IstroSec s.r.o. Unclaimed
Bratislava, Bratislava, Slovakia
IstroSec is a European cybersecurity company delivering incident response, threat intelligence, and cyber advisory services to organizations ranging from SMEs to Fortune 500 and government entities.
IstroSec is a European cybersecurity company that conducts research, development and security services to help organizations protect against and respond to cyber threats. The company provides proactive security offerings, including ethical hacking, cyber intelligence, governance, risk management and trainings, as well as reactive security services such as incident response, digital forensics, malware analysis, and offensive security. IstroSec serves a wide range of clients, from small and medium-sized enterprises to Fortune 500 companies and government entities across industries. With a focus on international leadership in cybersecurity research and services, IstroSec emphasizes practical, affordable solutions and continuous improvement of customers’ security resilience. The organization stresses ethical practices and a customer-focused approach, and maintains CSIRT capabilities and threat intelligence programs to monitor and counter threats. The portfolio covers incident response, threat hunting, defensive intelligence, managed defense, digital forensics, malware analysis, attack simulations, and advisory services, alongside trainings and incident preparedness.
To offer high-quality professional cybersecurity services at a reasonable price and to continuously increase customers' security resilience.
What we offer
GRYPHON
GRYPHON enhances cyber resilience with offline-first, AI-driven incident response.
gryphon.istrosec.com/IstroSec CSIRT Services
Expert Response and Proactive Security for Cyber Threats.
istrosec.com/service/csirt-services/Defensive Intelligence
Stay ahead of cyber threats with comprehensive leak monitoring and actionable intelligence.
istrosec.com/service/defensive-intelligence/Threat Hunting
Proactively discover hidden threats before they cause harm.
istrosec.com/service/threat-hunting/Managed Defense
Enhance your cybersecurity posture with systematic monitoring and expert incident response.
istrosec.com/service/managed-defense/Malware Analysis
Expertly analyze and mitigate malware threats to enhance security resilience.
istrosec.com/service/malware-analysis/Advisory Services
Expert regulatory compliance and strategic security guidance for organizations.
istrosec.com/service/advisory-services/Incident Preparedness
Enhances organizational resilience against cybersecurity incidents through comprehensive assessments and tailored recommendations.
istrosec.com/service/incident-preparedness/Trainings and Exercises
Equip Your Team with Practical Cybersecurity Skills and Experience.
istrosec.com/service/trainings-and-exercises/IstroSecure Coding
Enhances cybersecurity knowledge and skills for developers through targeted training and certification support.
istrosec.com/eu-projects/istrosecure-coding/Market segments
Market size by segment
Growth potential (CAGR)
Managed detection and response
Continuous monitoring, detection, and 24/7 response across endpoints, networks, and cloud with US-based SOC oversight and integrated threat intelligence.
Incident response and forensics
Rapid breach containment, forensic coordination, eradication, and post-incident analysis to restore operations and improve response capability.
Threat intelligence and dark web monitoring
Ongoing monitoring and research to detect compromised data, provide threat intelligence, and support incident investigations and risk awareness.
Governance, risk and compliance advisory
Advisory and delivery for controls readiness (including SOX), IT and operational risk management, internal audit and risk assurance, and regulatory compliance programs.
Developer security training and certification readiness
Hands-on developer education, secure-coding training, certification readiness (including EU Common Criteria) and practical exercises to build secure software and prepare products for certification.
More information about our offering
GRYPHON
GRYPHON is IstroSec’s AI-powered offline-first defense and incident-response product designed for on-premises or air-gapped environments. Leveraging advanced behavioral analytics and artificial intelligence, it monitors for real-time threats and automates detection and response. GRYPHON-EWS is integrated into this product as an early warning system against advanced cyber threats, utilizing cross-organizational monitoring to enhance detection accuracy.
- Ensure Compliance with EU RegulationsGRYPHON's deployment options allow organizations to maintain compliance with EU data privacy laws while leveraging advanced cybersecurity measures.
- Streamline Incident Response WorkflowsBy combining AI efficiency with human expertise, GRYPHON ensures rapid response to alerts while minimizing false positives and maximizing the accuracy of responses.
- Secure Operation in Sensitive EnvironmentsThis feature allows GRYPHON to function effectively in environments where data privacy is critical, ensuring that sensitive information is protected and inaccessible to unauthorized parties.
- Detects Threats AutomaticallyUtilizes AI-driven technology to automatically identify and respond to threats, ensuring a rapid and efficient security posture.
- Alerts Users EarlyEnables organizations to receive timely warnings about potential cyber threats, allowing for proactive mitigation measures.
