Contact

The email goes to the person who would do the work.

No form, no queue, and no qualifying call with someone who then hands you over to a stranger. One address, one number, one person.

There is no contact form on this page, and that is deliberate. A form is a promise that something on the other side is listening. This site runs no application and no back end, so that promise would be decorative. An email address is the honest version of the same thing.

Write in whichever of our working languages suits you. If what you need sits outside our work, you will get a referral rather than a proposal — a first call that ends in “this is not our work” is a good outcome, and it costs you an hour instead of a quarter.

Direct lines

Where to reach us

Email
contact@cybersolutions.lu
Telephone
+352 651 204 300
Registered office
34B Rue Philippe II
L-2340 Luxembourg
Working languages
English, French, Romanian
Vulnerability disclosure
/.well-known/security.txt
Legal entity
Cyber Solutions S.à r.l.-S
RCS Luxembourg B284059 · full details

Before the first call

Four things that make the first conversation short.

None of this is required. Send one line if that is all you have. But if you already know the answers, the first call stops being discovery and starts being work.

What is uncomfortable

The reason you are writing today rather than last year. An assessment that came back thin, a supplier question nobody could answer, an incident that showed the runbook was theoretical.

The date that matters

A supervisory deadline, an audit window, a contract renewal, a release. Work with no date behind it tends to stay in the plan.

The perimeter, roughly

Which systems, processes or suppliers are in scope. Approximate is fine — the point is to know whether we are talking about one pipeline or an estate.

Who decides

The person who can accept residual risk and sign. Every engagement we run has a human approval point in it, and it needs a name from the start.

You will speak to the person who would do the work.

Not an account manager, and not a pre-sales engineer who disappears at signature. The practice is founder-led, which is a limit as much as a promise: the calendar is finite, and nobody can hide behind a delivery team.

Procurement and due diligence

The answers you would otherwise wait two weeks for.

If you are the person who has to get a supplier through review, these are the questions that come back on the form. The answers do not change depending on who is asking.

Subcontracting
The work is performed by the founder. Nothing is subcontracted without naming the party and agreeing it with you in writing beforehand.
Where evidence lives
Wherever the engagement allows it, evidence stays in your own systems and repositories. What we have to hold is held in the European Union.
Contractual position
We accept the clauses of DORA article 30 as a supplier. We are not a CSSF-regulated entity, not a PSF de support, and we do not claim DORA compliance on our own behalf — a provider cannot.
Standards
Aligned to ISO 27001 practice. Not ISO 27001 certified, and we will not let a procurement pack say otherwise on our behalf.
Security questionnaires
Answered in your own format, not ours, and answered by the person who would do the work rather than by a template.
Scope of advice
Technical, operational and regulatory. Never legal advice, and we do not represent you before a supervisor. Whether a particular arrangement triggers requirements on your side is your determination with your own counsel; what we provide is the factual description of the service you need to make it.
If the founder is unavailable
A one-person practice is a real concentration risk, not a talking point. We manage it by working inside your systems and documenting as we go, so that work in progress is recoverable by your own team rather than living in someone's head. Where that is not enough for your risk appetite, say so early: we will scope it differently or decline.
Out of hours
We are not a managed security service provider and we hold no on-call obligation unless one is separately agreed. Where an engagement touches incident response, the hand-off to your own team or provider is written down before it is needed rather than improvised during.
Exit and transition
The exit is scoped at the start and the transition period is agreed with you, not fixed by us. Scoping the ending early is exactly what makes it possible to extend it calmly instead of urgently.
Data protection
We sign your data processing agreement. Where we must hold anything, it is held in the European Union and deleted on exit, on a date written into the engagement rather than left to good intentions.

Next step

Write the uncomfortable version.

The useful first email is not the polished one. Tell us what is actually wrong, and we will tell you honestly whether it is our work.

If you would rather understand how we think before you write: the story explains the operating model better than a services page can.

Regulation notes

Or start from what is on your desk.

The practitioner pages — dated, sourced, and written for engineers and risk officers rather than for search engines.