NIS2 deadlines
Directive in force, real fines, but policies and remediation still to be defined.
NIS2, security and AI governance for SMEs.
Companies of 10 to 250 employees, with a focus on the Italian market, that need to comply with NIS2, GDPR and the EU AI Act without an in-house SOC. noze offers affordable platforms and ongoing support.
Directive in force, real fines, but policies and remediation still to be defined.
Incomplete IT inventory, vulnerabilities discovered only after an incident.
Departments using cloud LLMs without policies or traceability.
No in-house CISO, no dedicated DPO, no red team.
Vulnerability assessment and automated pentest, monthly subscription.
NIS2 / GDPR / AI Act in one on-premise platform.
Open AI governance with Admina Enterprise: NIS2 and AI Act without lock-in.
SolutionCISO-as-a-service consulting to define posture and roadmap.
SolutionAI strategy, governance and responsible adoption for SMEs.
SolutionCloud-native architectures, web apps and scalable microservices.
TrueForge is an open-source harness in TypeScript holding the execution loop, MCP tools, approvals and secrets. smolvm is a Rust CLI booting microVMs with a separate guest kernel on libkrun, with an egress allowlist in the configuration file. Underneath sit five different isolation levels, from a syscall filter to a VM, and each stops different things.
Z.ai announced GLM-5.3 on 14 August, stating it starts from the same base model as GLM-5.2 and that every gain comes from post-training. The weights are not out yet. On CyberGym and ExploitGym the benchmarks measure something other than finding a vulnerability, and the CyberGym paper reports 759 raw crashes for 9 confirmed zero-days after manual triage.
Attestable announces a $20M seed and writes that practical zero-knowledge proofs were considered impossible and that the company solved it. The technical post declares two temporary limitations, a 16K token window and integer quantisation of matrix multiplications, and labels the benchmarks alpha results on a single H100. IACR ePrint 2025/535, a preprint with no experimental setup described and no peer review, states 150 seconds per token on one core for Llama-3 8B.
noze pairs CyberAgent's vulnerability assessment and automated pentest, on a monthly subscription, with DataGovern to handle NIS2, GDPR and the AI Act in one on-premise platform. CISO-as-a-service consulting sets posture and roadmap without hiring an internal security team.
CyberAgent is built for an SME budget: vulnerability assessment and pentest are delivered as a monthly subscription, with no need to build an internal red team. noze's platforms are affordable and come with ongoing support, so spending stays predictable and security does not depend on a single incident.
With Admina Enterprise, SMEs adopt open AI governance that covers NIS2 and the AI Act without lock-in, bringing policies and traceability to how departments use LLMs. noze's AI strategy guides responsible adoption without giving up generative tools.