
Pavel Láska.
Practitioner first. Witness second. Builder third — because the tooling that should have existed back then didn't.
Practitioner across regulated sectors.
Pavel started in education-sector IT, moved through online gaming, then spent eight years in banking — progressing from senior engineer to senior risk manager, on critical financial infrastructure. From there into pharma, managing a global security services team operating across three continents.
The credibility chain isn't titles or certifications (though both — CISSP and CISM). It is the lived experience of being the person filling the supplier spreadsheets, writing the risk assessments that went up to board committees, prepping the evidence packs for auditors, and explaining the same posture three different ways for three different stakeholders.
Vittnor — Supply Chain Assurance for the mid-market — is the tooling that should have existed back then. He founded Shards Cybersecurity s.r.o. in Bratislava in 2023.
Eighteen years in London. Returned to Bratislava in 2022.
Most of Pavel's career happened in London — large UK and global enterprises with mature cybersecurity functions, multi-million-pound technology budgets, dedicated supplier-assurance teams, the full apparatus.
The return to Slovakia in 2022 surfaced something that had been invisible from inside the enterprise: the central-European mid-market doesn't have any of that infrastructure, but it is now subject to the same NIS2 supply-chain obligations as the global enterprises that do. Enterprise GRC suites are priced and structured for the kind of customer Shards' target market will never be. Generic SaaS tools either ignore the regulatory shape entirely or layer it on as an afterthought.
The mid-market in this region needs something built specifically for them — by someone who has done supplier selection, vendor management, and audit-evidence preparation at enterprise scale — and now builds for the companies enterprise vendors don't bother with. That is the gap Shards is built to close.
Coming home has a teaching side too: guest lectures at the Slovak University of Technology in Bratislava and for a cybersecurity specialisation class at a Bratislava gymnasium.

Close the supplier-assurance gap for the segment that bigger players priced out.
Mid-market companies — 50 to 500 staff, often without a dedicated CISO, often without a full GRC team — are now in scope of NIS2 if they sit in a regulated sector or operate critical-infrastructure-adjacent services. Their boards have woken up to Article 20 personal accountability. Their customers have started sending supplier-assurance questionnaires.
Most of these companies cannot afford the enterprise GRC machine, and the advisory market rarely productizes an engagement small enough to make sense for them. They are stuck between a spreadsheet and a platform contract scoped for a company ten times their size.
Shards builds the in-between. The NIS2 Supplier Exposure Assessment when you need a written exposure picture. The NIS2 Qualified Manager retainer when you need ongoing oversight. Vittnor when you need to operationalise the lot. All scoped to fit the segment that's been ignored.
Small team by intention. Built on Microsoft. Shaped by an advisory circle.
Built lean by intention: a small core team — three developers and the founder — with a tight delivery loop. The architecture is built on Microsoft Azure, EU regions only, and the company is a Microsoft Partner with the platform tested through the Microsoft ISV programme. The choice of Microsoft is deliberate: it is the platform our customers already trust, already procure from, and already know how to evaluate for security.
The product itself was shaped by quiet conversations with practising CISOs and security leads across regulated industries — people who have sat in the audit chair, defended supplier decisions to boards, and lived with the consequences. They are not named on this page (they preferred not to be), but they are in the product. We are happy to make introductions in person where it's useful.
The model is: small team, productized engagements, sustainable cadence, customers we can actually know.
Three sensible next steps depending on where you are.
Apply for the pilot
Free or compute-cost. Founder access. Roadmap influence.
See cohort detailsThe two productized engagements
Supplier Exposure Assessment (one-off) and Qualified Manager retainer (ongoing).
See the engagementsTalk to the founder
Practitioner-to-practitioner. Roadmap input, regional context, introductions if useful.
Send a messageBuilt for the practitioner who used to do this on a spreadsheet.
Bratislava · CISSP · CISM · Microsoft Partner