IT Security

Information Security That Keeps IT Operations Moving.

We make IT security and compliance a natural part of your IT operations. From the CyberRiskCheck and ISMS implementation to AI-assisted operations - modular services with personal guidance from experienced consultants.

Digital shield with a lock in front of a bright IT infrastructure representing information security.

NIS-2, CRA, and the Supply Chain: Growing Requirements for Information Security and Compliance

Regulatory requirements and customer expectations are putting increasing pressure on companies to take action. NIS-2 affects more than organizations that are directly regulated. Requirements are also increasing across the supply chain: customers are asking for evidence of security measures, structured questionnaires, and transparent processes for risk management, information security, and incident response.

The Cyber Resilience Act (CRA) introduces additional requirements for manufacturers of products with digital elements. Companies in mechanical and plant engineering in particular therefore need to determine which legal, standards-based, and customer-specific requirements apply to them.

Mid-sized companies in particular face the challenge of integrating these requirements into day-to-day IT operations with limited staff and organizational capacity.

A Structured Starting Point for Information Security

The CyberRiskCheck and IT Compliance Assessment help you assess your current security posture and identify concrete areas for action. The right starting point depends on your situation: while the CyberRiskCheck provides a concise overview of your current security level, the IT Compliance Assessment focuses specifically on regulatory, standards-based, and customer-specific requirements.

CyberRiskCheck

The CyberRiskCheck in accordance with DIN SPEC 27076 is designed for small and medium-sized enterprises that want to assess their current IT security status in a structured way. A standardized process reviews relevant security areas and evaluates existing risks.

The result is a documented overview with prioritized recommendations for action. This shows which measures should be addressed first and where additional assessment or consulting may be required.

Duration: approx. half a day

IT Compliance Assessment

The IT Compliance Assessment is designed for companies where regulatory requirements, audits, or requirements from customers and business partners are a key concern.

The assessment first determines which requirements are relevant to your company. These may include NIS-2 and the German BSIG, ISO 27001, BSI IT-Grundschutz, the Cyber Resilience Act, or the GDPR. The current status is then assessed and documented: Which requirements have already been implemented? Where are the gaps? What are the next steps?

The structured current-state documentation can serve as a basis for further measures, internal coordination, audits, or the completion of security and supply-chain questionnaires.

Duration: approx. 1-2 days, depending on the scope assessed

Autonomous IT Operations: Connecting Security, Compliance, and Automation

Security solutions, compliance processes, and an ISMS deliver the greatest value when information and processes are connected rather than managed in isolation. Our approach therefore links IT security, compliance, and IT operations more closely.

AI-assisted automation can handle defined tasks, consolidate information from existing systems, and support recurring processes. Decisions, approvals, and escalations remain transparent and are governed by defined rules.

Three target operating models show how a more connected IT security and compliance operation can evolve:

Digital security dashboard with monitoring and analytics views for continuous observation of security events.
Autonomer SOC

IT security events are continuously monitored, assessed, and prioritized. AI-assisted methods support analysis and response. Defined actions can be triggered automatically and documented.

Digital interface with connected functions for analysis, security management and decision support.
Virtual CISO Assistant

The virtual CISO assistant supports CISOs, information security managers, and IT managers in systematically assessing risks, preparing decisions, and prioritizing security measures. Professional and organizational responsibility remains with people.

Digital compliance dashboard showing the status of risks, measures, evidence and the audit trail.
Compliance at the Push of a Button

Information from security, GRC, and other IT systems is consolidated so that policies, measures, and evidence can be continuously maintained and documented in a traceable manner for audits.

Controlled AI Automation

AI can assess information, structure it, and prepare recommendations. Automated steps take place within defined approval and escalation rules. Audit trails and transparent processes ensure that decisions and completed actions remain documented.

