# Syndis > Syndis provides tailored cybersecurity services including 24/7 SOC monitoring, penetration testing, and rapid incident response. A team you can rely on. ## Pages - [Almennir skilmálar](https://syndis.com/almennir-skilmalar): Almennir skilmálar Syndis ehf. um viðskipti, þjónustu og samninga við viðskiptavini. - [Physical Intrusion Testing](https://syndis.com/services/offensive-security/physical-intrusion-testing): Physical intrusion testing from Syndis. We attempt to enter your offices, reach your network, and plant a rogue device exactly as a real intruder would, so you find out what your physical security actually stops. - [M365 & AD Hardening: close common attack paths](https://syndis.com/services/offensive-security/m365-and-ad-hardening): Structured hardening of Microsoft 365 and Active Directory from Syndis. Three defined packages that close common attack paths, protect identities, and raise your security baseline across cloud and on-prem. - [Integritetspolicy](https://syndis.com/privacy-policy-sv): Så samlar Syndis AB in, använder och skyddar dina personuppgifter. - [Basics of AI Pentesting for Developers: secure your AI attack surface](https://syndis.com/services/training/ai-pentesting-for-developers): AI pentesting training for developers from Syndis. A hands-on course on the AI attack surface, prompt injection, and jailbreaking for teams building with LLMs and agents. - [Endpoint Defenses Testing: validate controls and SOC detection](https://syndis.com/services/offensive-security/endpoint-defenses-testing): Endpoint defenses testing from Syndis. A goal-oriented, post-exploitation assessment of your local security controls and SOC detection capabilities, with a findings overview, gap analysis, and remediation roadmap. - [Response Readiness: business continuity and disaster recovery](https://syndis.com/services/advisory/response-readiness): Response Readiness from Syndis. Business continuity and disaster recovery: business impact analysis, RTO/RPO, continuity and recovery runbooks integrated with incident response, tested before reality does. - [Cyber Due Diligence: technical risk assessment for M&A](https://syndis.com/services/advisory/cyber-due-diligence): Cyber due diligence from Syndis. A white-box technical and code assessment of acquisition targets, with OWASP Top 10 focus and investor-ready reporting, typically in 5 to 10 days. - [NIS2 Termometer](https://syndis.com/nis2-sv): NIS2-direktivet ställer nu högre krav på cybersäkerhet för kritisk infrastruktur. Använd vår termometer för att stämma av er verksamhet mot kraven och se var ni står idag. - [NIS-1 og NIS-2](https://syndis.com/blog/nis-1-og-nis-2): Í stuttu máli ættu allir sem vilja vera tilbúnir að bregðast við áföllum að eiga gagnlega áætlun um samfelldan rekstur. - [Gildissvið NIS2](https://syndis.com/blog/gildissvid-nis2): Með tilkomu NIS2 eru þeir rekstraraðilar sem flokkast undir nauðsynlega og mikilvæga starfsemi, skyldugir til þess að fylgja samræmdum net- og upplýsingaöryggiskröfum og að tryggja að tilteknir birgjar og þjónustuaðilar þeirra innleiði einnig viðeigandi öryggisráðstafanir. - [System Admin Training: harden everyday operations](https://syndis.com/services/training/system-admin-training): System administrator training from Syndis. Identity and privilege hygiene, hardening, patching, secure remote access, and monitoring readiness, tailored to your setup. - [Security Dev Training: secure coding, hands-on](https://syndis.com/services/training/security-dev-training): Security developer training from Syndis. Hands-on secure coding on the OWASP Top 10, auth, secrets, secure design, and dependencies, tailored to your stack. - [NIS2 and DORA Training: understand and own compliance](https://syndis.com/services/training/nis2-and-dora-training): NIS2 and DORA training from Syndis. Plain-language obligations, governance, incident reporting, supplier controls, and role-based guidance for leaders and teams. - [GDPR Training: safe data handling, made practical](https://syndis.com/services/training/gdpr-training): GDPR training from Syndis. Lawful handling, transparency, data minimisation, retention, data subject rights, and breach awareness, with role-based scenarios. - [Executive and Staff Awareness Training](https://syndis.com/services/training/executive-and-staff-awareness): Security awareness training from Syndis. Phishing recognition, safe data handling, MFA hygiene, and incident reporting, plus executive crisis and governance modules. - [AwareGo Platform: security training at scale](https://syndis.com/services/training/awarego-platform): AwareGo platform from Syndis. Partner resale and support: rollout, assignment workflows, completion tracking, and compliance reporting for training at scale. - [24/7 SOC Monitoring: always-on detection and triage](https://syndis.com/services/detection-response/soc-monitoring): 24/7 SOC monitoring from Syndis. Continuous monitoring of endpoint, identity, cloud, and network signals, with clean triage, clear escalation, and detection tuning. - [Managed Detection and Response (MDR): rapid containment](https://syndis.com/services/detection-response/managed-detection-and-response): Managed detection and response from Syndis. Expert investigation, containment, eradication, and recovery support with a documented response trail. - [Incident Response Team: contain, eradicate, recover](https://syndis.com/services/detection-response/incident-response-team): Incident response from Syndis. Triage, containment, eradication, and recovery with calm leadership and documented decisions, as emergency support or a retainer. - [Incident Management](https://syndis.com/services/detection-response/incident-management): On-call incident response from senior practitioners. Engagement within minutes, structured containment and recovery, post-incident learning baked in. - [Honeypots: high-confidence detection from decoys](https://syndis.com/services/detection-response/honeypots): Managed honeypots from Syndis. Decoy systems that produce high-confidence alerts and indicator capture, integrated into monitoring and response. - [Aftra - Cybersecurity through the eyes of the hacker. ](https://syndis.com/services/detection-response/aftra): Continuous visibility into your digital footprint, vulnerabilities and security risk, helping leadership stay in control while enabling IT teams to act faster. - [Digital Forensics: the facts, timeline, and evidence](https://syndis.com/services/detection-response/digital-forensics): Digital forensics from Syndis. Evidence acquisition, timeline reconstruction, impact validation, and defensible reporting, with chain-of-custody when needed. - [Dark Web Monitoring: early warning for leaked data](https://syndis.com/services/detection-response/dark-web-monitoring): Dark web monitoring from Syndis. Continuous monitoring for exposed credentials, data, and brand, with credibility assessment and recommended remediation. - [Crisis Communication Support during security incidents](https://syndis.com/services/detection-response/crisis-communication-support): Crisis communication support from Syndis. Stakeholder mapping, messaging, drafts, and sequencing that protect trust and support the technical response. - [Vanta Partnership: compliance automation, done right](https://syndis.com/services/advisory/vanta-partnership): Vanta partnership from Syndis. Proper setup, control and evidence mapping, integrations, and ongoing operation so evidence stays fresh and audits get easier. - [Tabletop Exercises: test your incident response live](https://syndis.com/services/advisory/tabletop-exercises): Tabletop exercises from Syndis. Realistic, facilitated crisis simulations that test decisions, communication, and escalation, with findings and improvement actions. - [Risk Management: a clear, prioritised view of real risk](https://syndis.com/services/advisory/risk-management): Practical risk management from Syndis. Asset and process mapping, threat analysis, scoring, treatment, and a living risk register aligned to ISO 27001. - [Regulatory Readiness: NIS2, DORA, ISO 27001, SOC 2, PCI](https://syndis.com/services/advisory/regulatory-readiness): Regulatory readiness from Syndis. Scoping, control mapping, gap remediation, and evidence for NIS2, DORA, ISO 27001, SOC 2, and PCI DSS, on one roadmap. - [NIS2 Compliance](https://syndis.com/services/advisory/nis2): NIS2 gap assessment, remediation, and ongoing compliance support. Pragmatic, audit-ready, delivered by senior practitioners. - [ISO 27001 implementation and audit support](https://syndis.com/services/advisory/iso27001): ISO 27001 gap analysis, ISMS implementation, internal audits, and certification support. Pragmatic and audit-ready. - [Internal Audits: strengthen your security program](https://syndis.com/services/advisory/internal-audits): Internal audits from Syndis. ISO 27001-aligned audit planning, control testing, findings classification, and corrective actions, for a calmer external audit. - [GDPR Gap Analysis: a prioritised path to compliance](https://syndis.com/services/advisory/gdpr-gap-analysis): GDPR gap analysis from Syndis. A clean baseline across governance, data flows, vendors, security, and retention, with a risk-rated report and roadmap. - [DPO as a Service: a dedicated Data Protection Officer](https://syndis.com/services/advisory/dpo-as-a-service): DPO as a Service from Syndis. A named privacy lead aligned to GDPR Articles 37 to 39: governance, RoPA, DPIAs, breach support, and regulator communications. - [Corporate IT Lawyer as a Service: tech and data contracts](https://syndis.com/services/advisory/corporate-it-lawyer): Corporate IT Lawyer as a Service from Syndis. Practical legal support for DPAs, SCCs, cloud contracts, security and liability