We make IT security and compliance a natural part of your IT operations. From the CyberRiskCheck and ISMS implementation to AI-assisted operations - modular services with personal guidance from experienced consultants.
Regulatory requirements and customer expectations are putting increasing pressure on companies to take action. NIS-2 affects more than organizations that are directly regulated. Requirements are also increasing across the supply chain: customers are asking for evidence of security measures, structured questionnaires, and transparent processes for risk management, information security, and incident response.
The Cyber Resilience Act (CRA) introduces additional requirements for manufacturers of products with digital elements. Companies in mechanical and plant engineering in particular therefore need to determine which legal, standards-based, and customer-specific requirements apply to them.
Mid-sized companies in particular face the challenge of integrating these requirements into day-to-day IT operations with limited staff and organizational capacity.
The CyberRiskCheck and IT Compliance Assessment help you assess your current security posture and identify concrete areas for action. The right starting point depends on your situation: while the CyberRiskCheck provides a concise overview of your current security level, the IT Compliance Assessment focuses specifically on regulatory, standards-based, and customer-specific requirements.
The CyberRiskCheck in accordance with DIN SPEC 27076 is designed for small and medium-sized enterprises that want to assess their current IT security status in a structured way. A standardized process reviews relevant security areas and evaluates existing risks.
The result is a documented overview with prioritized recommendations for action. This shows which measures should be addressed first and where additional assessment or consulting may be required.
Duration: approx. half a day
The IT Compliance Assessment is designed for companies where regulatory requirements, audits, or requirements from customers and business partners are a key concern.
The assessment first determines which requirements are relevant to your company. These may include NIS-2 and the German BSIG, ISO 27001, BSI IT-Grundschutz, the Cyber Resilience Act, or the GDPR. The current status is then assessed and documented: Which requirements have already been implemented? Where are the gaps? What are the next steps?
The structured current-state documentation can serve as a basis for further measures, internal coordination, audits, or the completion of security and supply-chain questionnaires.
Duration: approx. 1-2 days, depending on the scope assessed
Security solutions, compliance processes, and an ISMS deliver the greatest value when information and processes are connected rather than managed in isolation. Our approach therefore links IT security, compliance, and IT operations more closely.
AI-assisted automation can handle defined tasks, consolidate information from existing systems, and support recurring processes. Decisions, approvals, and escalations remain transparent and are governed by defined rules.
Three target operating models show how a more connected IT security and compliance operation can evolve:
IT security events are continuously monitored, assessed, and prioritized. AI-assisted methods support analysis and response. Defined actions can be triggered automatically and documented.
The virtual CISO assistant supports CISOs, information security managers, and IT managers in systematically assessing risks, preparing decisions, and prioritizing security measures. Professional and organizational responsibility remains with people.
Information from security, GRC, and other IT systems is consolidated so that policies, measures, and evidence can be continuously maintained and documented in a traceable manner for audits.
AI can assess information, structure it, and prepare recommendations. Automated steps take place within defined approval and escalation rules. Audit trails and transparent processes ensure that decisions and completed actions remain documented.
An Information Security Management System (ISMS) based on ISO 27001 organizes information security as an ongoing interaction of rules, responsibilities, processes, and controls rather than as a collection of individual measures.
Among other things, an ISMS defines the scope, existing information security risks, how those risks are handled, applicable policies, and the documentation of measures and their effectiveness.
This creates a transparent foundation for systematically planning, implementing, monitoring, and continuously improving information security.
Three Stages of ISMS Implementation
Depending on the existing level of maturity, an ISMS can be built step by step. Our approach combines strategic assessment, technical analysis, and ongoing operation.
The individual services can build on one another. However, you can also start at a later stage if the relevant foundations are already in place.
The Compliance & Strategy Workshop turns existing findings on regulatory requirements, gaps, and maturity levels into concrete strategic decisions.
Together, we review target standards, the required level of protection, the ISMS scope, necessary resources, and the organizational framework. The result provides a foundation for further planning and management decisions.
Duration: approx. 6-hour foundation workshop plus approx. 2-hour strategy workshop
The Technical Deep Dive assesses the current technical state of your IT environment. It covers defined areas such as the system landscape, network, identities and permissions, vulnerabilities, cryptography, monitoring, and suppliers.
The analysis is based on relevant controls from ISO 27002:2022. The result identifies technical gaps, the current maturity level, and prioritized measures for further implementation.
