Security that moves the mid-market forward.

We build measurable, provable security structures for small and medium-sized businesses — from ISMS to NIS2 to the cloud. Predictable on budget, clear in the boardroom, solid in the audit.

Remote across the EU Replies < 24 h on weekdays

Illustrative — distilled from typical starting points.

ISO 27001 NIS2 / NIS2UmsuCG TISAX KRITIS BSI IT-Grundschutz CIS Benchmarks

01 — Services

Three things. Good craft.

All services in detail

No catalogue of forty offerings. We do what companies actually need to move now: structure, obligations, cloud.

A6–10 weeks to start

ISMS & ISO 27001

An information security management system that fits your size — and ends in certification, not in the filing cabinet.

  • Risk assessment using recognised methods
  • Policies & principles in the right measure
  • Technical & organisational measures, prioritised
  • Audit preparation & audit support
Typically 4–8 months to certification More
B2–4 weeks to classification

Compliance: NIS2 · KRITIS · TISAX

We determine what applies to you — and make you audit-ready before your customers or the regulator ask.

  • Classification & obligations analysis
  • Reporting & documentation processes
  • Supply-chain & customer requirements
  • TISAX support for automotive
Audit-ready from a single source More
C4–8 weeks baseline

Cloud & DevSecOps

A secure cloud, a clean pipeline — without slowing down the delivery teams that drive your revenue.

  • Cloud hardening to CIS Benchmarks
  • Identity, Access & Secrets
  • CI/CD: scanning, signing, policy
  • A monitoring baseline for the mid-market
Security in the pipeline, not on a post-it More

02 — Context

The obligation is coming faster than you think.

Find out what applies to you

Since the start of 2025 the NIS2 implementation act has been in force — and it brings more companies into scope than most realise.

Fact 01

NIS2 is in force

The implementation act has applied since January 2025. The first question — are we affected at all? — is half the work. The most common mistake: not checking at all.

Fact 02

The supply chain decides with you

Your customers increasingly ask about security: TISAX certificates, NIS2 questionnaires, ISO references. Without evidence you risk losing the contract — regardless of what the regulation requires of you.

Fact 03

Attackers prioritise SMEs

Small and medium-sized businesses are seen as soft targets — and increasingly are. Tidy security is therefore not just risk reduction here, but the fastest differentiating advantage in sales.

03 — Process

Four steps. One point of contact.

More about our approach

Every phase has a result you keep — even if the engagement ends afterwards.

01

Current state

We listen and look: systems landscape, processes, legal classification. Usually two weeks, remote or on site. Afterwards both sides know where you stand.

02

Risk assessment

A prioritised list instead of a threat slideshow: what is risky, why — and what we do first. Traceable for management, team and customers.

03

Implementation

We build with you, not just for you: policies, technical measures, training. In sprints that fit daily work — with clear milestones.

04

Evidence & operation

Certification or audit support — and an operating model that keeps security part of the day-to-day, without us becoming the bottleneck.

Typical time to a finished risk assessment: 4–6 weeks.

04 — Work

What is left when the project is over.

All case examples

We only give names when it is explicitly okay. So anonymised — but with real results.

We did not even know what NIS2 meant for us. Now we have a classification, a system — and the audit under control.

Managing director · Engineering, 120 employees

For the first time someone explains security in a way the boardroom understands — and the team actually implements.

CTO · Logistics, 300 employees

Let's talk about your security position.

30 minutes, no obligation. You leave with an honest assessment — whether we work together afterwards is your decision.