clauses, and procurement. - [Compliance Gap Analysis: a fast baseline to readiness](https://syndis.com/services/advisory/compliance-gap-analysis): Compliance gap analysis from Syndis. A structured review against NIS2, DORA, ISO 27001, SOC 2, or PCI DSS, with severity-rated gaps and a staged roadmap. - [CISO as a Service: senior security leadership on tap](https://syndis.com/services/advisory/ciso-as-a-service): CISO as a Service from Syndis. Senior, hands-on security leadership, strategy, governance, risk ownership, and board reporting, without hiring a full-time executive. - [Syndis + LOGOS Morgunfundur](https://syndis.com/syndis-logos-morgunfundur): Syndis and LOGOS breakfast briefing on DORA and NIS2 obligations. - [Get a SOC Quote](https://syndis.com/soc-quote): Request a tailored Syndis SOC monitoring quote for your organization. - [Services](https://syndis.com/services): Offensive security, security management, training, and 24/7 detection and response. Senior experts who build their own tools, named on the team page. - [Training](https://syndis.com/services/training): Practical security training built on real attacker tactics. Developer secure coding, system admin hardening, executive and staff awareness, NIS2/DORA, GDPR, AwareGo platform. - [Offensive Security](https://syndis.com/services/offensive-security): Pentesting, red teaming, AWS audits, and social engineering by people who build their own tools. Senior Nordic team, OSCP-certified, no checklist work. - [Social Engineering Assessments: phishing, vishing, physical](https://syndis.com/services/offensive-security/social-engineering-assessments): Social engineering assessments from Syndis. Phishing, phone pretexting, and physical intrusion testing that measures how your people respond and strengthens your human firewall. - [Red Teaming](https://syndis.com/services/offensive-security/red-teaming): Goal-driven adversary simulations testing your full detection and response chain. Built by people who write their own tools. - [Purple Team Testing: collaborative red and blue team exercises](https://syndis.com/services/offensive-security/purple-team-testing): Purple team testing from Syndis. Red and blue teams work together in real time to validate and improve detection and response, including endpoint and SOC defense validation. - [Application & Cloud Pentests](https://syndis.com/services/offensive-security/penetration-testing): Penetration testing that finds what matters, proves what is exploitable, and tells you exactly how to fix it. One-off or two-per-year subscription. - [Syndis Cyber Journey Program](https://syndis.com/services/offensive-security/cyber-journey-program): The Syndis Cyber Journey Program. A structured path to mature, measurable security. - [AWS Infrastructure Audit: misconfigurations and attack paths](https://syndis.com/services/offensive-security/aws-infrastructure-audit): AWS infrastructure audit from Syndis. We find misconfigurations, excessive privilege, and real attack paths, including privilege escalation and cross-account abuse, from an attacker's perspective. - [Detection & Response](https://syndis.com/services/detection-response): 24/7 detection and response from senior Nordic analysts. Managed SOC, honeypots, dark web monitoring, external attack surface monitoring, incident response, digital forensics, crisis communication. - [Advisory](https://syndis.com/services/advisory): Senior security and privacy leadership embedded in your organisation. CISO and DPO as a service, NIS2, DORA, ISO 27001, BCP/DR, IT law, and compliance gap analysis. - [Privacy Policy](https://syndis.com/privacy-policy): How Syndis collects, uses, and protects personal data. - [Price Changes 2026](https://syndis.com/price-changes-2026): Information about Syndis price changes for 2026. - [NIS2 Hitamælir](https://syndis.com/nis2): Check your NIS2 readiness with Syndis. A quick self-assessment and follow-up from a senior advisor. - [IT-Säkerhetsbolaget och Syndis](https://syndis.com/itsb): IT-Säkerhetsbolaget and Syndis. Combined Nordic cybersecurity expertise from Stockholm. - [Insights](https://syndis.com/insights): Articles, research, and threat analysis from our security practitioners. Built for Nordic context, written for senior readers. - [Email Disclaimer](https://syndis.com/email-disclaimer): Confidentiality, accuracy, and liability statement for emails sent from Syndis. - [Contact](https://syndis.com/contact): Discovery call this week. Senior practitioner on the call. No sales pressure, just a conversation about whether we're the right fit. - [Careers](https://syndis.com/careers): Senior offensive, defensive, and advisory roles. Work alongside Iceland's most experienced cybersecurity practitioners on serious Nordic engagements. - [About Syndis: Cybersecurity since 2013](https://syndis.com/about-us): Iceland's most experienced cybersecurity