IT security and compliance

Security is not a product you buy but a state you establish and maintain.

Close-up of a screen showing syntax-highlighted source code of a service class

Buying another security product rarely improves your security posture. What helps is knowing where you are actually exposed, which measure has the greatest effect, and who implements it. That is where we start.

Security audit

We assess infrastructure, application layer and internal processes. The result is a prioritised remediation plan, ordered by impact and effort – not by product category. For a FinTech company in Hesse this became the basis for the subsequent ISO 27001 certification.

Tools we use include OpenVAS for vulnerability scanning, Wazuh for endpoint monitoring and verinice for documentation.

ISO 27001 and NIS2

Both are states, not projects with an end date. We guide you from assessment through implementation to audit readiness – building documentation that remains maintainable in daily operations rather than appearing once for the auditor.

Since its transposition, NIS2 affects considerably more companies than its predecessor, including indirectly through supply chains. We establish whether you are in scope before any effort is incurred.

Zero trust in daily operations

Conditional access, multi-factor authentication throughout, network microsegmentation. This can be introduced step by step without halting operations – we have done exactly that in grown environments several times.

Threat monitoring

SIEM platforms collect events from servers, endpoints and firewalls and flag what stands out. We set this up and, on request, help run it – as a co-managed model where your team handles the day-to-day and we handle the analysis.

At a manufacturer of industrial components in Baden-Württemberg this model runs with SIEM, endpoint detection and quarterly vulnerability assessments.

Typical engagements

Security audits and vulnerability assessments, introducing zero-trust principles and MFA, network segmentation, firewall concepts with pfSense or OPNsense, SIEM deployment, ISO 27001 and NIS2 readiness, contingency and recovery planning.

Firewalls have a page of their own: as a listed partner of Netgate, Deciso and Zenarmor we build and run pfSense and OPNsense environments with application awareness.

Discuss your security posture See our projects