Expect free drinks, some food, two practical talks, and open exchange with people who care about building stronger, more resilient companies. This event is for founders, leaders, operators, IT professionals, and anyone in startups or SMEs who wants to better understand security, pentesting, governance, certifications, and regulatory requirements such as ISO 27001, DORA, PCI DSS, and NIS2.
SME Security & Compliance Guild: Launch Event Agenda
Talk 1: Pentesting for SMEs – When to Do It, What to Expect, What to Avoid
Pentesting is often misunderstood. Some companies think it is only relevant for large enterprises, while others pay for low-value testing without knowing what good looks like. This session will explain when pentesting makes sense for SMEs, how professional pentests actually work, and how to get real value without wasting budget.
We will cover:
- the difference between automated scanning and a real pentest
- when a pentest makes sense, and
- when it does not
- what a professional pentest process actually looks like: scoping, rules of engagement, testing, reporting, and retesting common findings in smaller companies
- how to get value from a pentest without wasting budget
- how pentests support customer trust, audits, certifications, and enterprise sales
Talk 2: Start Early, Scale Smarter – GRC for Startups and SMEs
Governance, risk, and compliance are often treated as something to deal with later. In reality, waiting too long usually makes things slower, harder, and more expensive.
This session looks at why early GRC work is a strategic advantage for startups and SMEs, and how to start in a lean and practical way.
We will cover:
- why GRC is not just for large enterprises
- what happens when companies delay structure until a customer, investor, or regulator forces it
- how early work on policies, controls, responsibilities, and documentation reduces future pain
- how GRC supports certifications and frameworks like ISO 27001, DORA, PCI DSS, and NIS2 how basic governance decisions early on save time and money later
- common mistakes such as spreadsheet chaos, unclear ownership, retrofitting controls, and audit panic
- how SMEs can start lean without building a huge compliance machine
After the talks, we will open the floor for questions, discussion, and socialising. Whether you are just starting your journey or already dealing with growing customer, regulatory, or certification requirements, this meetup is designed to offer practical insight, real-world experience, and useful connections.
We look forward to welcoming you at OSM Solutions in Vienna.