Gerico Security Srl

Gerico Security Srl

Speciality: Offensive Security and Penetration Testing

milan, Italy 18 employees
[01] About

Gerico Security Srl is a Milan-based cybersecurity consulting company specializing in penetration testing, risk management, and operational continuity; with 15 employees, 28.6% YoY growth, founded in 2019, and offering services including offensive security, cybersecurity audits, and compliance consulting (ISO27001, ISO22301, PCI-DSS).

Azienda di consulenza specialistica, formazione e audit in tema di Information & Cyber Security, Business Continuity e Gestione dei rischi. Nasce da specialisti del settore per dare concretezza alla domanda del mercato di riferimento, portando valore attraverso l’esperienza maturata negli anni nel supporto in tema di Information Security, Continuità Operativa, Service and Governance Management ad Infrastrutture critiche e a grandi e piccole società di molteplici settori merceologici. L’azienda, certificata ISO/IEC 27001:13, eroga servizi di consulenza specialistica, audit (di prima e di seconda parte), formazione (security awareness e formazione specialistica), supporto al raggiungimento delle certificazioni in merito agli standard PCI DSS, ISO/IEC27001, ISO22301, ISO/IEC20000, TISAX. Inoltre gestisce progetti di Governance Risk & Compliance “chiavi in mano”, oltre che ad offrire il supporto continuativo al Cliente attraverso la formula di “CISO as a Service”. GeRiCO è il punto di riferimento italiano per le aziende della difesa che necessitano di un assessment NIST-SP800 171 o della certificazione CMMC per il DoD americano. ---------------------------- Gerico Security is an Italian centre of excellence in advisory on information & cyber security, business continuity, internal and third-party audit and security inspection activities. It has been set up by specialists of the sector to satisfy the demand for security. Gerico supports private organizations in business process certifications ISO27001, ISO22301, TISAX, PCI-DSS, ISO27701, ISO27017, ISO27018 through the provision of turn-key projects of Governance Risk & Compliance. Gerico Security Srl is the NIST SP-800 171 and CMMC’s reference point in Italy. Gerico is aimed at defining and achieving high levels of cybersecurity both on large and small Italian companies belonging to the DoD’s Defence Industrial Base.
[02] Services
Information & Cyber Security
Automotive Cybersecurity (tisax)
Business Continuity And Crisis Management
Cybersecurity For Defense Companies (cmmc)
PCI DSS Compliance
Technological Verifications
Datacenter Certification (iso/iec 22237)
Cloud Information Security (csa Star)
Cyber Security For Safety
DORA Regulation And NIS Directives Compliance
Risk Management
Security As A Service
Penetration Testing
Vulnerability Assessment
Offensive Security Services
[03] Certifications
ISO/IEC 27001

ISO/IEC 27001: Information Security Management System Certification


Origin


ISO/IEC 27001 was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), first published in 2005 and most recently updated in 2022. It evolved from the British Standard BS 7799, which was created in the 1990s by the UK government and industry experts to address growing information security concerns. The standard was developed to provide organizations with a systematic framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), helping them protect sensitive data in an increasingly digital business environment.


Industry Value and Importance


ISO/IEC 27001 is globally recognized as the gold standard for information security management, valued because it demonstrates an organization's commitment to protecting confidential information through risk-based controls and continuous improvement. The certification is particularly important for organizations handling sensitive data, as it helps them comply with legal and regulatory requirements, win contracts (especially with government entities and large enterprises), and build customer trust. Many industries require or strongly prefer vendors with ISO 27001 certification, as it provides independent verification that appropriate security controls are in place, reducing the risk of data breaches and ensuring business continuity in the face of evolving cybersecurity threats.

TISAX

TISAX: Trusted Information Security Assessment Exchange


Origin


TISAX (Trusted Information Security Assessment Exchange) was created by the ENX Association (European Network Exchange) in 2017 at the request of the German automotive industry, specifically the VDA (Verband der Automobilindustrie - German Association of the Automotive Industry). The certification was developed to address the automotive sector's need for a standardized, mutual recognition framework for information security assessments. It was created to reduce the burden of multiple audits on suppliers, as automotive manufacturers were each conducting their own security assessments of shared suppliers, leading to duplication and inefficiency.


