circl3.tech
  • Home
  • Cybersecurity Advisory
  • Business|Startup Advisory
  • Contact Us
  • More
    • Home
    • Cybersecurity Advisory
    • Business|Startup Advisory
    • Contact Us
circl3.tech
  • Home
  • Cybersecurity Advisory
  • Business|Startup Advisory
  • Contact Us

projects involved

CISOaaS for the Cyprus Government

European Certification for Cloud Service Providers (EUCS)

CISOaaS for the Cyprus Government

 Over a three-year period, supported the Deputy Ministry of Research, Innovation & Digital Policy in building the Cybersecurity Directorate from the ground up, establishing governance frameworks, policies, and standards, and spearheading a multimillion-euro initiative to deploy security controls and solutions protecting the pubic administration digital infrastructure. 

Setup CISO Offices at Banks

European Certification for Cloud Service Providers (EUCS)

CISOaaS for the Cyprus Government

 Established and developed the Information Security Offices of the two leading banks in Cyprus [Laiki  Bank | Bank of Cyprus] from the ground up, advancing them to a mature and robust security posture. 

European Certification for Cloud Service Providers (EUCS)

European Certification for Cloud Service Providers (EUCS)

European Certification for Cloud Service Providers (EUCS)

 Member of the EUCS Ad-hoc Working Group, contributing to the discussions and shaping of the scheme’s core components and framework. 

European Cybersecurity Skills Framework (ECSF)

European Cybersecurity Skills Framework (ECSF)

European Certification for Cloud Service Providers (EUCS)

Member of the European Cybersecurity Skills Framework (ECSF) Working Group, contributing to the development and alignment of cybersecurity roles, competencies, and skills across the EU. 

European /National Policy Advising

European Cybersecurity Skills Framework (ECSF)

European /National Policy Advising

 

Policy Advising at the Association of Cyprus Banks, providing strategic guidance on cybersecurity, regulatory compliance, and digital transformation—focusing on the EU AI Act, Open Finance Framework, and Data Act—while supporting ACB’s active participation in the European Banking Federation (EBF) and National policy initiatives.

ISO 27001 Implemenations

European Cybersecurity Skills Framework (ECSF)

European /National Policy Advising

 

Supported one of Cyprus’s leading ICT providers in strengthening its security governance and control environment, culminating in the successful attainment of ISO 27001 certification. 

Security metrics

Data Leakage Prevention programme

Data Leakage Prevention programme

Developed and implemented cybersecurity performance metrics (KPIs and KRIs) and designed a dashboard to effectively communicate thresholds, trends, and real-time status to management. 

Data Leakage Prevention programme

Data Leakage Prevention programme

Data Leakage Prevention programme

Developed a DLP strategy and programme. Recruited an enteprise wide DLP system (covering data in motion, data at rest, data in use) and put it in operation with a large number of rules in place.

Cybersecurity Stategy

Data Leakage Prevention programme

Cybersecurity Policies

Developed the cybersecurity strategy oat two financial institutions upon agreement with all stakeholders, the BoD and the Regulators. 

Managed the tactics and its implementation to completion.

Cybersecurity Policies

Security Controls Definition and Maturity Assessment

Cybersecurity Policies

Developed the Information Security Policies (High level and specific ones)  after reviewing with internal and external stakeholders and aligning them with regulatory frameworks.

Security Controls Definition and Maturity Assessment

Security Controls Definition and Maturity Assessment

Security Controls Definition and Maturity Assessment

Setup security controls in line with ISO27002, NIS2, GDPR, EBA Guidelines. PCI DSS, PSD2, Secure Controls Framework.

Assessed defined controls following a Capability Maturity Model, developed reemediation plan and monitored its progress to completion 

Risk Management

Security Controls Definition and Maturity Assessment

Security Controls Definition and Maturity Assessment

 Established the risk assessment framework in line with ISO27005 and carried our respective risk assessments. 

Security Awareness Program

Security Incident Response Plan

Security Awareness Program

Established a security awareness program:

 

> in-class 

> e-learning 

> through phishing simulations,

Security Operations Centre

Security Incident Response Plan

Security Awareness Program

Setup the framework for a 24x7 Security Operations Centre covering technology, people and processes pillars.  

Security Incident Response Plan

Security Incident Response Plan

Security Incident Response Plan

 Designed and implemented a comprehensive Security Incident Response Plan (SIRP) and established a dedicated Security Incident Response Team (SIRT), conducting regular cybersecurity exercises to validate readiness and continuously improve response capabilities. 

Penetration tests

Vulnerability and patch management

Security Incident Response Plan

Managed the penetration test program covering external, internal and social engineering scenarios.   

information classification

Vulnerability and patch management

Vulnerability and patch management

Developed the Information classification scheme, defined information owners and classified all information. Developed then controls to protect this information.

Vulnerability and patch management

Vulnerability and patch management

Vulnerability and patch management

Defined a vulnerability and patch management program with daily scanning of systems, setup of patching cycles and monitoring of metrics.  

speaking to conferences

Speaking to conferences

Organised CyberSecurity Hackathon

Partners | Cooperations | Associates

circl3.tech

+357 99465174 | panos.panayiotou@circl3.tech

Copyright © 2022 circl3.tech ltd -  All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept