About CQRE · Brownhat¶
This document introduces CQRE and the Brownhat methodology to new clients and new team members.
A Czech-language version of this document is maintained at O společnosti CQRE.
Who We Are¶
CQRE.NET is the business name of CZ Expert, s.r.o., a Czech limited-liability company founded around 2000 and operating from Prague. We work with organisations that have outgrown generic advice — mid-market companies, telcos, utilities, and financial institutions with real environments, existing investments, and specific threats that checkbox frameworks do not address — across Central Europe and the UK. Twenty-five years of practice teaches one quiet lesson: the problems repeat, only the tooling changes.
We operate under the Brownhat brand when engaging clients — a name that reflects our core philosophy: we work in brownfield environments (built up, lived in, carrying the weight of past decisions) and our job is to recultivate what exists before recommending anything new.
What We Do¶
We help organisations close the gaps between their security investments and their actual security posture. In practice, this means:
- Auditing what exists, honestly — not what the policies say should exist
- Maximising the value of tools and licences already paid for
- Closing the kill chain — the specific sequence of failures that would end the business — before anything else
- Building retained capability inside client organisations, not dependencies on us
Every engagement begins with the Brownhat Diagnostic — a structured two-day assessment that produces an honest picture of where the organisation stands and what matters most to fix. We do not make recommendations before we understand the environment.
For the full service menu, see Modular Engagements.
How We Think¶
Five principles shape every recommendation we make:
| Principle | What it means in practice |
|---|---|
| Structural Decoupling | We identify and remove hidden dependencies before they become fatal. We do not add complexity that creates new ones. |
| Optionality Preservation | We spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces your strategic flexibility. |
| Stress-to-Signal Conversion | Every incident, failure, and near-miss is intelligence. We build systems that learn from disruption rather than merely surviving it. |
| Sovereign Intelligence | Your proprietary data should improve your own capability, not a vendor's model. We build tools and systems you own and can operate. |
| Asymmetric Payoff Design | Small, targeted investments on existential risks yield disproportionate protection. We never distribute effort evenly — we concentrate it where failure is fatal. |
For the full philosophical foundation, see The Antifragile Manifest.
What Makes Us Different¶
1. We start with what you own.
Most consultants arrive with a shortlist of products. We arrive with a diagnostic. Before any purchase is discussed, we exhaust the capabilities of existing tools. If your Microsoft E3 tenant can close the gap, we configure it. We earn our fees from expertise, not licence margins.
2. We price by deliverable, not by the hour.
Every engagement has a defined scope and a defined deliverable before work begins. You know exactly what you are paying for. You know exactly what you will hold at the end. There are no open-ended retainers disguised as "ongoing support."
3. Everything we build belongs to you.
Every script, detection rule, configuration, and runbook produced during an engagement is delivered to your own repository. We do not leave proprietary tools running in your environment. We do not hold your own documentation behind a retainer. When an engagement closes, you are operationally independent.
4. We disclose our commercial relationships.
We have commercial partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. When we recommend one of these tools, we say so and explain why the open-source alternative does not meet your specific need. We do not recommend tools because of margin.
5. We tell you what we cannot do.
We are a small, specialist practice. We do not run a 24/7 SOC. We do not sign off on compliance audits. We do not replace your IT team. We work alongside your people, build capability inside your organisation, and leave. If a need falls outside our practice, we say so and point you to the right provider.
6. We operate what we sell.
Our own tooling — ASTRAL for configuration drift, PULSAR for audit-log intelligence, and the playbooks in this repository — runs in our own infrastructure first. The methods we deploy at clients are the methods we run at home, including the agent-assisted operational model we use to keep our own estate honest. We do not recommend anything we have not lived with.
The Team¶
We are a specialist practice of seven to nine people — architects, project managers, and specialist contractors — led by our CEO and Firm Architect. We stay deliberately small: every engagement is led by someone who does the technical work, not someone who manages those who do.
