Security architecture. From design to deployment.

Security architecture built to survive audit.

We design and deliver security architecture for governments, defence organisations, and critical infrastructure operators in Albania and the Western Balkans — combining independent architecture expertise with validated technology solutions. Architecture decisions are made on technical merit — and where required, we supply and deploy the technology to realise them.

  • Aligned with
  • ISO/IEC 27001
  • NIST CSF 2.0
  • NIS2
  • GDPR Art. 32
  • DORA
  • eIDAS 2

Advisory Services

Four service lines for regulated organisations

Each engagement produces auditable deliverables aligned to recognised frameworks. Architecture, compliance, and technology supply are available as integrated or standalone engagements.

Security Architecture & Design

Architecture for Zero Trust, Data-Centric Security, and segmented or high-assurance environments. Designs are documented to support independent review and audit.

Deliverables

  • Target architecture document (logical and physical views)
  • Control mapping to ISO 27001 Annex A, NIST CSF 2.0, NIS2
  • Trust boundaries, identity flows, and policy decision points
  • Migration roadmap with risk-prioritised sequencing
  • Architecture decision records (ADRs) for traceability

Risk & Compliance Advisory

Structured readiness work for ISO/IEC 27001, GDPR, NIS2, and sector-specific obligations. Outputs are designed for board reporting and regulator dialogue.

Deliverables

  • ISO 27001 gap assessment and certification roadmap
  • Risk register aligned to ISO 31000 / ISO 27005
  • GDPR Article 32 technical and organisational measures
  • NIS2 applicability and obligation mapping
  • Executive and board-level reporting templates

Security Assessments

Architecture reviews, control assessments, and exposure analysis. Findings are prioritised by risk to the organisation, not severity in isolation.

Deliverables

  • Architecture review report with documented findings
  • Control effectiveness assessment
  • Attack surface and trust boundary analysis
  • Prioritised remediation plan with owners and dependencies
  • Re-assessment after remediation (optional)

Secure Infrastructure Design

Network, identity, and platform design where security is part of the architecture, not retrofitted afterwards. Vendor-neutral, evidence-based selection.

Deliverables

  • Segmentation and macro/micro-segmentation design
  • Identity and access architecture (incl. PAM, IGA)
  • Cloud and hybrid landing zone reference architecture
  • Backup, recovery, and resilience design (RTO/RPO)
  • Procurement-ready technical requirements

Methodology

A consistent, auditable engagement structure

Every engagement follows the same four phases. Each phase produces documented outputs that can be reviewed independently and traced through to design decisions.

Phase 01

Discover

Current-state analysis, stakeholder interviews, document review, and regulatory mapping.

Phase 02

Analyse

Gap analysis, risk assessment, control effectiveness review against the target framework.

Phase 03

Design

Target architecture, control mapping, prioritised remediation, and migration sequencing.

Phase 04

Validate

Architecture decision records, audit-ready documentation, board-level summary, and handover.

Frameworks & Standards

Aligned with internationally recognised standards

Deliverables are mapped to the standards that your auditors, regulators, and internal stakeholders already use.

ISO/IEC 27001:2022

Gap analysis against the 93 Annex A controls, ISMS scoping, Statement of Applicability, certification readiness.

NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, Recover — function-by-function maturity baselining and roadmap.

NIS2 Directive

Applicability assessment, governance obligations, incident reporting, and Article 21 risk-management measures — aligned with EU accession requirements.

GDPR Article 32

Technical and organisational measures appropriate to the risk, including pseudonymisation, encryption, and resilience.

Credentials

Certified, independent, and grounded in practice

Industry certifications validate methodology and continued professional development. Project work — not certifications alone — establishes capability.

CISSP

(ISC)² Certified Information Systems Security Professional

CCSP

(ISC)² Certified Cloud Security Professional

CEH

EC-Council Certified Ethical Hacker

ISO/IEC 27001

Lead Implementer / Lead Auditor methodology

Engagement Models

How engagements are structured

Fixed scope, fixed deliverables, predictable timelines. Every engagement begins with a written proposal — scope, deliverables, and timeline — before any work commences.

Technology Ecosystem

Vendor-neutral, evidence-based selection

Technology selection is based on fit to the control objective, sovereignty requirements, and lifecycle cost. Pentaquark supplies hardware and software solutions from the vendors below as part of integrated architecture engagements.

Network Security

Palo Alto Networks
Fortinet
Check Point
Cisco
Juniper Networks

Identity & Access

Microsoft
Entrust
Yubico
Ivanti

Detection & Exposure Management

Trellix
Tenable
Rapid7
Fidelis Security
Bitdefender

Secure Infrastructure & Resilience

Red Hat
SUSE
HPE
Dell
Acronis
Arcserve

Contact

Request a scoping conversation

Introductions are typically a 30-minute call to confirm fit. Engagements begin with a written scope, deliverables, and timeline before any work commences.

Office
Pentaquark SHPK
Tunjë, 3307 Gramsh
Albania
NUIS
L61311062D
Email
contact@5q.al
Telephone
+355 68 203 0321