What we do
Most losses at crypto companies are not exotic. They are compromised credentials, poor key handling, an insider with too much access, a supplier with too much trust. Those are governance failures, and governance is what we do.
Where the regulation touches security
Two EU regimes put security squarely in scope for crypto businesses.
Crypto-asset service providers fall within DORA (Regulation (EU) 2022/2554), applicable across the EU since 17 January 2025, covering ICT risk management, incident reporting, resilience testing and third-party oversight.
MiCA (Regulation (EU) 2023/1114), applicable to crypto-asset service providers since 30 December 2024, connects to it directly. An authorisation application must describe the applicant’s ICT systems and security arrangements (Article 62(2)(j)), and a CASP’s governance must maintain resilient and secure ICT systems in line with DORA (Article 68).
Those technical and security sections are work we can do. The rest of MiCA is not ours. Authorisation strategy, white papers, licensing and the relationship with your national competent authority need a MiCA specialist or a law firm, and we expect to work alongside one rather than in place of one.
Commissioning an audit you can trust
We do not audit smart contracts. What we do is make sure the audit happens properly, which is a different job and one most companies buying their first audit have nobody to do:
We are familiar with the automated scanning tools in common use and where their limits lie. We also do not design cryptographic protocols or review consensus mechanisms — if that is your requirement, you need a cryptographer, and we will say so.
Our experience here
We are direct about this. Our depth is in security leadership, governance and compliance, applied to companies that happen to operate in blockchain. Alongside that practice, we have worked hands-on with a small blockchain payments project, running automated smart contract scanning and establishing its security policies and operating protocols from scratch.
If you need someone with a decade of protocol security behind them, that is not us, and we would rather tell you now. If you need the person who makes sure your company does not lose its keys to a phishing email, that is exactly us.
Questions we get asked
Book a free 30-minute consultation
Tell us what your company does, who is asking you for security assurances, and what worries you most. We will tell you whether we are the right people for it.
blockchain@metaluxo.com