Building A Culture Of Security

Cyber security, resilience, Gap Analysis and AI Governance for organisations that treat information security as an ethical value before it is a service or a product. Strategic consulting, CISO as a Service, real data breach exposure testing, cyber incident handling and internationally certified training.

No sign-up · Downloadable report · ~10 minutes

Training · Enrolment open

Ethical Hacker Course

A complete path in ethical hacking and offensive security: learn to think like an attacker to truly defend organisations. Seventeen modules covering the full spectrum of modern techniques, fully online and live.

  • 17 modules, from fundamentals to advanced techniques
  • 4 intensive days, fully online and live
  • Top-tier instructor, among the most qualified and awarded in the world
  • Final certificate issued by Cyber Industries

Enrolment open · the course starts once the minimum number of participants is reached.

Independent training path developed by Cyber Industries. The course does not include third-party certification exams and is not affiliated with, sponsored by, or endorsed by any certification body.

Training · CISO & Executive

CISO Executive Program

Strategic Cybersecurity Leadership

An executive path to govern cybersecurity as a strategic function: understand risk, define strategy and engage with Top Management and the Board. Not a technician, but a leader.

  • 5 focus areas: CISO role, risk & EU directives, controls & audit, operations & resilience, understanding the attack
  • 4 executive days, online and live
  • Top-tier instructor, among the most qualified and awarded in the world
  • Final certificate issued by Cyber Industries

Enrolment open · the course starts once the minimum number of participants is reached.

Independent training path developed by Cyber Industries. The course does not include third-party certification exams and is not affiliated with, sponsored by, or endorsed by any certification body.

Training · Active Directory

Active Directory Attack & Defense

Attacking and defending the domain, hands-on.

A hands-on course to master attack and defense in Active Directory: 12 hours of guided lab work on real infrastructures. For red teams, blue teams, administrators and incident responders.

  • 12 hours of guided lab work on real infrastructures
  • Attack & defense path: red team and blue team
  • Internationally certified trainers
  • Final certificate issued by Cyber Industries

Enrolment open · the course starts once the minimum number of participants is reached.

Independent training path developed by Cyber Industries. The course does not include third-party certification exams and is not affiliated with, sponsored by, or endorsed by any certification body.

Free tools · No registration

Free Quick Assessments

Twelve questions, five minutes, a downloadable report with score, exposure areas and roadmap. No name, no email: your answers stay in your browser.

Marco Galli
CEO Abstract

Marco Galli

We live in an era where connection is power, but also fragility. Marco Galli guides us to look beyond the surface of the digital world, where security is not just defence but an act of trust between human beings and technology. Innovation is born from the balance between intelligence and sensitivity, between code and conscience. It is in this space that Cyber Industries is building the future of cyber security: human, aware, resilient.

Read the full abstract
What we do

Services

A single certified counterpart for governance, defence and real verification of your security - from strategy to field testing, from regulatory compliance to incident handling.

CISO as a Service

CISO as a Service

A certified CISO at your organisation’s disposal, without the cost and lead time of an in-house hire. Governance, priorities and decisions you can defend in front of the board.

  • Definition of the security strategy and policies
  • Risk analysis and treatment plan
  • Reporting to the board and control bodies
  • Vendor and third-party governance
  • Ongoing cover or agreed days per month
Download the brochure
Cyber Incident & Ransomware

Cyber Incident & Ransomware

When the incident is already under way, time is everything. We coordinate the crisis unit and restore operations, collecting the evidence required for statutory notifications.

  • Activation and coordination of the crisis unit
  • Containment and isolation of affected systems
  • Forensic analysis and attack reconstruction
  • Restoration of operations and lessons learned
Download the brochure
Penetration Test

Penetration Test

A controlled attack carried out by OSCP- and C|EH-certified professionals using the same techniques as a real adversary, to demonstrate what an intruder could actually reach: not a list of alerts, but concrete proof of impact.

