From analysis to operation
Your business deserves security that does not stop at paper. We build your ISMS, guide you to certification and operate it day to day, so that compliance does not remain a project but becomes the normal state.
Managed Services
External ISO as a Service
Your certified information security officer, without recruiting, without onboarding, ready to act from day one. Full responsibility, no permanent employment.
- Direct reporting line to management
- Create, maintain & enforce policies
- Immediate coordination during security incidents
- Quarterly reviews with measurable KPIs
Security Awareness Training
93% of all security incidents begin with people. We turn your workforce from a risk factor into your first line of defence.
- Realistic phishing campaigns with evaluation
- Live workshops: recognising social engineering
- Flexible e-learning modules for every level
- Audit-compliant records & participation certificates
Design & Implementation
ISMS Implementation ISO 27001
From a blank page to a passed certification. We build your ISMS so that it passes the audit and works in everyday operations.
- Scope definition & complete asset inventory
- Annex A controls implemented precisely
- Internal audits that find weaknesses before the auditor
- Support all the way to the certificate, without a re-audit
IT-Grundschutz (BSI)
The BSI methodology implemented consistently, whether for public authorities under obligation or businesses with high standards. No module is left open.
- Structural analysis with clear protection requirements per asset
- Module modelling from the BSI compendium
- Basic & standard protection implemented without gaps
- Certification-ready on the first attempt
Incident Response & BCM
When the worst happens, every minute counts. We make sure your team knows what to do before it happens.
- Ready-to-use playbooks for every type of incident
- Business Impact Analysis of critical processes
- Recovery plans with defined RTOs & RPOs
- Regular crisis exercises under real conditions
Compliance & Regulation
NIS2 Compliance
NIS2 affects more companies than expected. We clarify whether you are affected and bring you into compliance before the deadline expires.
- Applicability check with a clear yes/no answer
- Art. 21 measures prioritised & planned to be actionable
- Reporting processes established, 24h/72h deadlines secured
- Supply chain risks identified & documented
DORA Compliance
BaFin-compliant IT resilience for financial firms and their ICT service providers. We deliver the framework, you pass the review.
- ICT risk management to DORA requirements
- Incident reporting chain including reporting templates
- TLPT test scenarios for digital operational resilience
- Third-party register with risk classification
GDPR Interface
Information security and data protection must not be silos. We interlink both disciplines into a single framework, with no duplicated work.
- TOMs under Art. 32, robust & audit-proof
- ISO/DPO alignment with no gaps in responsibility
- DPIA for high-risk processing activities
- Records of processing current, complete & audit-ready
Analysis & Assessment
Gap Analysis & Maturity
You know where you want to go. We show you where you stand, with a prioritised roadmap instead of an endless list of deficiencies.
- Systematic as-is assessment in under 2 weeks
- Benchmarking against ISO 27001 & BSI IT-Grundschutz
- Roadmap prioritised by risk & effort
- Management summary for the executive team
Risk Analysis & Management
You cannot manage the risks you do not know. We quantify threats to ISO 27005 so that you can decide on a sound basis.
- Complete asset & threat map
- Clear treatment options per risk
- Living risk register with tracking
- Seamless integration into your ISMS
Audit & Certification
No surprises in the audit. We prepare you so that the external auditor confirms what we already know.
- Mock audits under real examination conditions
- Documentation complete & verifiable
- On-site support on the audit day
- Findings tracked through to closure
Answers on information security
NIS2 affects companies with 50 or more employees or EUR 10 million in turnover across 18 sectors, as well as smaller businesses classified as critical. In the free initial assessment we clarify whether you are affected and what specific action is required.
Depending on the starting point, typically four to nine months: from the gap analysis through the ISMS implementation to the external certification audit. We accompany every step through to the closure of the findings.
You get an experienced information security officer as a managed service, without having to create your own full-time position. They steer your ISMS, prepare audits and maintain ongoing compliance.
The cost depends on company size, scope and existing documentation. After a free initial assessment you receive a fixed quote rather than a flat rate.
ISO 27001 is internationally recognised and risk-based, while BSI IT-Grundschutz is measure-oriented and common in the German public sector. Internationally active companies are usually better served by ISO 27001, while the public sector often calls for BSI IT-Grundschutz. The two can be combined.
The GDPR protects personal data, while NIS2 governs the cybersecurity of important and critical entities. NIS2 requires technical and organisational measures as well as reporting obligations, regardless of whether personal data is involved. Many companies must meet both.
An internal information security officer knows the company in detail but creates fixed costs and cover risks. An external ISO as a Service brings immediate experience from many projects, stays independent and scales with demand. For mid-sized companies, the external model is usually more economical.
TISAX is based on ISO 27001 but is the mandatory assessment standard of the automotive industry. Anyone supplying OEMs or suppliers generally needs TISAX; an existing ISMS to ISO 27001 is the ideal foundation and shortens the path considerably.
Not sure where you stand?
The free initial assessment shows you, in a single conversation, whether you are affected, what action you need to take and the next sensible step.
Request initial assessment