Exposure monitoring, penetration testing, incident response and ISO 27001 readiness for Swiss companies. Fixed scope, known price, senior specialists only. No junior handoffs and no 90-page decks.
Geneva-based, independentSwiss company, tied to no vendor.
Founder-ledYou deal directly with the founders. No account managers and no sales layers.
Fixed priceAgreed in writing before any work starts.
Reply within 48 hoursUsually within 24, with a proposal or clear questions.
Founder-led. Senior-delivered. Direct access.
Senior expertise. Direct access.
Technical engagements are led by senior cybersecurity practitioners with current leadership experience in highly regulated financial environments. You work directly with the people responsible for your engagement.
Cybersecurity leadership
Regulated environments
Direct senior access
Cybersecurity services for Swiss companies
Use one service or combine them. Every engagement ends with clear priorities and a plan your team can act on.
External attack surface monitoring
We map every domain, server, cloud service and login page you expose to the internet, then flag what an attacker would try first.
Continuous
Dark web monitoring
We watch criminal markets and leak sites for your credentials, your data and your executives' identities, and tell you what to do when something appears.
Continuous
Penetration testing
We attack your web apps, network or cloud the way real attackers would, with your written authorisation, and show you how to close every gap.
Project
Incident response
We contain the attack, establish what happened, restore operations and help you meet your nFADP and insurer reporting duties.
On demand
ISO 27001 and nFADP compliance
Gap analysis, policies and audit preparation that turn certification and nFADP (nLPD/nDSG) compliance into a project with an end date.
Project
Leadership briefings
Your real threat picture, legal exposure and decision rights, explained to the board and management in business terms.
Half day
Why it can't wait
Cybersecurity obligations are becoming more specific, with defined reporting deadlines and potential personal liability in certain cases.
nFADP
Certain intentional offences under the Swiss nFADP are punishable by fines. Depending on the offence, liability can fall on the responsible individual.
24 h
Critical infrastructure operators must report a cyberattack to the federal NCSC within 24 hours. Fines apply since 1 October 2025.
72 h
Where the GDPR applies, certain personal data breaches must be notified to the competent supervisory authority within 72 hours.
Sources: Swiss Federal Act on Data Protection (nFADP), Art. 60–64. Information Security Act, reporting obligation in force since 1 April 2025 (NCSC / Federal Office for Cybersecurity). GDPR, Art. 33.
From first message to fixed-price proposal in 48 hours
1
Answer a short questionnaire
About two minutes, no call needed. Tell us what you need and how urgent it is.
2
Receive a fixed-price proposal
Within 48 hours, usually within 24: scope, timeline and price in writing.
3
We do the work
The founders remain directly involved throughout the engagement, with senior specialists leading the technical work. NDA available if required, with written rules of engagement for any testing.
4
Act on clear answers
Prioritised findings, a 90-day action plan and a debrief with the founders and the technical lead where relevant.
Fixed scope. Clear outcome. Known price.
Three ways to start. Every proposal confirms scope, timeline and price in writing before any work begins.
Founding clients: 20% off your first engagement for our first 5 clients, until 31 December 2026, in exchange for a reference.
Start here
Cyber Exposure Assessment
5 days
What attackers can see, what is leaking, and where your controls and nFADP duties fall short.
External attack surface and dark-web check
Review of your key security controls
nFADP gap review
Prioritised risk map and 90-day plan
Debrief with the founders and senior technical lead
FromCHF 4'900
Fee fully credited if you book a pentest or retainer within 30 days.
ISO 27001 implementation is quoted after the gap analysis.
Payment terms
Projects: 50% on order, 50% on delivery.
Larger projects can be split into monthly instalments on request.
Monitoring and retainers are billed monthly.
Launch offer, limited places
Free External Exposure Snapshot
See what attackers can already find about your company: exposed services, forgotten domains, leaked company data. Passive and non-intrusive: we never touch your systems.
In Japanese martial arts, zanshin is the awareness a fighter keeps after the strike. The exchange is not over until it is over.
Zanshin Cyber Combat CH was founded at the crossroads of cybersecurity and combat sports, and we work the same way: no panic, no theatre, and no dropped guard once the report is delivered.
Competence
Senior specialists only. Technical work is led by experienced cybersecurity practitioners, with direct founder involvement throughout the engagement.
Speed
Proposals within 48 hours. Decisions in days, not quarters.
Solutions
Every finding comes with a fix, an owner and a priority.
A deliberately limited client roster
We cap the number of clients we take on, so each one gets founder attention and continuity. Every request is reviewed individually.
An elite combat-sport professional with top-level competition experience leads the physical pressure drills. Their full profile is shared with clients under confidentiality during preparation.
When pressure removes time, certainty and control, how does your team actually perform?
Cybersecurity combined with elite combat-sport principles. Your leadership team practises decision-making under pressure, in a cyber crisis tailored to your organisation.
For executives, principals and their families. We map what is exposed about you online, from personal data and home addresses to leaked credentials and impersonation, then reduce it and keep watch.
Contact us from a clean device, not a compromised one.
Get a fixed-price proposal
Answer a few questions; it takes about two minutes. We reply within 48 hours, usually within 24, with a proposal or the few questions we still need answered.
Zanshin Cyber Combat CH is a brand of PTK&Co Consultants Santin Aguilera Chemin de la Traille 21 1213 Onex, Geneva, Switzerland Responsible: Irina Santin, Co-Founder [email protected]
Privacy
Controller: PTK&Co Consultants Santin Aguilera (Zanshin Cyber Combat CH), Chemin de la Traille 21, 1213 Onex. We process the details you send us through the questionnaire or by email (name, company, role, contact details, message) only to answer your request, prepare a proposal and, if we work together, perform the contract, in line with the Swiss Federal Act on Data Protection (nFADP). The questionnaire is processed by our own web server and delivered to us by email; we use no third-party form service. To block spam, the server keeps a hashed (anonymised) form of your IP address for one hour. Our email is hosted by Infomaniak in Switzerland; web hosting is provided by a service provider that processes data on our behalf. We keep enquiries only as long as needed for these purposes, unless the law requires longer retention. No tracking cookies, no analytics and no third-party fonts. Your data is never sold. To access, correct or delete your data, email [email protected].