CYBER-
SECURITY.

How far does someone get who is in once?

Attackers do not look for the biggest, but for the most reachable, and that is often the Mittelstand: grown IT, few hands, long supply chains. Add obligations such as NIS2 and insurers who want to see evidence. We bring security to a level that stands up to auditors and does not paralyse operations, and so create the basis on which cloud and AI become defensible in the first place.

A small factory with a solid fence, a watchtower with a searchlight and a robot guard dog

Where we start.

Security is not a product you buy, but an order you keep to. We start where the biggest damage is most likely.

A person holds a map with marked spots and a shield

Overview & obligations.

Which systems are critical, where are the gaps, what do NIS2, insurers and customers demand? At the end there is a priority list, not a hundred-page risk analysis.

A castle with several inner walls, every gate with a lock

Architecture & hardening.

Multi-factor login, clean permissions, separated networks, verified backups. Whoever gets a door open is not standing in the whole house right away.

A robot night watchman with a lantern walks past server racks

Operation & response.

Monitoring that reports anomalies, an emergency plan that has been rehearsed, and contacts who know what to do when it matters, on a Sunday too.

One door is enough, if everything behind it is open.

Most attacks start trivially: a phishing email, an old password, a server without updates. What matters is how far the attacker gets afterwards. Switch protection layers on and off, and see where the attack gets stuck.

The order is no accident: Multi-factor login and backups stop the majority of real incidents, long before expensive technology becomes necessary.

attack path · phishing mailrunning…

How we proceed.

01

A person shines a torch into a dark server room

At the end you haveThe priority list: what first, what next, what can wait, with effort and obligation per item.

Assess the situation.

Inventory, access, backups, dependencies on service providers, and a view from outside, as an attacker would have it. That becomes an honest priority list, not a fear presentation.

02

Workers build a wall of blocks with padlocks around a server

At the end standsThe basis: multi-factor login, verified backups, separated networks, tidy permissions, documented.

Secure.

The measures in the order of their effect, together with your IT, in stages that do not disrupt operations. Every measure is verified, not just set up.

03

A robot with binoculars on a watchtower above a small factory at night

At the end there runsMonitoring with clear alarms, a rehearsed emergency plan and evidence that auditors and insurers accept.

Stay alert.

Monitoring, regular rehearsals of the emergency, updates under control, and reports that management, auditors and insurers understand. On request we take over operations.

Pragmatic instead of panic.

A solid front door with a good lock, a person holds the key

Basics first, then fine-tuning.

The most expensive technology does not help if the admin password has been the same for years. We first close the doors attackers really come through, and only then do we talk about finer points.

A folder with a shield stamp is handed to an auditor

Evidence for auditors and insurers.

NIS2, customer audits, cyber insurance: whoever can prove what they do saves time and premium. We document so that the evidence is already there at the next audit.

Where would an attacker start at your company?

The situation assessment answers exactly that, without a fear presentation.

FAQ.

We are too small to be interesting, aren't we?

Attacks run automatically today: programs look for open doors, not for big names. Whoever is reachable gets hit. A solid baseline makes you uninteresting for the mass of attacks, and that is exactly the goal.

Does NIS2 affect us?

Many mid-sized companies directly, many more indirectly via their customers, who demand evidence from suppliers. We clarify in the situation assessment what applies to you, and build the evidence so that it arises on the side, not as a separate project.

What do we do in an emergency?

Follow a plan that was rehearsed beforehand: who decides, who disconnects systems, who informs customers and authorities, where the backups are. We create this plan with you, and rehearse it before it is needed.

Do we need our own security team?

Usually not. The basis can be built with your IT; monitoring and response around the clock we or a partner take over as an operations service. What matters is that someone is watching, not where they sit.

How does this fit with AI and cloud?

AI and cloud are only as secure as the access, data and rules beneath them. Whoever lets agents loose on ERP and CRM needs clean permissions and logs, exactly the basis we build here. Security is the prerequisite, not the brake.