Who We Are

Who stands behind OR Security?

Cybersecurity and data protection are not just technical services. They are mandates of trust.

Before an organisation decides who should protect its systems, sensitive data, compliance obligations, and reputation, one question naturally comes first:

Who are we willing to trust with this responsibility?

OR Security is a founder-led cybersecurity and data protection practice built on practical experience, senior judgement, discretion, and clear communication.

Trust Before Technology

Serious work starts with judgement, confidentiality, and responsibility.

When an organisation works with us, it is trusting us with confidential information, operational context, and decisions that can affect reputation, resilience, and continuity.

We treat that responsibility seriously.

OR Security was built for organisations that need senior cybersecurity and data protection support without inflated overhead or generic consulting language. Our aim is simple: focused expertise, practical recommendations, and fair pricing.

For the first years of the company, most of our work came through long-standing relationships and word of mouth. That remains the standard we try to live up to.

Founder

Founder: Örs Apor Horváth

OR Security was founded by Örs Apor Horváth, a cybersecurity and information security professional with 25+ years of experience and a deeply technical background.

His career began in 1996 in the hacker community. Over time, this evolved into ethical security work across red team, purple team, blue team, threat intelligence, social engineering, cloud security, vCISO leadership, and strategic information security advisory.

Today, Örs leads OR Security’s professional direction and standards, working with senior specialists across cybersecurity, technology, data protection, and offensive security.

His work focuses on helping organisations understand and reduce real-world cyber risk through practical technical insight, security awareness, responsible leadership, and long-term resilience.

Örs speaks four languages and works comfortably across international teams, cultures, and stakeholder groups.

Senior Expertise

Founder-led, supported by senior specialists.

OR Security is founder-led, but not founder-only.

Behind the work is a trusted senior circle of cybersecurity, data protection, technology, vCISO, red teaming, and offensive security professionals.

Together, this senior group brings more than 100 years of cumulative professional experience.

This allows OR Security to support clients from governance and compliance through to the technical reality of how systems are built, attacked, defended, audited, and improved.

Quiet Security

A career built on prevention, not noise

The systems and organisations represented under Örs’ responsibility have no known record of compromise or data breach.

We do not present this as a guarantee. Cybersecurity can never be reduced to slogans, and no serious professional promises absolute safety.

We present it as evidence of an approach built on preparation, realism, discipline, and continuous improvement.

Good security is often quiet. It prevents incidents before they become visible. It strengthens people before mistakes become breaches. It improves systems before attackers turn weaknesses into consequences.

What We Stand For

What shapes our work

OR Security exists to make serious cybersecurity and data protection more accessible to organisations that need experienced support, but do not need unnecessary complexity or enterprise-sized overhead.

Our work is shaped by practical security awareness, responsible handling of sensitive and health-related data, inclusive cybersecurity communities, and Free / Libre / Open Source values.

Security should not be theatre. It should reduce risk, support responsible decisions, and protect the people behind the data.

Experience That Matters

Experience that stands up to scrutiny

Technical security background

Hands-on experience across offensive, defensive, and purple-team security work.

vCISO and advisory work

Strategic information security support grounded in technical reality, not generic consulting language.

Grey hat / purple-team perspective

A practical understanding of how attackers think, how defenders operate, and where organisations are most exposed.

Certification and community experience

Experience leading teams through BSI certification and successful re-audits, plus six years as Hacktivity conference ambassador for Germany.

Next Step

Discuss the mandate and the right level of support.

If you are deciding who should be trusted with cybersecurity, data protection, or sensitive operational responsibility, we can start with a direct conversation about your risks, responsibilities, and the right level of support.

Discuss your mandate