Skip to content

Cybersecurity consulting · European Union

Security decisions that still hold in 2035.

kulanek.net helps European organisations get identity governance right, migrate to Quantum-Safe cryptography before the deadlines bite, and put real controls around AI agents that act without a human in the loop. Practitioner-led advisory, delivered as evidence you can hand to an auditor.

NIS2 / KSC · DORA · ISO/IEC 27001 · SOC 2 · NIST FIPS 203–205 · EU AI Act

2030

EU target for critical infrastructure and other high-risk use cases to be protected with post-quantum cryptography.

2035

Year after which RSA and elliptic-curve cryptography are set to be disallowed under NIST’s draft transition guidance (IR 8547).

3 Oct 2026

Deadline for Polish essential and important entities to register under the amended National Cybersecurity System Act implementing NIS2.

What we do

Three problems, solved properly.

We deliberately do not do everything. These three areas share the same root question — who or what is allowed to do what, and can you prove it — and that is where we are genuinely useful.

01

Cybersecurity consulting

Identity governance and administration, access risk, cloud estates, security operations, and audit readiness for NIS2, DORA, ISO/IEC 27001 and SOC 2. The unglamorous controls that decide whether an audit, or an incident, goes well.

Explore consulting →

02

Quantum-safe migration

Find every place your organisation relies on quantum-vulnerable cryptography, rank it by how long the data must stay secret, and replace it in an order that survives contact with reality. Standards-based, vendor-neutral, built for crypto-agility.

Explore quantum-safe →

03

AI agent security

An agent that holds credentials, calls tools and decides its own next step is a privileged identity that nobody onboarded. We threat-model it, scope its entitlements, red-team it, and give you the logs to explain what it did.

Explore AI agent security →

Why now

The deadlines stopped being theoretical.

Nobody has to break RSA today to hurt you. Encrypted traffic captured now can be stored and decrypted later, once a cryptographically relevant quantum computer exists – the “harvest now, decrypt later” problem. Anything that must stay confidential into the 2030s is already exposed.

The standards and the schedule now exist, so “we’ll look at it later” has become an auditable decision rather than a reasonable one. Meanwhile AI agents are being handed production credentials at a speed no access review process was designed for.

How a migration actually runs →

  1. Aug 2024

    NIST publishes the first PQC standardsFIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) become final. The waiting-for-standards excuse expires.

  2. Mar 2025

    HQC selected as a backupA second, mathematically different key-encapsulation mechanism is chosen, so a break in lattice assumptions is not a single point of failure.

  3. Jun 2025

    EU coordinated roadmap publishedThe NIS Cooperation Group sets a synchronised transition path for Member States, following the Commission’s 2024 Recommendation.

  4. End 2026

    First steps dueMember States should have national strategies and the first migration steps under way — inventory, risk assessment, planning.

  5. End 2030

    High-risk systems protectedCritical infrastructure and other high-risk use cases are expected to be running post-quantum cryptography.

  6. 2035

    Legacy cryptography retiredNIST’s draft guidance disallows RSA and ECC; the EU target is for the transition to be complete wherever practically feasible.

How we work

Four steps, no theatre.

STEP 01

Discover

Interviews, configuration exports and scanning to establish what actually exists — not what the architecture diagram says exists.

STEP 02

Prioritise

Rank findings by business exposure and effort, so the first quarter of work removes the most risk rather than the easiest tickets.

STEP 03

Design

Target architecture, policies and runbooks your team can operate after we leave — written for the tools you already own.

STEP 04

Prove

Tests, evidence packs and metrics that stand up in an audit and tell you honestly whether the control is working.

Why kulanek.net/

Senior people, on your problem.

Small by design. You get the person who did the work, not a pyramid with a partner on the cover slide.

  • Practitioner-led. Built on years of hands-on enterprise identity governance, security operations and compliance work.
  • Vendor-neutral. No reseller margins, no implementation partnership steering the recommendation. If your existing platform can do the job, we will say so.
  • Evidence, not slideware. Deliverables are inventories, decision records, architectures, policies and test results that your team and your auditor can both use.
  • Built for European regulation. NIS2 and its national implementations, DORA, GDPR and the EU AI Act are the frame, not a translation of a US programme.
  • Fixed-scope starts. Most engagements begin as a defined assessment with a fixed price and a date, so you can judge the value before committing to a programme.

Start with a conversation, not a proposal.

Thirty minutes is usually enough to tell whether you need a two-week assessment, a second opinion on a design, or nothing from us at all. We will tell you which.