  • External perimeter, internal network and Active Directory
  • Web applications, APIs and mobile apps according to OWASP
  • Black, grey or white box, as agreed
  • Verified exploitation of vulnerabilities, without damage to systems
  • Technical and executive report with remediation priorities and retest included
Request a penetration test
Vulnerability Assessment

Vulnerability Assessment

A complete, periodic picture of the vulnerabilities present across systems, networks and applications, validated by an analyst who removes false positives and ranks findings by real risk, not by automated score.

  • Authenticated scanning of servers, endpoints, network devices and cloud
  • Classification by severity (CVSS), exposure and exploitability
  • Manual verification of findings and removal of false positives
  • Prioritised remediation plan and comparison with the previous scan
  • Quarterly or continuous cycle, also in support of NIS2 and ISO/IEC 27001
Request a vulnerability assessment
NIS2 Gap Analysis

NIS2 Gap Analysis

A precise measurement of the distance between your organisation and the NIS2 obligations, with a concrete action plan to close it within the deadlines.

  • Scope of applicability and the organisation’s role
  • Assessment of the minimum security measures required
  • Notification duties for significant incidents
  • Accountability of the management bodies
  • Remediation plan with priorities and deadlines
Download the brochure
ISO/IEC 27001 Gap Analysis

ISO/IEC 27001 Gap Analysis

Where your information security management system stands today against the standard, and what it actually takes to reach certification with no surprises at audit.

  • Review of the Annex A controls
  • Check of policies, procedures and records
  • Risk analysis and Statement of Applicability
  • Preparation for the certification audit
  • Remediation plan with ownership and timing
Request the gap analysis
Data Recovery

Data Recovery

Recovery of data deleted, corrupted or made unavailable by a ransomware attack, with a documented chain of custody that stands up in court.

  • Recovery from damaged or formatted media
  • Restoration after ransomware encryption
  • Recovery of mailboxes and mail archives
  • Chain of custody and technical report
Download the brochure
Cyber Training

Cyber Training

Certified training recognised worldwide, delivered by an instructor twice awarded by EC-Council among the best trainers in the world.

  • Official EC-Council tracks, C|CISO included
  • Classroom, remote or tailored paths
  • Hands-on labs on real environments
  • Exam preparation and sitting
Download the brochure
Active Directory Attack & Defense

Active Directory Attack & Defense

A hands-on course to become an expert in attacking and defending Active Directory: 12 hours of guided lab work on real infrastructures, delivered by internationally certified trainers. For red teams, blue teams, administrators and incident responders; accessible with basic knowledge of AD and Windows.

  • AD enumeration: users, groups, GPOs, ACLs and intra/inter-forest trusts
  • Privilege escalation, domain persistence and cross-trust attacks
  • Kerberos (Golden, Silver and Diamond tickets), Kerberoasting, DCSync, Skeleton key
  • How attacks are detected, and bypassing Defender, AMSI and EDR
  • Mitigations, useful logging and deception to reduce real risk
  • 12 hours via video conference: 2 days of 6 hours or 3 days of 4 hours
Download the brochure
Proprietary method · Real verificationFeatured

Data Breach Simulator

Are you sure your Cyber strategy really protects you? We verify whether your protection systems - MDR, SOC, XDR - actually defend the business, using attack techniques those systems have never seen. We find out in the lab, not during a real incident.

  • Real attack, controlled environment - no risk to operations, no theoretical simulation
  • Evidence, not opinions - what was detected, what got through, and how long it took
  • A report you can use - results the board can read and the IT team can act on
GITEX AI Singapore · April 2026Successfully presented at the GITEX AI international exhibition in Singapore, to industry operators and investors.
What we actually test
  • Data Breach Exfiltration Test
  • Ransomware Test
  • Trojan Test and system takeover
  • MDR Test
  • SOC Test
  • AV / EDR / XDR Test
ExfiltrationEncryptionTakeoverDetection GITEX AI Singapore 2026
Proprietary programme · OnlyWay™Featured

OnlyWay™

Many companies invest in technology without knowing how effective it really is. OnlyWay™ answers the fundamental question: is your organisation actually protected, or does it only think it is? An integrated path across strategic consulting, data breach exposure testing and specialist training for the IT department.