Duration: approx. 1-2 days, depending on the infrastructure
The ISMS Bundle combines a Governance, Risk, and Compliance (GRC) platform with ongoing support from an experienced GRC consultant. The goal is not only to implement an ISMS, but also to maintain and continuously develop it as part of day-to-day operations.
The platform supports the structured management of policies, measures, and evidence. The GRC consultant supports users, provides guidance on specialist issues, and can take on tasks depending on the agreed scope of services.
Duration: ongoing support based on a monthly flat fee
The ISMS Bundle can also be used directly if a reliable compliance status, existing documentation, or other suitable foundations are already in place.
If the previous steps were completed together, the existing results can feed directly into the next phase. Policies, measures, and evidence can then be aligned more precisely with the company's actual starting point and, in some cases, prepared with AI assistance.
Not every company can or wants to fill the role of an information security officer internally on a permanent basis. In this case, an external information security officer can provide ongoing support in organizing and further developing information security.
Depending on the agreed scope, the external information security officer supports internal security processes, provides guidance on specialist and regulatory issues, and serves as a point of contact for management, business units, customers, and other stakeholders.
At a Glance
External Information Security Officer or ISMS Bundle?
The external information security officer provides ongoing support in a defined professional role. The ISMS Bundle focuses on establishing and continuously operating an Information Security Management System. The two services can be combined.
Companies today must address a range of legal, regulatory, standards-based, and industry-specific requirements. Which requirements actually apply depends on factors such as industry, company size, products, customer base, and supply chain structure.
We help you assess these requirements, identify overlaps, and translate them into concrete measures for information security, compliance, and IT operations.
Relevant topics include:
Information security does not end with concepts, assessments, and policies. When identified measures lead to concrete technical changes, additional ISO-Gruppe teams can support implementation and operations.
Managed Security Services take on defined tasks in the day-to-day operation of your security infrastructure - for example, configuring, monitoring, and troubleshooting selected security components.
Security Engineering & Integration supports the selection, implementation, and integration of security solutions into existing IT infrastructures. This includes both technical design and implementation, as well as the handover to your internal IT operations team.
Whether your company falls directly within the scope of NIS-2 depends on factors such as your industry, company size, and business activities. The BSI provides a dedicated applicability check for this purpose.
Additional security requirements can also arise through customers and supply chains, regardless of whether your company is directly subject to the legislation. If you want to determine which requirements actually apply to your company, we consider both your own situation and existing customer and supply-chain requirements.
That depends on what you need to clarify right now:
If you want a structured overview of your current IT security status and concrete areas for action in a short amount of time, the CyberRiskCheck in accordance with DIN SPEC 27076 is the right choice. It typically takes about half a day.
If regulatory requirements, audits, or specific customer requirements are your main focus, the IT Compliance Assessment is the appropriate starting point. Over approximately one to two days, we review the requirements relevant to your organization, document the current status, and identify existing gaps.
That depends on the service you choose and your starting point. Our entry-level services are deliberately designed to give you clarity with a manageable level of internal effort.
For example, the CyberRiskCheck takes about half a day, while the IT Compliance Assessment typically takes one to two days. For more extensive services, we agree in advance which people and information are required and what level of internal effort to expect.
The services are modular and can be used individually depending on your starting point.
For example, if you already have a documented compliance status, you do not need to begin with another baseline assessment. The ISMS Bundle can also be started without completing the previous stages. Together, we determine which starting point makes the most sense for your situation.
There is no single answer. The duration and effort depend on factors such as the scope, the existing security level, current processes, and available internal resources.
We therefore begin by clarifying your starting point and target state. The Compliance & Strategy Workshop defines the key parameters, while the Technical Deep Dive assesses the technical environment. Together, these activities provide the foundation for establishing an ISMS that can be operated and continuously improved over time. Automation and AI can support defined tasks and reduce manual effort.
Yes. The right solution depends on the skills and responsibilities already available within your organization.
With the ISMS Bundle, your organization remains responsible for its ISMS, while the platform and a Governance, Risk & Compliance (GRC) consultant support you in establishing and operating it. If you do not have a suitable internal information security role, you can use an external information security officer instead - or combine both services.
This makes it possible to organize information security in a structured way even if you do not want to establish a dedicated internal security function or need to relieve existing resources.
Do you want to assess the current state of your information security, establish an ISMS, or further develop existing security and compliance processes?
In an initial consultation, we review your starting point and determine which of the services described is the right next step for you.
In-Depth Information on NIS-2, IT Security, and Autonomous IT Operations