Sustainability
Last updated: January 16, 2026
Our Approach
Cybora is a remote-first, digital-native business. No physical offices, no server rooms, no unnecessary overhead. That's partly practical, partly intentional. This page is a straightforward account of how we think about environmental, social, and governance responsibilities as a small but growing cybersecurity company.
Environmental
Our team works remotely across Lithuania and the EU. No daily commutes, no office building running electricity and heating around the clock. The tools we use live in the cloud, and we pick providers who take their own environmental impact seriously.
When client work requires travel, we default to rail and try to keep trips short and purposeful. We don't manufacture hardware or run our own data centres. The physical footprint of this business is basically the laptops our team members use, and we manage those through proper device lifecycle and endpoint security practices.
Social
The core of what we do has a social angle that's easy to overlook. Enterprise-grade cybersecurity has historically been something only large organisations could afford. We're trying to change that for SMEs and smaller organisations that carry real risk but don't have the budget or in-house expertise to deal with it properly. A less secure business environment hurts everyone in the chain: employees, customers, suppliers.
We also put effort into growing cybersecurity knowledge locally in Lithuania, through knowledge-sharing and awareness work. Our security awareness training is built to create real, lasting security habits inside client organisations. Not just a certificate at the end of a compliance exercise.
We're committed to fair employment, equal opportunity, and building a working environment where people can do good work without unnecessary friction.
Governance
We're a cybersecurity company. If we weren't transparent and accountable in how we operate, we'd have no business telling clients to be. We hold ourselves to the same standards we recommend: clear ownership, documented processes, honest communication when something goes wrong.
We're registered in the Republic of Lithuania and comply with applicable EU law, including GDPR. Our internal practices follow the principles of ISO/IEC 27001, and we apply the same risk-based thinking to our own operations that we apply to client work.
On data: we don't collect what we don't need, we don't keep it longer than necessary, and we don't share it without a lawful reason. That's not a policy statement, it's just how we operate.
Continuous Improvement
We're not going to claim we have all of this figured out. As the company grows, our responsibilities grow with it, and we'll revisit and update our practices accordingly. Anything material will show up as an update to this page.
Contact
Questions about any of this? Reach us at:
- Email: support@cybora.tech
- Post: CYBORA, UAB, Mikėno g. 15-1, LT-30245 Rokiškis, Lithuania