Frutree, s.r.o.
A food-industry company that needed to bring its IT into line with cybersecurity legislation while modernising and securing the whole IT environment, from backup through the network to endpoint protection.
- Industry: Food industry
- Focus: cybersecurity, NIS2, IT infrastructure
- Scope: compliance, IT modernisation and IT management
- Length of engagement: since January 2026, ongoing
NIS2 compliance and secure, modern IT
From 1 January 2026 the company had to comply with Act 69/2018 Coll. on cybersecurity, its implementing decrees and the NIS2 directive, and at the same time modernise and secure its entire IT environment.
- Reach compliance with Act 69/2018 and the NIS2 directive
- Protect company data and the network from cyber threats
- Modernise the ageing network and server infrastructure
- Put permanent supervision, monitoring and expert IT management in place
A solution built to fit
We took on the role of cybersecurity manager and designed and implemented a modernised IT infrastructure that meets cybersecurity requirements. From 15 June 2026 we also took over management of the whole IT environment.
- Cybersecurity manager , coordinating security measures, overseeing compliance with legislation (Act 69/2018, NIS2), assessing cyber risk and supporting the roll-out of new processes.
- Central backup , a Synology RS822+ with enterprise disks (32 TB), daily backups of critical data, a separate backup account and immutable 30-day retention.
- Off-site backup and recovery , copies of critical data to geographically separate storage, alerting on failed backups, regular recovery testing and a documented disaster recovery (DR) plan.
- Network security , a central FortiGate 70G firewall (Unified Threat Protection licences, FortiCare Premium), firewall rules, secure remote access and VPN including OpenVPN.
- Network modernisation , managed Ubiquiti UniFi switches with PoE, a new enterprise Wi-Fi 7 network (UniFi U7 Pro), topology optimisation and a tidy-up of the central data cabinet.
- Domain environment , a hybrid domain, security policies for domain controllers and workstations, and a gradual move of workstations into the centrally managed domain.
- Endpoint protection , centralised protection and a central ESET console, plus security configuration of the Microsoft 365 environment in cooperation with an external supplier.
- Security monitoring , deployment of Wazuh to collect, evaluate and centrally monitor security events, along with technical installation and configuration of workstations, peripherals and scanners.
What we worked with
Real impact for the client
The company complies with cybersecurity requirements, its data and network are protected by modern infrastructure, and the IT environment is under continuous expert management.
The company meets its cybersecurity obligations under the supervision of a cybersecurity manager.
Daily, immutable and geographically separate backups with tested recovery and a disaster recovery plan protect the critical data.
Since June 2026 we have run the day-to-day management of servers, network, workstations, backup and security systems, incident handling included.