- Build Trust with Proven AnalyticsThis feature ensures that AI-driven insights and metrics can be verified against actual data, promoting transparency and reliability in security operations.
- Utilize Comprehensive Cyber IntelligenceGRYPHON's advanced machine learning capabilities deliver actionable insights without relying on external data sources, ensuring data integrity and security.
- Proactively Mitigate Advanced ThreatsGRYPHON-EWS enables organizations to stay ahead of evolving threats by leveraging behavioral analytics for timely, actionable alerts.
- Aggregates Diverse Threat SignalsAnalyzes extensive datasets to discern patterns and signals indicative of potential cyber threats, enhancing situational awareness.
- Monitors Threats in Real-TimeContinuously assesses threat landscapes across various sectors, ensuring organizations can respond effectively to emerging threats.
- Enhance Accountability in OperationsThis feature mitigates the risk of errors and malicious manipulations by maintaining an immutable record of all actions taken during incident responses.
- Enhances Detection AccuracyUtilizes insights from sector-wide data to refine threat detection processes, leading to faster and more precise responses.
IstroSec CSIRT Services
IstroSec CSIRT Services provide reactive and proactive cybersecurity incident response and security operations on a subscription basis, including on-site and remote incident response, digital forensics, malware analysis, threat profiling, technology watch, and security monitoring.
- Respond to IncidentsEnsures rapid and effective containment of breaches to minimize impact on client operations.
- Coordinate Incident ResponseEnsures organized and efficient handling of incidents, facilitating swift recovery.
- Investigate Digital EvidenceEnsures thorough collection and analysis of digital footprints, aiding in identifying threats and incidents effectively.
- Analyze Malware ThreatsDelivers insights into malware behavior, aiding in the prevention of future incidents.
- Monitor Security ContinuouslyMaintains a vigilant watch over systems to detect and respond to threats proactively.
- Enhance Incident ReadinessImproves organizational capability to swiftly respond and recover from incidents, mitigating potential damages.
- Conduct Security EvaluationsIdentifies and mitigates vulnerabilities before they can be exploited by attackers.
- Profile Active ThreatsEnhances understanding of relevant threats, enabling strategic defense planning.
Defensive Intelligence
Defensive Intelligence provides targeted threat intelligence, leak monitoring across clear, deep and dark web, and threat briefings to keep organizations ahead of adversaries.
- Monitor Data LeaksIstroSec experts continually scan various web layers for leaks that might impact the security of the customer organization.
- Provide Actionable IntelligenceCustomized intelligence reports are delivered to enhance decision-making based on the unique threats faced by each organization.
- Deliver Insightful BriefingsRegular reports on current threats and vulnerabilities keep management informed and prepared.
Threat Hunting
Threat Hunting actively searches for suspicious activity or remnants of malicious activity within the client’s infrastructure, based on standard attacks and custom threat landscapes.
- Focus Search with HypothesesEmploys a structured approach to threat hunting by generating specific hypotheses about potential threats, improving hunt efficiency and effectiveness.
- Identify Threats ProactivelyThis feature allows for the detection of Indicators of Compromise (IOCs) hidden within network traffic and system endpoints, enhancing the detection capabilities against advanced threats.
- Automate Security MonitoringThis feature includes continuous monitoring of critical systems for IOCs, coupled with detailed reporting for insights into the threat landscape.
- Tailored Attack QueriesUtilizes custom queries to match the client's unique infrastructure, increasing the chances of uncovering malicious activity specific to their environment.
- Access Critical Data SourcesThis ensures that threat hunts are based on accurate data, allowing for a more effective search for anomalies and malicious activity.
- Tailor Monitoring SolutionsOffers personalized recommendations for both open-source and commercial solutions to enhance client monitoring efforts, ensuring effective threat detection.
- In-Depth Threat AnalysisThis provides a deeper examination of alerts generated from monitoring tools, allowing for accurate identification of potential threats.
- Enhance Monitoring CapabilitiesProvides recommendations on the appropriate use of tools for tracking and responding to threats, optimizing the existing security infrastructure.
Managed Defense
Managed Defense provides continuous cybersecurity monitoring and SOC-like oversight, including tool administration, configuration, and tailored monitoring across networks and endpoints.
- Detects Network and Endpoint ThreatsUtilizes advanced monitoring tools to identify suspicious activities at both network and endpoint levels.
- Ensures Comprehensive Threat VisibilityIntegrates logs from various sources to provide actionable insights for threat detection and response.
- Streamlines Incident ResponseEmploys a hierarchical approach to manage incidents effectively and escalate as needed.