Our Clients¶
We work primarily with:
- Telecommunications operators — carriers and ISPs with signaling, fraud, and 5G-era exposure, usually driven to us by NIS2 obligations or a scare
- Utilities and critical infrastructure — power generation, transmission, and water organisations with OT/IT convergence problems and NIS2/CER scope
- Financial services — institutions working through DORA, PSD2, and SWIFT CSP alignment who need demonstrable controls, not documentation exercises
- Mid-market hybrid estates — 200–2000 employees, AD plus M365, years of accumulated technical debt, and an IT team that knows exactly where the gaps are but has never had the runway to close them
What our clients typically have in common: They have been building and running IT infrastructure for years. They have accumulated technical debt, partially deployed tools, and security gaps they know exist but have not had the resources to address systematically. They do not need a new platform — they need someone to make what they have work properly.
Selected Work¶
We reference engagements anonymously and share detailed case studies — with measurable outcomes — on request. Three archetypes of recent work:
- Critical-infrastructure identity remediation: attack paths to domain dominance reduced by two orders of magnitude; privileged access re-architected around just-in-time, phishing-resistant authentication
- M365 tenant rescue: an E3 tenant reconfigured to close the gaps its owner was paying a SOC to watch; licence spend redirected into capability
- NIS2 readiness sprint: 180 days from "we think we're in scope" to evidence packages an auditor accepts — built almost entirely from tools the client already owned
Partnerships and Accreditations¶
Commercial partnerships (tools we can procure and manage on behalf of clients):
| Partner | What they provide | When we recommend them |
|---|---|---|
| Huntress | Managed EDR, 24/7 threat hunting | Clients without Defender P2 who need round-the-clock endpoint coverage |
| Thinkst Canary | Deception-based intrusion detection | Estates that need high-signal tripwires without a SOC |
| Tailscale | Zero-config overlay networking | Distributed teams and vendor-access scenarios |
| Tenable | Vulnerability management | Organisations that need commercial-grade scanning and reporting |
What We Do Not Do¶
We do not run a 24/7 operations centre. We deploy, configure, and enable monitoring tools. For round-the-clock managed response, we work with commercial partners (Huntress, Thinkst Canary) or help clients build internal capability.
We do not sign off on compliance audits. We prepare clients for audits — mapping controls, building evidence packages, and closing gaps. The audit opinion belongs to the qualified auditor your regulator requires.
We do not replace your IT team. We work alongside your people. Knowledge transfer is part of every engagement. When we leave, your team must be able to operate what we built.
We do not resell tools we would not use ourselves. Every commercial recommendation is disclosed and explained. If an open-source alternative meets your need, we deploy that instead.
We do not take engagements where the goal is paperwork without remediation. If the objective is a certificate rather than a posture, we are the wrong practice.
How to Engage¶
The starting point for every new client is the Brownhat Diagnostic — a two-day structured assessment that produces a prioritised picture of your security posture and a recommended module sequence. It is a paid, bounded engagement that delivers value regardless of whether any further work follows.
For the full diagnostic methodology, see NIST CSF 2.0 Baseline Assessment.
To start a conversation:
| hello@cqre.net | |
| Web | cqre.net |
| Languages | Czech, English, Slovak |
| Geography | Czech Republic and Slovakia on-site; remote engagements across the EU and UK |
| Response time | Initial response within one business day |
Commercial terms summary:
- Engagements are fixed-scope, fixed-price, with deliverables agreed in writing before work begins
- Payment: 50% at kickoff, 50% at completion
- Currency: CZK or EUR
- Contracts governed by Czech law
Integration With Existing Frameworks¶
| Document | Integration |
|---|---|
| Engagement Model | The full engagement lifecycle, pricing model, and client requirements referenced in this document |
| Modular Engagements | The complete service menu |
| NIST CSF 2.0 Baseline Assessment | The Brownhat Diagnostic described in the "How to Engage" section |
| C-Suite Conversation Guide | Client-facing persuasion scripts for executive conversations |
| Sovereign Tool Stack | The tools and partnerships referenced in this document |
For the engagement process, see Engagement Model. For the full service menu, see Modular Engagements.