Files
website/content/en/about.md
T

53 lines
3.7 KiB
Markdown

---
title: "About CQRE"
description: "Specialist cybersecurity consultancy and open-source tool developer. Antifragile security for organisations that have outgrown generic advice."
eyebrow: "About Us"
lead: "CQRE.NET Ltd is a specialist cybersecurity consultancy registered in the United Kingdom, operating primarily from Prague, Czech Republic. We work with organisations across Central Europe and the UK."
---
## Who We Are
We help organisations close the gap between their security investments and their actual security posture. In practice, this means auditing what exists honestly — not what the policies say should exist — maximising value from tools already paid for, and building retained capability inside client organisations rather than dependencies on us.
We operate under the **Brownhat** brand when engaging with clients — a name that reflects our core philosophy: we work in brownfield environments (built up, lived in, carrying the weight of past decisions) and our job is to recultivate what exists before recommending anything new.
We also build open-source tools — **PULSAR** and **ASTRAL** — used by M365 administrators and security teams who need continuous audit log retention and configuration governance without vendor lock-in. **AURORA**, our commercial intelligence layer, sits above both.
## How We Think
Five principles shape every recommendation we make:
| Principle | What it means in practice |
|-----------|--------------------------|
| **Structural Decoupling** | Identify and remove hidden dependencies before they become fatal. Do not add complexity that creates new ones. |
| **Optionality Preservation** | Spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces strategic flexibility. |
| **Stress-to-Signal Conversion** | Every incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it. |
| **Sovereign Intelligence** | Your proprietary data should improve your own capability, not a vendor's model. Own the tools and systems you depend on. |
| **Asymmetric Payoff Design** | Small, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal. |
## What We Do Not Do
**We do not run a 24/7 SOC.** We deploy, configure, and commission monitoring tools. For continuous managed response, we work with commercial partners or help clients build internal capability.
**We do not sign off on compliance audits.** We prepare clients for audits — mapping controls, building evidence packages, closing gaps. The audit opinion belongs to a qualified auditor.
**We do not replace your IT team.** We work alongside your people, transfer knowledge as a matter of course, and leave when the engagement closes. When we leave, your team can operate what we built.
**We disclose our commercial relationships.** We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. If we recommend one of these tools, we say so and explain why the open-source alternative does not meet your specific need.
## Contact {#contact}
The best way to start is to send us a message describing your situation. We will respond with an honest assessment of whether and how we can help.
| | |
|-|-|
| **Email** | hello@cqre.net |
| **Web** | cqre.net |
| **Languages** | English, Czech |
| **Geography** | Czech Republic, Slovakia, UK; remote engagements across the EU |
| **Response time** | Initial reply within 1 business day |
For open-source tool questions, issues, and contributions, please use the GitHub repositories directly:
- [github.com/cqrenet/pulsar](https://github.com/cqrenet/pulsar)
- [github.com/cqrenet/astral](https://github.com/cqrenet/astral)