Our approach

No checklist ticket. No panic selling.

We are a small consultancy for a clear target group: small and medium-sized businesses in Germany. That means: one point of contact, recommendations you can trace — and recommendations a mid-market company can actually implement.

Principles

Four things we do not negotiate.

Everything else — scope, tools, rhythm — adapts to your company.

Traceable

Every recommendation comes with a reason, the risk, and the alternative. You always know why — and what it costs not to do it.

Pragmatic

Security for 200 employees looks different from security for a corporation. We build what fits your size — not the most expensive variant.

Provable

What we do has to hold up: to auditors, to customers — and in three years, when other people's decisions have to carry it. Documentation is not an extra.

One person, not many

One point of contact from the initial classification to the audit. No ping-pong between analyst, consultant and account manager.

How we work

Method without mystique.

Three decisions that shape how we work — regardless of which offering you book with us.

Recognised methods, no magic

The foundation is BSI IT-Grundschutz and ISO 27002. Nothing proprietary, no black box: auditors know the methods, and they will still be standard in three years.

Risk before volume

Prioritise first, build second. An ISMS with 400 unimplemented measures is not an ISMS — it is an Excel file.

Step by step, measurable

Every phase has a result you keep. Interim results are usable, not sales material.

FAQ

Short and honest.

Different question? Write to us
What does an ISMS project cost?

That depends on scope, sector and goal — a serious range only comes after the first analysis. What we can tell you now: before the contract you receive a fixed quote with a clear scope. No day-rate surprises.

How long does ISO 27001 certification take?

Realistically 4–8 months, depending on the starting point. The first risk assessment is in place after 4–6 weeks — that is most of the work done, and the project has already delivered value.

Do we need to plan internal capacity?

Yes, but in a predictable way: typically 10–20 % of a contact person from IT and management. We define who that is together, in advance.

Do you work remotely or on site?

Both. Analysis and implementation are mostly remote; we are happy to run workshops, training and audits in your office.

What if you find something we cannot fix?

Then we document the risk deliberately (risk acceptance), prioritise it, and you decide. No standstill, no drama — a management process with a documented decision.

Do you stay involved after the project?

If you want: an operating model with defined availability, a review rhythm and a fixed point of contact. But not because it has to be.

The first analysis is the best place to start.

30 minutes, no obligation, no sales show. Afterwards you know where you stand — and what it costs not to know.