Services
Three offerings. One standard: provable.
No catalogue. Three offerings that overlap when you need them — and work cleanly together when we implement all three for you.
ISMS & ISO 27001
An ISMS is not a pile of mandatory documents. It is the decision about how your company handles information — assessed, documented, alive. We build it to fit your size and to carry the certification.
What we do
- Gap analysis & current-state assessment of the systems landscape
- Risk assessment per ISO 27005 / BSI IT-Grundschutz
- Protection objectives & treatment options per risk
- Principles, policies & procedures
- Technical & organisational measures, prioritised
- Documentation in the right measure — no more
- Preparation & support for the audits (stage 1 & 2)
- Security awareness programme for the team
Compliance: NIS2 · KRITIS · TISAX
Regulation is becoming a customer requirement. We translate it: what applies to us? what must we report? what must we be able to do? — and turn it into processes that hold up without a dedicated security team.
What we do
- NIS2: classification — annex, size, sector
- Obligations & reporting catalogue incl. the 24/72/72-hour rules
- Documentation & governance model
- KRITIS: sectoral classification & regulatory obligations
- TISAX: gap analysis per VS-ITS (Level 2 / 3)
- Accompaniment through the assessment body
- Supply chain: NIS2 annex & TISAX evidence for customers
- Customer questionnaires answered from a single source
Cloud & DevSecOps
Your applications grow faster than your security processes. We close the gap between speed and security — without slowing down the teams that deliver your revenue.
What we do
- Cloud hardening (AWS, Azure, GCP) to CIS Benchmarks
- Identity & Access: MFA, permissions model, roles
- Secrets & key management
- CI/CD: dependency & container scanning
- Signed builds & Policy-as-Code
- IaC reviews: Terraform, Pulumi, CloudFormation
- Monitoring & alerting baseline — what a mid-market company really needs
- Secure by design: architecture reviews & patterns
Not sure where to start?
Then we start with the question that orders everything else: what applies to you — and what is risky? 30 minutes, no obligation.