- Enhances Response TimesAutomation speeds up analysis and incident response, ensuring quick action against threats.
- Facilitates Smooth IntegrationGuides clients through the initial setup while ensuring continuous monitoring and detailed reporting.
- Optimizes Security ToolsRegularly tunes and maintains monitoring tools for optimal performance in threat detection.
Malware Analysis
Malware Analysis provides in-depth analysis of malicious code, including type, behavior, configuration and potential impacts, with reverse engineering and defensive antibody development.
- Attributes Malware to Threat ActorsIdentifies potential threat actors behind malware, improving response effectiveness and future prevention.
- Identifies Malware TypesUnderstanding the type and functionality of malware enables better defense strategies and response planning.
- Creates Custom AntibodiesSpecialized antibodies allow organizations to effectively counteract specific malware threats, enhancing overall security.
- Disrupts Advanced MalwareTargets malware defenses that standard anti-virus solutions can't detect, ensuring robust protection strategies.
- Extracts Malware SettingsProvides insight into malware behavior and intentions by extracting configurations, aiding in threat mitigation.
Advisory Services
Audits and advisory services including CISO-as-a-service, implementation of information security management processes, information security audits, security awareness raising, and incident preparedness.
- Provides Strategic OversightWith dedicated CISOs from IstroSec, organizations can ensure their information security governance is handled by experienced professionals, bridging gaps and enhancing compliance with regulatory standards.
- Enhances Incident Response CapabilityBy evaluating and improving existing incident response processes, organizations can ensure swift reactions to cybersecurity incidents, effectively mitigating potential damages.
- Ensures Regulatory ComplianceRegular audits conducted by IstroSec experts ensure that organizations meet necessary security standards and effectively address vulnerabilities.
- Streamlines Security ProcessesTailored implementation of information security measures according to varied organizational needs helps in maintaining a robust security posture.
- Builds Security CultureBy educating employees about potential threats and security practices, organizations can significantly reduce human-related security risks.
Incident Preparedness
Incident Preparedness assesses an organization’s readiness for cybersecurity incidents, focusing on people, processes, technology and documentation, delivering final reports and recommendations with optional implementation or exercises.
- Ensures Effective Incident ManagementEvaluating existing processes and technologies ensures the organization's capability to effectively respond to incidents.
- Provides Insightful RecommendationsAn in-depth assessment culminates in a report outlining actionable recommendations to enhance incident response capabilities.
- Enhances Security AwarenessA thorough review of relevant documentation ensures that an organization's security posture is aligned with current threats and vulnerabilities.
- Identifies Relevant ThreatsMapping out threats specific to the organization enables focused preparations and strategic defense measures.
- Facilitates Practical TrainingEngaging in hands-on exercises prepares teams to respond effectively during actual cybersecurity incidents.
Trainings and Exercises
IstroSec offers advanced trainings in cybersecurity, including RealWorld forensic analysis, penetration testing and incident response, plus table-top and team exercises.
- Enhance Forensic SkillsEquip participants with practical skills to analyze and investigate digital evidence effectively.
- Improve Incident ManagementTrain teams to react swiftly and effectively during cybersecurity incidents, ensuring better preparedness.
- Master Penetration TechniquesDevelop advanced skills in identifying and exploiting vulnerabilities to strengthen defenses.
- Test and Enhance Response PlansSimulate real incidents to evaluate and improve the preparedness and collaboration of security teams.
- Deep Dive into CybersecurityParticipate in thorough workshops designed to offer practical skills and knowledge crucial for cybersecurity.
IstroSecure Coding
IstroSecure Coding supports education and professional training of developers in cybersecurity solutions, aiding preparation for EU Common Criteria certification for the Gryphon product.
- Enhances Skills and KnowledgeEquips developers with essential skills to create secure applications and mitigate cybersecurity risks.
- Supports Certification ProcessGuides organizations through the certification process to ensure compliance with EU security standards.
- Provides Financial AssistanceFacilitates access to funding for cybersecurity training initiatives and project development.
References
Methodology and sourcing behind the figures shown above.
Managed detection and response
Multiple industry reports in the searchResults show the global MDR market in the low-to-mid single-digit billions (2024–2026) with high projected growth. Reported 2026 market sizes range ~USD 2.8B–6.2B and horizon CAGRs range ~15%–23%. I selected USD 6.22B (MarketsandMarkets 2026 figure) as a representative current-market estimate and a consensus growth potential of ~20% CAGR reflecting the mid-point of reported forecasts (17.8%–23.2%), acknowledging definitional differences across reports (scope, inclusion of platforms/services, forecast periods).