  • CISO consulting - governance, priorities and decisions you can defend in front of the board
  • Data Breach simulation - field verification of the defences that are actually active
  • Advanced IT training - operational skills for the team that runs the systems
  • Awareness for management - risk exposure expressed in business terms
Why choose OnlyWay™
1

Assess the existing defences

Not what the vendors claim, but what the systems actually do under attack.

2

Raise cyber maturity

From incident reaction to structured prevention, along a measurable path.

3

Strengthen the IT team

The skills stay in-house: the people running the systems learn to spot and react.

GovernanceSimulationTrainingBoard reporting
New service · ADG Framework

AI Governance & Security Assessment

Artificial intelligence is already inside your organisation: in your processes, in your vendors’ tools, in the data that leaves the perimeter every day. Governing it is no longer a strategic option, it is a regulatory obligation. We measure your AI maturity with a structured method and hand you the route to compliance before the deadlines arrive.

  • 12 Minimum Controls - a precise assessment of the minimum controls across AI adoption, defence and governance
  • Gap analysis and risk heatmap - where you are exposed, how much it weighs, in which order to act
  • Regulatory crosswalk - EU AI Act (Reg. EU 2024/1689), NIST AI RMF, ISO/IEC 42001
  • Remediation roadmap - concrete actions, ownership and priorities, not a list of good intentions
  • Shadow AI and data leakage - which AI tools are in use and what data they are processing
The ADG model
A

Adopt

Adopt AI with judgement: use cases, vendor assessment, risk classification.

D

Defend

Defend models, data and prompts: prompt injection, data poisoning, exfiltration, shadow AI.

G

Govern

Govern the lifecycle: policies, roles, AI system register, evidence and audit.

EU AI ActNIST AI RMFISO/IEC 42001 NIS2GDPR
EC-Council ADG AI Framework - Adopt, verified
Adopt
EC-Council ADG AI Framework - Defend, verified
Defend
EC-Council ADG AI Framework - Govern, verified
Govern

EC-Council credentials · ADG AI Framework verified

New service · Cyber Resilience Act

CRA Product Security Assessment

If you design, import or distribute products with digital elements - software, connected devices, components - the Cyber Resilience Act already applies to you: from 11 September 2026 actively exploited vulnerabilities and severe incidents must be reported within 24 hours, including for products already on the market. We measure the distance from the essential requirements and hand you the route to CE marking before the deadline.

  • 12 operational controls - a precise assessment across compliance, secure design and product maintenance
  • Product classification - default, important (class I and II) or critical: which conformity procedure you actually need
  • Regulatory crosswalk - CRA (Reg. EU 2024/2847), IEC 62443-4-1, ETSI EN 303 645, NIST SSDF
  • Remediation roadmap - concrete actions, ownership and priorities ranked by risk and regulatory impact
  • Reporting, SBOM and vulnerabilities - the 24/72-hour process, the software bill of materials and coordinated vulnerability disclosure
The CRA model
C

Comply

Meet the manufacturer’s obligations: inventory and classification, risk assessment, reporting, technical documentation.

D

Design

Secure from the start: default configuration, access control, data protection, attack surface and resilience.

M

Maintain

Maintain the product throughout the support period: updates, logging, SBOM, coordinated vulnerability handling.

Cyber Resilience ActIEC 62443-4-1ETSI EN 303 645 NIST SSDFNIS2
11.09.2026
Reporting obligation: 24h / 72h / 14 days
11.12.2027
Full application of the Regulation
Penalties
Up to EUR 15 M or 2.5% of worldwide turnover

Regulation (EU) 2024/2847 · Cyber Resilience Act

New tool · NIS2 · Legislative Decree 138/2024

NIS2 Readiness Assessment

If your organisation is an essential or important entity, the deadlines are already live: from January 2026 significant incidents must be reported to CSIRT Italia within 24 hours, and by 31 October 2026 the baseline security measures defined by ACN must be implemented and demonstrable. We measure the distance from the obligations of the decree and the ACN determinations and hand you the route to compliance before the audits.

