03 · IT Security

Know where you’re exposed — before someone else does.

Audits based on BSI baseline protection, penetration testing, and NIS-2 consulting. We show you where your vulnerabilities are — and close them.

Most attacks aren’t looking for a target. They just find one.

Mid-sized companies are rarely singled out — they get found. Automatically, through a known vulnerability, a weak password, or an invoice attachment that looks entirely convincing. The damage then comes not from the sophistication of the attack but from the days it takes to recover.

We examine your IT from an attacker’s perspective and tell you in plain language where you stand. What happens next is your call: much of it can be handled internally, and we take on the rest.

What we do

We examine your IT the way an attacker would: an audit based on BSI baseline protection, penetration testing, and a review of your backup and recovery paths. What you get back is not a document dump but a risk-ordered list with effort estimates — and we can implement it with you. Also suitable as preparation for NIS-2 or customer audits.

How we implement it

After the audit you get a prioritised list with effort estimates, not a document dump. What you can implement yourselves we document clearly; what’s complex we can take on directly. A follow-up check confirms the gaps are actually closed.

Why us

You get a prioritised list with effort estimates, not an 80-page PDF.

Services in detail

01

BSI baseline protection audit

We work through systems, processes and access rights methodically — against a recognised standard rather than gut feeling. The result is a risk-ordered list with effort estimates that you can actually work from.

02

Penetration testing

We try to get in before someone else does: from outside through your internet-facing services, and on request from inside too — from the position of an employee, or of a lost laptop.

03

NIS-2 & customer audits

Many suppliers only discover they are in scope when a customer asks. We establish what genuinely applies to you and prepare the evidence your clients and insurers will want to see.

04

Incident response & recovery

We assess your protection status and recovery paths — GDPR-compliant backups, an incident plan with clear responsibilities. Ongoing monitoring and defence is handled by our Managed Security team on request.

Our Promise

A calm IT setup isn’t luck. It’s preparation.

We’re not a hyperscaler. We’re the team that answers the call, shows up, and solves the problem — before it costs your business anything.

On site
in the Munich area
8
service areas
2
named contacts
EU
Data hosted in the EU