Fisherman Labs

Security · Engineering · Consulting

Security engineering and consulting for teams that need steady hands.

We help organisations design, operate, and recover secure systems — from board-level direction to pipelines and industrial environments.

About

Privacy-driven security, from design to operations

Fisherman Labs s.r.o. has designed, built and secured systems in Prague since 2012. We pair advisory work with hands-on engineering, so recommendations end up as running systems, not shelfware.

Who we are

Fisherman Labs is led by Jakub Rybář, Secure Solution Designer, Architect & Engineer. He has worked in IT operations since 2000 and in security for more than ten years.

That includes leading a SOC analyst shift at a global logistics company, and serving as Cyber Security Architect at a university hospital in Pilsen under Czech cyber-security law. He co-founded and ran GuardIoT, an OT/ICS/IIoT security startup. Later work covered DevSecOps for fintech, crypto and media companies, and CERT/SOAR plus security engineering lead work in the gaming sector.

Certifications: GIAC Certified Incident Handler (GCIH) and ITIL Foundation.

Incident-tested GCIH-certified, with SOC shift leadership and CERT/SOAR experience behind it.
Privacy-driven Secure solution design that protects people and data, not just audit checklists.
IT, OT & IoT From cloud, Kubernetes and pipelines to ICS/SCADA and (I)IoT networks.

Services

How we can help

From advisory work to hands-on engineering. Pick one area or combine several.

01

Consultancy

Security audits, ISMS policy and threat modeling, aligned with ISO 27k and the Czech Cyber Security Act. We also harden how software gets built, through a secure development lifecycle (SSDLC).

Audits · ISMS · ISO 27k · Threat modeling · SSDLC

02

Incident Handling & Response

Incident response service design, hands-on handling and digital forensics, led by a GIAC Certified Incident Handler. Built on SOC, CERT and SOAR experience, with threat intelligence feeding detection.

GCIH · DFIR · SOC/CERT · SOAR · SIEM · MISP

03

vCISO

Part-time security leadership: strategy, governance, risk management and a roadmap your stakeholders accept. Grounded in his role as Cyber Security Architect at a university hospital in Pilsen — shaping security strategy, governance and stakeholder buy-in — plus GRC across ISO 27k, PCI DSS and SOC 2.

Strategy · Governance · Risk · ISO 27k · PCI DSS · SOC 2

04

DevSecOps

Secure CI/CD and SSDLC baselines built on Zero Trust principles, so every change is checked on its way to production. GitLab pipelines, Kubernetes runtime security and GitOps delivery.

GitLab CI · Kubernetes · Falco · Flux · Zero Trust

05

DevOps & Infrastructure as Code

Kubernetes platforms built and run as code, from bare metal and small VPS setups to AWS and Azure, with monitoring and observability in place from day one.

K3s · K8s · Rancher · AKS · EC2 · Ansible · Terraform · Podman

06

OT/ICS & IoT security

Ethical hacking of IT, OT, ICS/SCADA and (I)IoT environments, continuous vulnerability assessment, and anomaly and intrusion detection for networks where availability comes first.

ICS/SCADA · (I)IoT · Vulnerability assessment · IDS

Experience across

  • Healthcare
  • Finance
  • Logistics
  • Gaming
  • Crypto & fintech
  • Media
  • Telco & cloud
  • Public sector & research
  • SMB

Contact

Tell us what you’re building — or fixing.

Short discovery calls are welcome. If you’re mid-incident, say so in the subject line and we’ll prioritise accordingly.

Email [email protected]