Industry Importance


TISAX has become essential for companies working with the automotive industry, particularly in Europe, as many major manufacturers now require it from their suppliers and partners. The certification provides a trusted, industry-recognized validation of a company's information security practices, protecting sensitive data such as intellectual property, product designs, and business information. Its importance stems from the mutual recognition principle—once a company achieves TISAX certification, the results are shared across participating organizations, eliminating redundant audits and creating efficiency while maintaining high security standards. For suppliers, TISAX certification has become virtually mandatory to maintain or establish business relationships with automotive OEMs and tier-1 suppliers.

CMMC

Cybersecurity Maturity Model Certification (CMMC)


Origin


The Cybersecurity Maturity Model Certification (CMMC) was created by the U.S. Department of Defense (DoD) in 2020 in response to increasing cybersecurity threats targeting the Defense Industrial Base (DIB). The framework was developed to ensure that defense contractors and subcontractors adequately protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) in their systems. The DoD recognized that existing self-attestation methods were insufficient to safeguard sensitive defense-related data from sophisticated cyber attacks, particularly from nation-state adversaries, prompting the need for a more rigorous, third-party verification system.


Industry Value and Importance


CMMC certification has become essential for companies seeking to do business with the Department of Defense, as it is now a contractual requirement for defense contractors. The certification demonstrates that an organization has implemented appropriate cybersecurity practices and processes to protect sensitive government information, making it a competitive differentiator in the defense contracting marketplace. Beyond compliance, CMMC helps organizations improve their overall cybersecurity posture, reduce breach risks, and build trust with government clients and partners. The tiered certification structure allows companies to align their security investments with the sensitivity of the information they handle, making it both practical and scalable across the diverse defense supply chain.

PCI DSS

PCI DSS Certification


Origin


The Payment Card Industry Data Security Standard (PCI DSS) was created in 2004 by the major credit card companies: Visa, Mastercard, American Express, Discover, and JCB International. These companies formed the PCI Security Standards Council in 2006 to manage and evolve the standard. PCI DSS was developed in response to increasing credit card fraud and data breaches, establishing a unified set of security requirements for all organizations that store, process, or transmit cardholder data. The goal was to create consistent security measures across the payment card industry to protect sensitive payment information.


Industry Value and Importance


PCI DSS compliance is mandatory for any business that handles credit card transactions, making it one of the most critical security standards in commerce today. The certification demonstrates that an organization has implemented robust security controls, including network protection, access management, encryption, and regular security testing. Non-compliance can result in severe consequences, including substantial fines (up to $100,000 per month), increased transaction fees, loss of payment processing privileges, and reputational damage following a breach. For IT professionals, PCI DSS expertise is highly valued as organizations across all industries need qualified personnel to implement, maintain, and audit these security controls.

ISO/IEC 22237
CSA STAR
DORA

DORA (Digital Operational Resilience Act)


DORA is a regulatory framework created by the European Union that entered into force in January 2023, with full application required by January 2025. Developed by the European Commission, the European Parliament, and the Council of the European Union, DORA was established to strengthen the digital operational resilience of financial entities across the EU. The regulation emerged from growing concerns about cyber threats, ICT disruptions, and third-party dependencies that could destabilize the financial sector, particularly following increased digitalization and cloud adoption in financial services.


DORA is highly valued in the penetration testing and cybersecurity industry because it mandates comprehensive testing requirements for financial institutions, including advanced threat-led penetration testing (TLPT) for critical entities. Penetration testing companies reference DORA compliance as it creates significant demand for their services—financial organizations must conduct regular security testing, vulnerability assessments, and sophisticated red team exercises to meet regulatory obligations. For cybersecurity firms, demonstrating knowledge of DORA requirements and offering DORA-aligned testing services has become a competitive differentiator, as it shows they understand the specific regulatory landscape their financial sector clients must navigate and can deliver testing programs that meet these stringent EU standards.

NIS 1
NIS 2