  • 12 NIS2 controls - mapped to articles 7, 23, 24 and 25 of Legislative Decree 138/2024: govern, protect and respond
  • ACN baseline measures - Determination 379907/2025, Annexes 1 and 2: requirement-by-requirement verification in the Gap Analysis
  • Management bodies - approval, oversight and training required by article 23, with direct liability
  • Incident reporting - 24h / 72h / 1 month process, significance criteria and CSIRT referent
  • ACN obligations - annual registration, service categorisation and relevant suppliers (Determinations 127437/2026 and 155238/2026)
The NIS2 model
G

Govern

Management body accountability, risk analysis, relevant suppliers and obligations towards ACN.

P

Protect

The article 24 measures: training and basic hygiene, access and assets, MFA, cryptography, vulnerability management.

R

Respond

Detect and handle incidents, report them to CSIRT Italia on time, ensure continuity and recovery.

Legislative Decree 138/2024ACN Det. 379907/2025ISO/IEC 27001 CIS Controls v8NIS2
January 2026
CSIRT reporting: 24h / 72h / 1 month
31.10.2026
ACN baseline measures for entities listed in 2025
Penalties
Up to EUR 10 M or 2% of worldwide turnover

Legislative Decree 138/2024 · ACN determinations updated September 2026

New tool · DORA · Regulation (EU) 2022/2554

DORA Gap Assessment

If you are a financial entity, or an ICT provider serving one, DORA is not an upcoming deadline: it has applied since 17 January 2025 and is already supervised by Banca d'Italia, IVASS, Consob and COVIP. We measure the distance from the obligations of the Regulation and its technical standards and hand you the route to being ready for a supervisory request.

  • 12 DORA controls - mapped to articles 5-30: ICT risk governance, resilience, third parties
  • Register of information - field-by-field verification under ITS 2024/2956, annual submission by 15 March
  • Major incidents - classification (RTS 2024/1772) and reporting within 4 hours / 72 hours / 1 month (RTS 2025/301)
  • ICT provider contracts - article 30 clauses, concentration risk, subcontracting and exit strategies
  • Resilience testing - annual programme and TLPT preparation (Reg. 2025/1190)
The DORA model
G

Govern

Management body, ICT risk management framework, assets and critical or important functions.

R

Resilience

Protection, detection, incident management and reporting, continuity and resilience testing.

T

Third-party

Third-party strategy, register of information, due diligence, contracts, monitoring and exit.

Reg. (EU) 2022/2554RTS / ITSD.Lgs. 23/2025 ISO/IEC 27001NIST CSF 2.0
17.01.2025
Regulation fully applicable
15 March
Register of information, every year
Penalties
Up to 10% of turnover and disqualification of executives

Regulation (EU) 2022/2554 · Technical standards updated September 2026

Cyber Lounge
Events · Cyber Lounge™

Cyber Lounge™

Unique events in an informal atmosphere, where security is discussed without slides and without a sales pitch. A chance to talk with people who practise cyber security every day, and to leave with answers instead of brochures.

  • Meet a certified Cyber strategy expert
  • A point of reference for your doubts and questions
  • Exclusive locations across Italy and Europe
  • Free, no cost for participants
Where you stand

Cyber Security Maturity

Four levels of awareness. Recognising your own is the first concrete step: most organisations believe they sit higher than they actually do.

Level 4 · Progressive

A new era of awareness

Progressive organisations enjoy deep involvement of Top Management in setting up, managing and reviewing security measures. While they work to prevent as many future breaches as possible, these companies realise they are under constant attack and that some attacks will succeed. To counter this inevitability they turn to advanced consulting and technology and carry out risk reviews and assessments, with third-party expertise that lightens the load on the ICT team.

