Kreluna ecosystem

Cybersecurity for SMEs and professional services firms

Kreluna Cyber is being developed to help organisations understand exposure, prioritise risks and document improvements. Scope and authorisation are agreed before any activity.

Kreluna is in active development. Early access, feature availability and integration coverage are confirmed individually for each request.

A clear security improvement path

Security assessment

Review the agreed perimeter and identify priority risks.

Vulnerability management

Track vulnerabilities and verify remediation work.

Awareness and reporting

Provide practical guidance, reporting and support against phishing and common threats.

Understand current exposure

An assessment begins with an agreed perimeter and authorised assets. Findings are prioritised in context so responsible people can plan remediation and track progress.

  • Explicit authorisation
  • Context-based prioritisation
  • Clear technical reporting

Support risk work without overclaiming

Technical reporting may support internal risk management and compliance activities, but it is not legal advice, certification or a guarantee of compliance. Coverage and operating terms are confirmed first.

  • No testing outside the agreed scope
  • Clear responsibilities and escalation
  • Capabilities confirmed before engagement

Frequently asked questions

Can Kreluna test systems without consent?

No. Technical activity requires explicit authorisation, identified systems and an agreed scope.

Does a report prove compliance?

No. Technical reporting can support risk work but is not legal advice, certification or a compliance guarantee.

Is continuous monitoring included?

Coverage, hours, escalation and operational availability must be agreed in writing and are not implied by this page.

Built around control and clarity

Every project starts with a defined objective, authorised information and a clear review process. Capabilities are enabled progressively and important actions remain subject to approval.

  • Defined scope and responsibilities
  • Human review for important actions
  • Clear limits and measurable outcomes
Kreluna resources

Guide: phishing, ransomware and tested backups

Essential controls for accounts, updates, recovery and incident readiness.

Read the guide
Practical applications

An assessment should lead to practical decisions

Security is more than a scan. Scope, authorisation, asset criticality and response capability determine what to test and how to interpret the findings.

Identity and access

Review accounts, privileges, multi-factor authentication, remote access and joiner–mover–leaver procedures.

Email and behaviour

Assess configuration, reporting processes and awareness around phishing, fraud and reused credentials.

Vulnerabilities and updates

Identify exposed or outdated systems, put technical findings in context and set achievable remediation priorities.

Backups and incidents

Review separation, protection and restore testing, plus contacts and first actions for a suspected incident.

Project method

Scope, authorisation, evidence and priority

Technical testing must be agreed in writing. The deliverable should be a readable report with evidence, impact, urgency and accountable next steps—not an indiscriminate list.

  1. Define assets and boundaries

    Agree included systems, exclusions, test windows, contacts and operational constraints.

  2. Gather evidence

    Authorised checks produce repeatable technical evidence without exceeding scope.

  3. Put risk in context

    Interpret a weakness alongside exposure, data, existing controls and business impact.

  4. Build the roadmap

    Separate urgent action, planned improvement and consciously accepted residual risk.

Data and accountability

Assessment, monitoring and compliance are not synonyms

A technical report does not certify GDPR, NIS2 or another regime, nor does it imply continuous monitoring. Actual scope and availability belong in the proposal.

  • No scanning or testing without owner authorisation
  • Credentials and data handled only within agreed scope
  • Technical evidence kept separate from legal conclusions
  • Restricted communication of findings and priorities
  • Retesting included only when explicitly agreed
Measuring value

Measure risk reduction, not finding volume

The raw number of vulnerabilities can mislead. The roadmap should show which material risks were reduced and what remains open.

Asset coverage

Systems, identities and services actually assessed against the known inventory.

Remediation time

Time from confirmed finding to mitigation, separated by priority.

Verified restoration

Recorded restore-test outcomes rather than the mere presence of a backup.

Residual risk

Deferred or accepted findings with rationale, owner and review date.

Before you begin

What to expect from an assessment

Is an assessment a penetration test?

Not necessarily. It may include configuration, identity, process and vulnerability work; penetration testing has specific techniques and authorisation.

Does the report prove compliance?

No. It provides technical evidence within scope. Compliance assessment requires applicable requirements, roles and additional expertise.

Is continuous monitoring included?

Only when stated. This page is not a promise of a permanent security operations service or an unagreed SLA.

References for responsible design

Requirements depend on the organisation’s role, the data and the system’s actual use. That is why assessment comes before configuration.

These sources help frame the work; they do not replace legal, privacy or security advice for a specific situation.