Autonomous IT Operations: The Approach in Detail

ISMS Based on ISO 27001: Organizing Information Security Systematically

An Information Security Management System (ISMS) based on ISO 27001 organizes information security as an ongoing interaction of rules, responsibilities, processes, and controls rather than as a collection of individual measures.

Among other things, an ISMS defines the scope, existing information security risks, how those risks are handled, applicable policies, and the documentation of measures and their effectiveness.

This creates a transparent foundation for systematically planning, implementing, monitoring, and continuously improving information security.
Three Stages of ISMS Implementation

Three Steps to an ISMS

Depending on the existing level of maturity, an ISMS can be built step by step. Our approach combines strategic assessment, technical analysis, and ongoing operation.

The individual services can build on one another. However, you can also start at a later stage if the relevant foundations are already in place.

Person working on a laptop representing the analysis, documentation and management of IT security tasks.
Stage 1
Compliance & Strategy Workshop

The Compliance & Strategy Workshop turns existing findings on regulatory requirements, gaps, and maturity levels into concrete strategic decisions.

Together, we review target standards, the required level of protection, the ISMS scope, necessary resources, and the organizational framework. The result provides a foundation for further planning and management decisions.

Duration: approx. 6-hour foundation workshop plus approx. 2-hour strategy workshop

Bright futuristic corridor as an abstract representation of modern and scalable IT architectures.
Stage 2
Technical Deep Dive

The Technical Deep Dive assesses the current technical state of your IT environment. It covers defined areas such as the system landscape, network, identities and permissions, vulnerabilities, cryptography, monitoring, and suppliers.

The analysis is based on relevant controls from ISO 27002:2022. The result identifies technical gaps, the current maturity level, and prioritized measures for further implementation.

Duration: approx. 1-2 days, depending on the infrastructure

White modular elements with symbols representing IT security, compliance and automation.
Stage 3
ISMS Bundle

The ISMS Bundle combines a Governance, Risk, and Compliance (GRC) platform with ongoing support from an experienced GRC consultant. The goal is not only to implement an ISMS, but also to maintain and continuously develop it as part of day-to-day operations.

The platform supports the structured management of policies, measures, and evidence. The GRC consultant supports users, provides guidance on specialist issues, and can take on tasks depending on the agreed scope of services.

Duration: ongoing support based on a monthly flat fee

ISMS Bundle Available Without Prior Stages

The ISMS Bundle can also be used directly if a reliable compliance status, existing documentation, or other suitable foundations are already in place.

If the previous steps were completed together, the existing results can feed directly into the next phase. Policies, measures, and evidence can then be aligned more precisely with the company's actual starting point and, in some cases, prepared with AI assistance.

External Information Security Officer

Not every company can or wants to fill the role of an information security officer internally on a permanent basis. In this case, an external information security officer can provide ongoing support in organizing and further developing information security.

Depending on the agreed scope, the external information security officer supports internal security processes, provides guidance on specialist and regulatory issues, and serves as a point of contact for management, business units, customers, and other stakeholders.

At a Glance

  • Hourly service package or monthly flat fee
  • Ongoing professional support
  • Organizational, regulatory, and information security topics

External Information Security Officer or ISMS Bundle?

The external information security officer provides ongoing support in a defined professional role. The ISMS Bundle focuses on establishing and continuously operating an Information Security Management System. The two services can be combined.

IT security consultant discussing information security, compliance and security measures with a company team.

Regulations, Standards, and Frameworks: Assessing and Implementing Requirements.

Companies today must address a range of legal, regulatory, standards-based, and industry-specific requirements. Which requirements actually apply depends on factors such as industry, company size, products, customer base, and supply chain structure.

We help you assess these requirements, identify overlaps, and translate them into concrete measures for information security, compliance, and IT operations.
 

Relevant topics include:

NIS‑2 / BSIG
ISO 27001
BSI IT‑Grundschutz
Cyber Resilience Act
TISAX
EU AI Act
GDPR
DORA

From Consulting to Technical Implementation

Information security does not end with concepts, assessments, and policies. When identified measures lead to concrete technical changes, additional ISO-Gruppe teams can support implementation and operations.