  • Deep involvement of Top Management
  • Awareness of being under constant attack
  • Certainty that some attacks will succeed
Verifiable expertise

International certifications

Twenty-one active international certifications and credentials, grouped by area of expertise, AI Governance included. Not titles to display: they are the proof that every service is delivered by someone who studied it and was examined on it.

A|CCISOAssociate Certified Chief Information Security OfficerEC-Council
C|CISOCertified Chief Information Security OfficerEC-Council
C|EHCertified Ethical HackerEC-Council
EC|SACertified Security AnalystEC-Council
OSCPOffensive Security Certified ProfessionalOffSec
CRTPCertified Red Team ProfessionalAltered Security
CRTECertified Red Team ExpertAltered Security
C|NDCertified Network DefenderEC-Council
C|SACertified SOC AnalystEC-Council
C|TIACertified Threat Intelligence AnalystEC-Council
E|CIHCertified Incident HandlerEC-Council
C|HFIComputer Hacking Forensic InvestigatorEC-Council
E|DRPDisaster Recovery ProfessionalEC-Council
ICS/SCADAICS/SCADA Cyber SecurityEC-Council
C|CTCertified Cybersecurity TechnicianEC-Council
E|CSSCertified Security SpecialistEC-Council
C|SCUCertified Secure Computer UserEC-Council
C|EICertified EC-Council InstructorEC-Council
ADG · AdoptAdopt. Defend. Govern. AI FrameworkEC-Council
ADG · DefendAdopt. Defend. Govern. AI FrameworkEC-Council
ADG · GovernAdopt. Defend. Govern. AI FrameworkEC-Council
Recognition

International awards

Exclusive recognition for those who believe Cyber Security is an ethical and moral value before it is a profession.

2021

Instructor Circle of Excellence Award

Among the best Cyber Security trainers in the world, the only one awarded in Italy.

EC-Council
2022

CISO of the Year

Among the top 10 finalists at the London Cyber Security Awards, the only finalist in Italy and Europe.

Cyber Security Awards · London
2022

Cyber Personality of the Year

Among the top 10 finalists at the London Cyber Security Awards, the only finalist in Italy and Europe.

Cyber Security Awards · London
2023

CISO of the Year

A second consecutive year among the finalists in the CISO of the Year category.

Cyber Security Awards · London
2023

Cyber Educator of the Year

Finalist in the category dedicated to training and knowledge sharing.

Cyber Security Awards · London
2025

Cyber Educator of the Year

Again among the top 10 finalists, the only Italian representative at the London ceremony.

Cyber Security Awards · London
2025

Instructor Circle of Excellence Award

A second EC-Council recognition among the best Cyber Security instructors in the world.

EC-Council
Recognition

Cybersecurity Career Mentor

Certified mentor for cyber security career paths.

EC-Council
International partnership · London, United Kingdom

Cyber Industries × SecureThreads

A structured partnership with SecureThreads, a London-based cyber security firm, to serve clients operating across Italy, San Marino and the United Kingdom with a single point of contact and two jurisdictions covered.

  • CREST and CHECK penetration testing - assessments delivered by accredited consultants under the schemes recognised by the UK government
  • UK compliance - Cyber Essentials Plus, ISO/IEC 27001 and UK GDPR for organisations selling or operating in the UK
  • Cloud security and Zero Trust - architecture and implementation on AWS, Azure and Google Cloud
  • Joint coverage - vCISO, vulnerability management and monitoring with teams in two countries
  • One point of contact - Cyber Industries coordinates the engagement, SecureThreads delivers within the UK perimeter
The partner

SecureThreads

“Weaving Security Into Every Thread of Your Business”

Headquarters
London, United Kingdom
Accreditations
CREST consultants · CHECK scheme
Sectors
Finance, healthcare, government and regulated industries
CRESTCHECKCyber Essentials Plus ISO/IEC 27001UK GDPRZero Trust

Active partnership · joint engagements with enterprise clients