, incident reporting, supply chain security, business continuity, and management responsibility. In Poland, its implementation is linked to the amendment of the National Cybersecurity System Act, or KSC.

Who does NIS2 apply to?

NIS2 applies to essential and important entities operating in sectors significant for the economy and state security. It may include energy, transport, healthcare, public administration, digital infrastructure, ICT services, water supply, banking, industry, food, or selected digital services. In Poland, the scope of obligations is defined by the KSC amendment.

How to prepare an organization for NIS2?

Preparation for NIS2 should begin by verifying whether the organization is subject to new requirements, followed by conducting a gap analysis. The next step is risk assessment, organizing documentation, implementing security procedures, preparing an incident handling process, and planning periodic security verification. Audits, penetration testing, training, and vCISO support are also helpful.

Does NIS2 require penetration testing?

NIS2 does not reduce cybersecurity solely to penetration testing but requires the application of appropriate technical, operational, and organizational measures for risk management. Pentests can be one element confirming that the organization regularly verifies the resilience of applications, systems, and infrastructure. In practice, they often support audits, risk analysis, and preparation for inspections.

How does NIS2 differ from KSC?

NIS2 is a European Union directive that sets common cybersecurity requirements for member states. KSC, or the National Cybersecurity System, is Polish legislation implementing these obligations at the national level. In practice, NIS2 defines the direction and minimum requirements, while KSC specifies how they are to be applied by organizations operating in Poland.

What is DORA?

DORA, or the Digital Operational Resilience Act, is an EU regulation concerning the digital operational resilience of the financial sector. It covers ICT risk management, incident handling, resilience testing, oversight of technology providers, and business continuity. It applies to banks, investment firms, insurers, and other financial entities. The regulation applies from January 17, 2025.

What does a compliance audit look like?

A compliance audit involves verifying whether an organization meets the requirements of specific regulations, norms, or standards such as NIS2, KSC, DORA, KRI, or ISO 27001. The work includes analysis of documentation, processes, technical security measures, risk management, incident handling, and organizational responsibilities. The result is a report with gaps, risks, and recommendations for remedial actions.

Do you help prepare an organization for an audit?

Yes, we support organizations before an audit, during it, and after completion of audit work. We help organize documentation, identify gaps, prepare required procedures, assess security measures, and plan remedial actions. Support may also include penetration testing, risk analysis, training, technical consulting, and vCISO advisory services.

What services support compliance with NIS2 and DORA?

Compliance with NIS2 and DORA can be supported by security audits, risk analysis, penetration testing, documentation review, implementation or optimization of ISMS, vCISO service, training, and support in incident management. In the case of DORA, actions related to ICT operational resilience, security testing, and assessment of technology providers are also important.

How often should the security level be verified?

The security level should be verified regularly, as well as after significant changes in systems, infrastructure, processes, or the company’s operating model. Periodic audits, penetration testing, risk reviews, and training help maintain compliance with requirements and detect gaps more quickly. The frequency of such actions should depend on the industry, scale of operations, regulations, and risk level.

How to protect information

In this section, we explain how OSINT and OPSEC help companies better protect data, reduce digital footprint, and decrease the risk of information leakage. These are areas particularly important for organizations that want to verify what data about them is publicly available and how it can be used by attackers.

OSINT

What is OSINT?

OSINT, or Open Source Intelligence, is the acquisition and analysis of information available in open sources. These may include websites, social media, public registers, search engines, forums, code repositories, file metadata, or technical data regarding infrastructure. In cybersecurity, OSINT helps verify what information about the company, employees, and systems is visible from the outside.

Is OSINT legal?

OSINT is legal if it is based on publicly available information and is conducted in accordance with the law, source terms of service, and ethical principles. Analysis of open data should not include breaking security measures, bypassing access controls, or obtaining information in an unauthorized manner. In security projects, the scope of OSINT activities should be clearly defined before starting work.

How do companies use OSINT?

Companies use OSINT to assess their own digital footprint, identify potential sources of information leakage, and verify what data can be used in an attack. Analysis can support security testing, Red Teaming, brand exposure assessment, protection of management personnel, and preparation for social engineering campaigns. This helps the organization better understand what is visible about it on the internet.

What information can be found using OSINT?

Using OSINT, one can find information about domains, IP addresses, technologies used on a website, employees, organizational structure, public documents, metadata, social media accounts, code repositories, or data leaks. Some of this information may seem harmless, but when combined, it creates a picture useful for preparing an attack.

Does OSINT help during security testing?

Yes, OSINT helps prepare security tests because it shows what information about the company is publicly available before starting technical activities. It can indicate potential targets, technologies, people, email addresses, domains, services exposed to the internet, or data used in social engineering. This makes tests better reflect the attacker’s method of operation.

How to reduce a company's digital footprint?

A company’s digital footprint can be reduced through regular review of information published on the internet, control of document metadata, organizing employee visibility online, and monitoring data leaks. It is also important to remove unnecessary resources, limit public exposure of systems, and educate the team on safe information publishing.

OPSEC

What is OPSEC?

OPSEC, or Operational Security, is an approach to information protection that involves identifying data that may reveal too much about a company, its employees, processes, or security measures. The purpose of OPSEC is to reduce the risk that seemingly minor information will be combined and used for an attack, data extraction, or bypassing security procedures.

Why is OPSEC important?

OPSEC is important because many attacks begin with analysis of publicly available information or accidentally disclosed by employees. Data about company structure, technologies, suppliers, projects, locations, or procedures can facilitate phishing, social engineering attacks, or preparation of a Red Team scenario. Good OPSEC practices help reduce such risk.

How to implement OPSEC?

Implementing OPSEC should begin with identifying information that is particularly important for company security. Next, it is necessary to verify where such data may be disclosed, e.g., on social media, in documents, job postings, presentations, or repositories. The next step is to develop information publishing rules, train employees, and regularly monitor the digital footprint.

What are the most common OPSEC mistakes?

The most common OPSEC mistakes include publishing overly detailed information about technologies, projects, team structure, suppliers, locations, and procedures. Problems also include metadata in documents, uncontrolled social media posts, public code repositories, photos with visible identifiers or screens, and lack of rules regarding external information sharing.

How does OPSEC help reduce the risk of information leakage?

OPSEC helps reduce the risk of leakage because it teaches the organization to recognize information that can be used against it. This allows the company to better control what it publishes, what data employees share, and which processes require additional protection. Good OPSEC practices reduce the amount of information available to potential attackers.

How does OPSEC differ from cybersecurity?

Cybersecurity encompasses protection of systems, networks, applications, and data against digital threats. OPSEC focuses primarily on protecting operational information that may reveal the company’s method of operation, its processes, technologies, or weaknesses. It can be said that OPSEC complements cybersecurity by helping reduce data that could facilitate attack preparation.

How do OSINT and OPSEC complement each other in practice?

OSINT shows what information about the company is publicly available, while OPSEC helps limit its excessive disclosure. In practice, OSINT analysis can indicate data that requires organization, removal, or better control. OPSEC translates these findings into rules, procedures, and educational activities that reduce the organization’s digital footprint.

Did not find an answer?

If you did not find an answer to your question, contact our team.
We will help select the appropriate service and explain what actions will be best for your organization.