Skip to content

About

An intelligence house, not a reseller

Founded in 2021 and EU-registered. We build the platform, run the investigations and answer the phone — an unusual combination, and the reason our response times are worth publishing.

Where we work

Six regions, one team, one standard.

Our clients operate across the Baltics, the European Union, the Caucasus, Central Asia, the Gulf and the United States — and the adversaries targeting them rarely respect any of those borders. A credential-stuffing crew testing a bank in Baku is frequently the same crew that tested one in Riga a fortnight earlier.

Working across all six is what makes that visible. Intelligence gathered defending one client in one market becomes a detection for every client in every other — which is a genuine advantage of breadth, and the reason we have not narrowed to a single region.

  • Baltics
  • European Union
  • Caucasus
  • Central Asia
  • Gulf
  • United States

Cyberross is registered in Estonia and operates under EU jurisdiction. Where a client’s regulator requires local data residency, that is a scoping conversation — ask us directly rather than assuming either way.

How we work

  • Nothing is subcontracted

    Every engagement is delivered by our own team. It is the only honest way to commit to a response time, and it means the person on your call can actually change what happens next.

  • Intelligence before controls

    We establish who is likely to come for you before configuring anything. A control tuned to a generic threat model protects against a generic threat.

  • Findings escalate immediately

    A critical finding reaches you the moment it is confirmed, never held back to make a report land better at the readout.

  • We say when it is not us

    If your problem is better solved by someone else, or by nobody at all, we will tell you on the first call. It costs us engagements and earns us referrals.

  • Plain language

    Board packs without jargon, findings without severity theatre, and no invented acronyms. If a report needs a translator, it has failed.

  • One standard everywhere

    The same team, the same method and the same reporting whether you are in Riga, Baku, Dubai or Chicago. We do not run a cheaper tier for smaller markets.

The team

The people who answer at 03:00 are the people who wrote the detection.

Our analysts split their time between incident response, threat research and building the platform. It is deliberately inefficient — and it is why a detection we ship reflects how systems are actually breached rather than how a vendor imagines they might be.

We publish research, contribute to international investigations and support law enforcement where we are asked to. That work does not generate revenue. It generates the knowledge everything else depends on.

Read our research

53

Professional certifications held across the team, from 15 issuing bodies.

Independently checkable

Every one is held by a named individual and issued by a body that maintains a public register — so you can verify any of them without asking us. The company itself is not certified, and we will not claim otherwise.

Registered

Cyberross OÜ, Ahtri tn 12, 10151 Tallinn, Estonia. “Cyberross” is a registered European Union trade mark, EUTM 018977523, in classes 9 and 42.

Trust centre and claim register

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.