Bright data center with server racks representing professionally managed IT infrastructure and managed services.
Managed Security Services

Managed Security Services take on defined tasks in the day-to-day operation of your security infrastructure - for example, configuring, monitoring, and troubleshooting selected security components.

Connected servers, systems and endpoints in a modern IT environment representing integrated security solutions.
Security Engineering & Integration

Security Engineering & Integration supports the selection, implementation, and integration of security solutions into existing IT infrastructures. This includes both technical design and implementation, as well as the handover to your internal IT operations team.

Technical Implementation and Operations with ISO-Gruppe

Frequently Asked Questions About IT Security, ISMS, and Compliance

Whether your company falls directly within the scope of NIS-2 depends on factors such as your industry, company size, and business activities. The BSI provides a dedicated applicability check for this purpose.

Additional security requirements can also arise through customers and supply chains, regardless of whether your company is directly subject to the legislation. If you want to determine which requirements actually apply to your company, we consider both your own situation and existing customer and supply-chain requirements.

That depends on what you need to clarify right now:

If you want a structured overview of your current IT security status and concrete areas for action in a short amount of time, the CyberRiskCheck in accordance with DIN SPEC 27076 is the right choice. It typically takes about half a day.

If regulatory requirements, audits, or specific customer requirements are your main focus, the IT Compliance Assessment is the appropriate starting point. Over approximately one to two days, we review the requirements relevant to your organization, document the current status, and identify existing gaps.

That depends on the service you choose and your starting point. Our entry-level services are deliberately designed to give you clarity with a manageable level of internal effort.

For example, the CyberRiskCheck takes about half a day, while the IT Compliance Assessment typically takes one to two days. For more extensive services, we agree in advance which people and information are required and what level of internal effort to expect.

The services are modular and can be used individually depending on your starting point.

For example, if you already have a documented compliance status, you do not need to begin with another baseline assessment. The ISMS Bundle can also be started without completing the previous stages. Together, we determine which starting point makes the most sense for your situation.

There is no single answer. The duration and effort depend on factors such as the scope, the existing security level, current processes, and available internal resources.

We therefore begin by clarifying your starting point and target state. The Compliance & Strategy Workshop defines the key parameters, while the Technical Deep Dive assesses the technical environment. Together, these activities provide the foundation for establishing an ISMS that can be operated and continuously improved over time. Automation and AI can support defined tasks and reduce manual effort.

Yes. The right solution depends on the skills and responsibilities already available within your organization.

With the ISMS Bundle, your organization remains responsible for its ISMS, while the platform and a Governance, Risk & Compliance (GRC) consultant support you in establishing and operating it. If you do not have a suitable internal information security role, you can use an external information security officer instead - or combine both services.

This makes it possible to organize information security in a structured way even if you do not want to establish a dedicated internal security function or need to relieve existing resources.

Eric-Hänsel
ISO-Gruppe

Eric Hänsel

Sales Consultant Security Services
Eichendorffstrasse 33
90491 Nuremberg
Germany
+49 (911) 995940
Contact

Where Should You Start?

Do you want to assess the current state of your information security, establish an ISMS, or further develop existing security and compliance processes?

In an initial consultation, we review your starting point and determine which of the services described is the right next step for you.

Downloads

In-Depth Information on NIS-2, IT Security, and Autonomous IT Operations

Digital illustration of IT security and cybersecurity with a shield protecting connected data
NIS-2 Readiness Workshop
Is Your IT Secure?
Visual representation of digital security: The image features a glowing shield with a checkmark, symbolizing a successful cyber risk check. Ideal for topics related to IT security, risk assessment, and digital protection measures.
CyberRisikoCheck
Security Starts with Clarity
Robotic hands reviewing system status, compliance and security protocols on a digital interface in a server environment.
White Paper
Autonome IT & Compliance
Contact