We build measurable, provable security structures for small and medium-sized businesses — from ISMS to NIS2 to the cloud. Predictable on budget, clear in the boardroom, solid in the audit.
Since the start of 2025 the NIS2 implementation act has been in force — and it brings more companies into scope than most realise.
Fact 01
NIS2 is in force
The implementation act has applied since January 2025. The first question — are we affected at all? — is half the work. The most common mistake: not checking at all.
Fact 02
The supply chain decides with you
Your customers increasingly ask about security: TISAX certificates, NIS2 questionnaires, ISO references. Without evidence you risk losing the contract — regardless of what the regulation requires of you.
Fact 03
Attackers prioritise SMEs
Small and medium-sized businesses are seen as soft targets — and increasingly are. Tidy security is therefore not just risk reduction here, but the fastest differentiating advantage in sales.
Every phase has a result you keep — even if the engagement ends afterwards.
01
Current state
We listen and look: systems landscape, processes, legal classification. Usually two weeks, remote or on site. Afterwards both sides know where you stand.
02
Risk assessment
A prioritised list instead of a threat slideshow: what is risky, why — and what we do first. Traceable for management, team and customers.
03
Implementation
We build with you, not just for you: policies, technical measures, training. In sprints that fit daily work — with clear milestones.
04
Evidence & operation
Certification or audit support — and an operating model that keeps security part of the day-to-day, without us becoming the bottleneck.
Typical time to a finished risk assessment: 4–6 weeks.