- Projected to reach USD 17.64 billion by 2031 from USD 6.22 billion in 2026; CAGR 23.2% (2026–2031)
- Market valued at USD 2.31 billion in 2025; projected USD 2.81 billion in 2026; CAGR 17.80% (2026–2034)
- 2024 Market Size $5.2 Billion; CAGR (2025–2035) 21.5%.
- Market size USD 3.40 billion in 2025; CAGR 15.12% (2026–2035).
Incident response and forensics
Estimated 2025 market size derived by combining reported incident response and digital forensics market figures from the search results (38.67B + 12.94B = 51.61B) and reducing ~5.0B to conservatively account for overlap between incident response and forensics offerings, yielding ~46.61B. CAGR set to 15.0% as a midpoint reflecting reported growth rates for incident response (~20.2%), digital forensics (~12.0%), and network forensics (~17.45%), weighted conservatively to reflect overlap and differing forecast windows.
Threat intelligence and dark web monitoring
Estimated current market size (~2025) derived from multiple industry reports in the provided results (MarketsandMarkets, Precedence Research, ResearchNester). These sources report 2025 market values in the $11.6–16.8B range and multi-year forecasts implying mid-teens CAGRs (~14.5–15%). I weighted recent 2025 point estimates (11.6, 15.6, 16.8) to produce a rounded $15B size and selected a consensus CAGR of ~15% (consistent with 14.7%–15.2% range in the sources).
Governance, risk and compliance advisory
Primary estimate uses the WiseGuy Reports figure valuing the global risk & compliance consulting (advisory) market at USD 34B in 2025 with a 3.9% CAGR (2026–2035). I cross-checked other search results showing a range driven by definitional differences: BusinessResearchInsights (USD 17.87B in 2026; 6% CAGR) and IndustryResearch (USD 11.36B in 2026; 5.31% CAGR) for narrower scopes, while MarketsandMarkets reports a larger eGRC software market (USD 20.56B in 2025 to USD 39.99B in 2030; 14.2% CAGR). Given the search-result variance, the advisory services estimate follows WiseGuy’s consulting-focused sizing and growth rate, with other sources shown to illustrate range and methodological differences.
- Market Size, 2025 USD 34 Billion
- market size is projected at USD 17.87 Billion in 2026...hit USD 29.78 Billion by 2035 with a CAGR of 6%.
- forecast to expand from USD 11360.22 million in 2026 to USD 18094.9 million by 2035, CAGR of 5.31%.
- eGRC market projected to reach USD 39.99 billion by 2030 from USD 20.56 billion in 2025, at a CAGR of 14.2%.
Developer security training and certification readiness
Estimate based on reported niche secure-code training market (~USD 0.8B in 2026) and broader cybersecurity certification/training market figures (cybersecurity certification ~USD 3.98B in 2024, broader training markets $1.8–4.4B range). Developer security training and certification-readiness is a subset of both secure-code training and certification services; I set current market size at ~USD 1.0B and growth potential aligned with certification and training CAGR signals (~12% annual growth).
- projected to grow from USD 3.98 billion in 2024 to USD 8.03 billion by 2030 at a CAGR of 12.4%
- secure code training software market is valued at approximately USD 0.8 Billion in 2026; projected to reach USD 1.48 Billion by 2035, CAGR ~6.6%
- Cyber Security Training Market Size accounted for USD 4.1 Billion in 2022 and projected to USD 19.2 Billion by 2032, CAGR 17.1%
Related Organizations
- AW
Arctic Wolf
Arctic Wolf provides AI-powered security operations and incident response services to protect organizations worldwide.
www.arcticwolf.com - BC
BitLyft Cybersecurity
BitLyft Cybersecurity is a managed security provider delivering high-touch, cost-effective cybersecurity solutions for mid-sized enterprises.
www.bitlyft.com - BI
BitSight Technologies, Inc.
Security ratings and cyber risk analytics to measure, monitor, and reduce organizational risk.
www.bitsight.com - B
BugFoe
BugFoe is an ISO/IEC 27001:2022 certified MSSP providing enterprise-grade cybersecurity, penetration testing, and compliance-focused security solutions.
bugfoe.com - CS
CBIZ Pivot Point Security
CBIZ Pivot Point Security helps organizations prove they are secure and compliant through information security assessment and governance services.
www.pivotpointsecurity.com - C
Cybersecop
Cybersecop is a cybersecurity consulting firm delivering risk management, regulatory compliance, and security operations services across industries.
cybersecop.com