company. Founded 2013. Senior practitioners across Reykjavík and Stockholm. ## Posts - [Possibly the First Serious AI-Assisted Cyberattack Investigated by Syndis](https://syndis.com/insights/possibly-the-first-serious-ai-assisted-cyberattack-investigated-by-syndis): Over the past few days, cybersecurity experts at Syndis have been grappling with what appears to be one of the most complex and sophisticated cyberattacks the company has investigated to date. Strong evidence suggests that the attack methodology was developed with the assistance of a Large Language Model (LLM), despite the safety guardrails typically built into these models to prevent such misuse. - [The best compliance software for European companies in 2026](https://syndis.com/insights/the-best-compliance-software-for-european-companies-in-2026): Compliance without security rarely holds up. It should strengthen an organization's actual security posture, not just create paperwork for audits. - [Defcon CTF](https://syndis.com/insights/defcon2023): The Defcon CTF (Capture The Flag) competition, widely regarded as the most prestigious contest among cybersecurity professionals, concluded on August 14th in Las Vegas. - [Precision fraud: Analyzing the personalized WhatsApp hospitality phishing campaign](https://syndis.com/insights/whatsapp-phishing): In recent weeks, Syndis has observed a unique and targeted phishing campaign affecting over 3,000 travelers. Unlike traditional phishing waves that rely on mass emails and generic lures, this operation is precise, structured, and leverages real reservation data to deceive even security aware individuals based on what seems to be stolen or compromised data. - [The Mythos effect: Securing your infrastructure against AI-generated exploits](https://syndis.com/insights/the-mythos-effect): The media hype around AI-driven vulnerability discovery is deafening right now, especially following the news of Anthropic's Mythos and Project Glasswing. But what does the actual technical data tell us? - [Tabletop Exercises](https://syndis.com/insights/tabletop-exercises): Unhack the planety - [Syndis secures major contract in Sweden to protect public services](https://syndis.com/insights/syndis-secures-major-contract-in-sweden-to-protect-public-services): We are thrilled to announce a significant milestone in our expansion journey: Syndis has officially signed its first major contract in Sweden, winning a public tender to provide comprehensive security monitoring and response services to four Swedish municipalities - [How we embrace AI at Syndis; On both sides of the cyber battlefield](https://syndis.com/insights/syndis-on-artificial-intelligence): Artificial Intelligence is transforming cybersecurity faster than any previous technology wave. But despite the hype, AI is neither a silver bullet nor an autonomous hacker replacing human expertise. It is a force multiplier, and like any powerful tool, it must be guided, constrained, and governed. Here is how we approach AI at Syndis. - [Syndis and Dropbox](https://syndis.com/insights/syndis-dropbox): Unhack the planety - [The Syndis Security Conference 2026!](https://syndis.com/insights/syndis-conference-2026): In a world where digital threats move faster than ever, staying ahead isn't just about having the right software, it's about having the right mindset. This year, we're bringing together some of the brightest minds in global cybersecurity to help you Unhack the planet right here in Reykjavík. - [Syndis named company of the year 2026 and wins the VR Education Award](https://syndis.com/insights/syndis-company-of-the-year-2026): Both recognitions come directly from employee feedback in VR's annual workplace survey. - [Syndis at Stockholm Tech Show 2025](https://syndis.com/insights/syndis-at-stockholm-tech-show-2025): Syndis recently took part in the Stockholm Tech Show 2025, marking a key step in expanding our presence in the Nordic region. With a booth, two keynote talks, and a live hacking competition, the event offered a valuable opportunity to engage with the wider tech and cybersecurity community. - [Syndis at Palo Alto Networks Annual Security Event in Reykjavík](https://syndis.com/insights/syndis-at-palo-alto-networks-annual-security-event-in-reykjavik): We're excited to join the Palo Alto Networks Cybersecurity Conference on October 16th at Nauthóll, Reykjavík. - [Syndis and Dediko bring elite cybersecurity to Denmark.](https://syndis.com/insights/syndis-and-dediko-collaboration): We are proud to announce our partnership with Dediko A/S, one of Denmark's most trusted names in IT security. - [Syndis and Abero arrive in Helsinki to strengthen Finnish cybersecurity](https://syndis.com/insights/syndis-and-abero-collaboration): We are excited to announce that Syndis and Abero Finland are expanding and opening a joint operation in Helsinki! - [Syndis acquires