ComCERT SA

ComCERT SA

Speciality: Penetration Testing and Red Teaming

Poland 26 employees
[01] About

ComCERT SA is a Poland-based cybersecurity firm specializing in computer and network security; 19 employees with -7.1% YoY growth and $12M annual revenue. It offers penetration testing and red teaming services to identify vulnerabilities and simulate cyberattacks, emphasizing proactive security measures. Founded in 2011, it has a modest web presence with 794 monthly visits and ranks #9,634,911 globally.

ComCERT SA, jedyna w Polsce, specjalizuje się w oferowaniu pomocy dla Administratorów IT/zespołów bezpieczeństwa w czasie i po ataku cyberprzestępczym (tzw. druga, a w przypadku dużych organizacji, posiadających zespoły bezpieczeństwa – trzecia linia wsparcia). Przed atakiem sprawdzamy, czy organizacja jest przygotowana na odparcie ataku oraz wprowadzamy takie zasady, procedury itp., aby pierwszy taki incydent nie spowodował chaosu w przedsiębiorstwie. Poza powyższymi usługami ComCERT oferuje: • powiadamianie o naruszeniach bezpieczeństwa organizacji (bez ingerencji ) i zbliżających się zagrożeniach • powiadamianie o lukach i słabościach systemowych organizacji w momencie, gdy się pojawiają • obrona przed atakami DDoS • usługi informatyki śledczej • klasyczne usługi bezpieczeństwa (szkolenia, audyty, itp.). ComCERT opiera się na doświadczeniu i kompetencji ekspertów i menedżerów z wieloletnim doświadczeniem. Dzięki międzynarodowym relacjom (a przeważnie ataki internetowe mają właśnie taki charakter) może wstrzymać wiele ataków w czasie ich trwania, a poprzez dostęp do danych, jakich praktycznie nikt w Polsce nie posiada, może oferować – jako jedyna w Polsce – powyższe usługi (naszym udziałowcem jest jeden z największych w Europie podmiotów, które zajmują się pozyskiwaniem informacji o zagrożonych i zaatakowanych komputerach). Dopiero wsparcie ComCERT-u pozwala na stworzenie kompletu działań zapewniających bezpieczeństwo teleinformatyczne organizacji.
[02] Services
Provides Comprehensive IT Security Services Including Penetration Testing
24/7 SOC Outsourcing
Cyber Threat Intelligence
Compliance Consulting
Audits
Innovative Security Advisory.
[03] Certifications
ISO/IEC 27001

ISO/IEC 27001: Information Security Management System Certification


Origin


ISO/IEC 27001 was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), first published in 2005 and most recently updated in 2022. It evolved from the British Standard BS 7799, which was created in the 1990s by the UK government and industry experts to address growing information security concerns. The standard was developed to provide organizations with a systematic framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), helping them protect sensitive data in an increasingly digital business environment.


Industry Value and Importance


ISO/IEC 27001 is globally recognized as the gold standard for information security management, valued because it demonstrates an organization's commitment to protecting confidential information through risk-based controls and continuous improvement. The certification is particularly important for organizations handling sensitive data, as it helps them comply with legal and regulatory requirements, win contracts (especially with government entities and large enterprises), and build customer trust. Many industries require or strongly prefer vendors with ISO 27001 certification, as it provides independent verification that appropriate security controls are in place, reducing the risk of data breaches and ensuring business continuity in the face of evolving cybersecurity threats.

NATO Security Clearance (nato Secret
NATO Confidential)
EU Security Clearance (eu Secret
EU Confidential)
ISO 22301

ISO 22301: Business Continuity Management


Origin


ISO 22301 was developed and published by the International Organization for Standardization (ISO) in 2012, with a major revision released in 2019. It emerged from the need for a globally recognized standard for business continuity management systems (BCMS), replacing the earlier British standard BS 25999-2. The standard was created to help organizations of all sizes and sectors prepare for, respond to, and recover from disruptive incidents that could threaten their operations.


Industry Value


Note: ISO 22301 is actually a business continuity management certification, not specifically a cybersecurity/IT certification, though IT resilience is often a key component. Organizations value ISO 22301 certification because it demonstrates a systematic approach to identifying potential threats and maintaining critical business functions during disruptions. The certification is particularly important for organizations that must prove operational resilience to clients, regulators, and stakeholders. It provides a competitive advantage by showing commitment to minimizing downtime, protecting revenue streams, and ensuring service delivery even during crises—whether those involve cyber incidents, natural disasters, or other operational disruptions.

Cert™
FIRST
TF-CSIRT
[05] Notable Clients
  • Major banks (including 3 of the largest 5 in Poland)
  • Polish Parliament (Sejm)
  • large critical infrastructure entities