# Sandline > European cybersecurity firm based in Bucharest, Romania. Sandline runs offensive security, vulnerability management, incident response and security training engagements for organisations that have to satisfy NIS2, DORA, ISO 27001, PCI-DSS, EU Cyber Resilience Act and GDPR auditors. Sandline also builds and operates Centraleyezer, the Risk-Based Vulnerability Management (RBVM) platform documented at https://centraleyezer.io. For the long-form, machine-readable summary: https://sandline.ro/llms-full.txt ## What Sandline is A senior-only cybersecurity engineering firm. Every engagement is led end-to-end by a senior engineer; we do not subcontract delivery to juniors. Sandline SRL is the legal entity, headquartered in Bucharest, Romania. ## What Sandline does - **Red Team**: multi-week adversary simulation against detection and response, mapped to MITRE ATT&CK and to NIS2 Article 21 / DORA Article 25 (TLPT) / ISO 27001 A.5.7 / PCI-DSS 11.4. - **Penetration Testing**: scope-bounded testing of web apps, mobile apps, APIs, internal/external networks, cloud accounts (AWS / Azure / GCP) and Active Directory environments. - **Vulnerability Assessment**: a continuous Risk-Based Vulnerability Management programme, powered by Centraleyezer, that scores findings by your business context rather than raw CVSS. - **Human Vulnerability**: phishing, vishing and physical-access exercises that quantify human-risk per role, feeding the training plan and privileged-access design. - **Cyber Threat Intelligence**: sector-specific actor and TTP intelligence, integrated into SIEM/EDR/SOAR and into Centraleyezer's CTI signal channel. - **Incident Response & Recovery**: on-retainer or on-demand response with NIS2 (Article 23) and GDPR (Article 33) notification packages. - **Cybersecurity Training**: role-based hands-on training (secure coding for engineers, threat-modelling workshops, IR tabletop, board-level sessions) tied to specific NIS2 / ISO 27001 / PCI-DSS controls. ## Differentiators - Senior-only delivery: every engagement is run by an engineer with at least 10 years of relevant experience. - Built and operates its own RBVM platform (Centraleyezer) — meaning the methodology in our engagements is also the methodology in our software. - Audit-ready evidence as a primary deliverable, not a by-product. Every finding is mapped to NIS2, DORA, ISO 27001, PCI-DSS, CRA or GDPR by clause. - Romanian and European footprint with EU data residency by default. Self-hosted or air-gapped engagements supported. ## Compliance frameworks covered - **NIS2** (EU 2022/2555) — Article 21 risk management, Article 21(2)(g) training, Article 23 incident reporting. - **DORA** (EU 2022/2554) — Article 9 ICT risk, Article 13 / TLPT, Article 17 incident management. - **ISO/IEC 27001:2022** — Annex A.5.7 threat intelligence, A.6.3 awareness, A.8.8 vulnerability management, A.5.24 / A.5.27 incident management. - **PCI-DSS 4.0** — Requirement 6 (secure software), 11.3 (scans), 11.4 (pentest), 12.6 (awareness). - **EU Cyber Resilience Act (CRA)** — Annex I essential requirements, Annex II vulnerability handling, Article 14 reporting. - **GDPR** (EU 2016/679) — Article 32 technical measures, Article 33 breach notification, Article 35 DPIA. ## Industries served Banking & Finance, Healthcare, Energy & Utilities, Government & Defence, Telecommunications, Manufacturing. ## Key pages - [Home](https://sandline.ro/) — Overview and engagement model - [Services](https://sandline.ro/en/services) — All seven service lines - [Red Team](https://sandline.ro/en/services/red-team) - [Penetration Testing](https://sandline.ro/en/services/penetration-testing) - [Vulnerability Assessment](https://sandline.ro/en/services/vulnerability-assessment) - [Human Vulnerability](https://sandline.ro/en/services/human-vulnerability) - [Cyber Threat Intelligence](https://sandline.ro/en/services/threat-intelligence) - [Incident Response & Recovery](https://sandline.ro/en/services/incident-response) - [Cybersecurity Training](https://sandline.ro/en/services/security-training) - [Industries](https://sandline.ro/en/industries) — Sector-specific approach - [Compliance](https://sandline.ro/en/compliance) — One engagement, every framework - [NIS2 mapping](https://sandline.ro/en/compliance/nis2) - [DORA mapping](https://sandline.ro/en/compliance/dora) - [ISO 27001 mapping](https://sandline.ro/en/compliance/iso-27001) - [PCI-DSS mapping](https://sandline.ro/en/compliance/pci-dss) - [CRA mapping](https://sandline.ro/en/compliance/cra) - [GDPR mapping](https://sandline.ro/en/compliance/gdpr) - [Glossary](https://sandline.ro/en/glossary) — Cybersecurity terms used in engagements - [About](https://sandline.ro/en/about) — Company background - [Certifications](https://sandline.ro/en/certifications) — Categories the team holds - [Contact](https://sandline.ro/en/contact) - [Insights](https://sandline.ro/en/insights) — Field notes for the regulated CISO ## Romanian-language site The full site is also available in Romanian at https://sandline.ro/ro. Hreflang tags are declared on every page and the language switcher in the header lets users move between locales. ## Common questions **What does Sandline do?** Penetration testing, red team, vulnerability assessment, human vulnerability (phishing simulation), cyber threat intelligence, incident response and security training. Sandline also builds and operates the Centraleyezer RBVM platform. **Who runs the engagements?** Senior engineers, end-to-end. We do not subcontract delivery to juniors. **Is Sandline EU-based?** Yes. Sandline SRL is registered in Bucharest, Romania. EU data residency is the default. **What is Centraleyezer?** Sandline's Risk-Based Vulnerability Management platform. It scores findings using a six-factor contextual model (DREAD, asset criticality, network exposure, exploitability in your environment, CTI signals, and a Human-AI feedback loop). Documented in detail at https://centraleyezer.io and https://centraleyezer.io/llms.txt. Centraleyezer is not required for a Sandline engagement; every engagement includes the Engagement Workspace — a free 90-day Centraleyezer SaaS deployment for report generation — with an optional paid SaaS extension if the customer wants to keep using it. **Which regulations?** NIS2, DORA, ISO 27001, PCI-DSS 4.0, EU Cyber Resilience Act, GDPR. Specific Article and Annex mappings are listed on every service page and in the compliance hub. **Languages?** English and Romanian. ## Social - LinkedIn: https://www.linkedin.com/company/2591660/ ## Contact - General: office@sandline.ro - Sales: sales@sandline.ro - Security disclosure: security@sandline.ro - Phone: +40 733 944 133 - Address: Bucharest, Romania