IT-Säkerhetsbolaget](https://syndis.com/insights/syndis-acquires-it-sakerhetsbolaget): We're incredibly proud to announce that Syndis has officially acquired IT-Säkerhetsbolaget, a trusted Swedish cybersecurity firm with deep expertise in compliance, data protection, and advisory services. - [Season's greetings and thank you for a strong year](https://syndis.com/insights/seasons-greetings-and-thank-you-for-a-strong-year): The past year has been an important and eventful one for Syndis. We continued to grow rapidly, both through our own expansion and through the strategic acquisitions of Ísskógar and IT-Säkerhetsbolaget, strengthening our service offering and accelerating our growth. During the year, we also opened a new office in Stockholm, further supporting our expansion in Sweden. - [Proactive measures against system intrusions](https://syndis.com/insights/proactive-measures-against-system-intrusions): In today's world, computer systems are the backbone of most companies. It's crucial to protect these systems, yet often the mindset is, “It’s been set up this way for years—why change it now?” - [Phishing-Resistant Authentication](https://syndis.com/insights/phishing-resistant-authentication): Traditional multi-factor authentication (MFA) is no longer sufficient against increasingly complex cyberattacks targeting identity theft. - [Partnership with Wise](https://syndis.com/insights/partnership-with-wise): Syndis is proud to announce a strategic partnership with Wise, one of Iceland's leading technology companies, aimed at strengthening the cybersecurity posture of businesses and public institutions across the country. - [A strategic cybersecurity partnership with Axia IT](https://syndis.com/insights/partnership-with-axia-it): As the cybersecurity landscape grows increasingly complex, defending against modern threats requires a unified approach that combines resilient IT infrastructure with specialized security operations. Today, Syndis is pleased to announce a strategic partnership with Axia IT to deliver exactly that. - [Outsourcing Security Awareness Training to Experts](https://syndis.com/insights/outsourcing-security-awareness-training-to-experts): Syndis offers outsourced management of cybersecurity awareness training. The program includes regular assessments and short educational videos provided by AwareGO, available in 18 languages—including Icelandic, English, Polish, and the Nordic languages. - [ISO 27001 Consulting and Services](https://syndis.com/insights/iso-27001-consulting-and-services): Syndis provides specialized consulting services for organizations seeking to implement and maintain ISO/IEC 27001 compliance. - [Incident Management](https://syndis.com/insights/incident-management): At Syndis, we've assisted in numerous incidents following cyberattacks, ranging from those affecting individual users to attacks that cripple entire computer systems and organizations. - [Ransomware](https://syndis.com/insights/gagnagislataka): Syndis has observed a significant increase in cyberattacks in recent months. Incidents are now occurring on a monthly or even weekly basis where attackers have successfully breached the IT systems of Icelandic companies. - [The top cybersecurity expert in Sweden](https://syndis.com/insights/david-jacoby-joins-syndis): David has over 25 years of experience in cybersecurity, making his appointment a key addition to Syndis' strong team and strengthening the company's international expansion. - [Cybercrime can happen to anyone, the real lesson from Sweden](https://syndis.com/insights/cybercrime-can-happen-to-anyone-the-real-lesson-from-sweden): Every week brings headlines of another cybersecurity incident. Each one is a stark reminder of how fragile our societies have become in a world where everything is connected. A single breach at one supplier can ripple out to affect hundreds of municipalities. - [Crowdstrike/Microsoft outage summary](https://syndis.com/insights/crowdstrike-microsoft-outage): Hér vantar description - [Collaboration with LOGOS](https://syndis.com/insights/collaboration-with-logos): Syndis is excited to announce a strategic partnership with LOGOS, a leading Icelandic law firm specializing in corporate law. This collaboration merges Syndis' cybersecurity expertise with LOGOS' legal know-how, providing integrated solutions for organizations facing complex security and compliance challenges. - [ClickFix – A recent cyberattack every company should be aware of](https://syndis.com/insights/clickfix): ClickFix is a recent type of cyberattack that leverages phishing techniques to deceive company employees. - [A Note on Remote Access VPNs](https://syndis.com/insights/a-note-on-remote-access-vpns): Many companies talk about moving away from their VPN: a deliberate, planned project involving architecture reviews and modern zero-trust frameworks. That's often a big undertaking.