Our approach
No checklist ticket. No panic selling.
We are a small consultancy for a clear target group: small and medium-sized businesses in Germany. That means: one point of contact, recommendations you can trace — and recommendations a mid-market company can actually implement.
Principles
Four things we do not negotiate.
Everything else — scope, tools, rhythm — adapts to your company.
Traceable
Every recommendation comes with a reason, the risk, and the alternative. You always know why — and what it costs not to do it.
Pragmatic
Security for 200 employees looks different from security for a corporation. We build what fits your size — not the most expensive variant.
Provable
What we do has to hold up: to auditors, to customers — and in three years, when other people's decisions have to carry it. Documentation is not an extra.
One person, not many
One point of contact from the initial classification to the audit. No ping-pong between analyst, consultant and account manager.
How we work
Method without mystique.
Three decisions that shape how we work — regardless of which offering you book with us.
Recognised methods, no magic
The foundation is BSI IT-Grundschutz and ISO 27002. Nothing proprietary, no black box: auditors know the methods, and they will still be standard in three years.
Risk before volume
Prioritise first, build second. An ISMS with 400 unimplemented measures is not an ISMS — it is an Excel file.
Step by step, measurable
Every phase has a result you keep. Interim results are usable, not sales material.
FAQ
Short and honest.
What does an ISMS project cost?
That depends on scope, sector and goal — a serious range only comes after the first analysis. What we can tell you now: before the contract you receive a fixed quote with a clear scope. No day-rate surprises.
How long does ISO 27001 certification take?
Realistically 4–8 months, depending on the starting point. The first risk assessment is in place after 4–6 weeks — that is most of the work done, and the project has already delivered value.
Do we need to plan internal capacity?
Yes, but in a predictable way: typically 10–20 % of a contact person from IT and management. We define who that is together, in advance.
Do you work remotely or on site?
Both. Analysis and implementation are mostly remote; we are happy to run workshops, training and audits in your office.
What if you find something we cannot fix?
Then we document the risk deliberately (risk acceptance), prioritise it, and you decide. No standstill, no drama — a management process with a documented decision.
Do you stay involved after the project?
If you want: an operating model with defined availability, a review rhythm and a fixed point of contact. But not because it has to be.
The first analysis is the best place to start.
30 minutes, no obligation, no sales show. Afterwards you know where you stand — and what it costs not to know.