Skip to content
Call +49 40 88192642 Send an email [email protected] Chat in Teams [email protected]
Services

IT security that works day to day and holds when it matters.

From risk analysis through endpoint and network protection to backup, incident plan and security awareness: a security concept that fits your company and also takes account of what cyber insurers, clients and regulatory frameworks require.

Starting point

Cyber attacks have long stopped being a problem only for large companies. In small and mid-sized companies, though, there is often neither the time nor the capacity to review protective measures regularly and develop them further. At the same time cyber insurers, clients and frameworks such as NIS2 increasingly ask for security measures that can be evidenced.

Goal

The aim is an environment that makes attacks harder and is prepared for an incident: secured identities and devices, segmented networks, protected email and dependable backups. Alongside that, clear responsibilities and an incident plan for the case where protective measures are not enough.

Typical work

Services

  1. Risikoanalyse und Sicherheitskonzept

    Risk analysis and security concept

    Vulnerability analysis, a review of network, permissions and configurations, and a prioritised action plan as the basis for budget and sequence.

  2. Identity und Access Management

    Identity and access protection

    Multi-factor authentication, Conditional Access, least-privilege permissions, protection for privileged accounts, a password manager.

  3. Endpoint Protection und MDR

    Endpoint protection and MDR

    Endpoint protection with detection and response (EDR/XDR), device encryption and, if you want it, managed detection and response with an analyst team around the clock.

  4. Netzwerksicherheit

    Network security

    Next-generation firewall, segmentation into security zones, secure VPN and zero-trust principles for access from outside.

  5. E-Mail-Sicherheit

    Email security

    Protection against phishing, spam and malware, SPF, DKIM and DMARC, encryption and archiving.

  6. Schwachstellen- und Patchmanagement

    Vulnerability and patch management

    Regular, controlled updates for operating systems, applications and firmware, with monitoring of open vulnerabilities.

  7. Backup und Disaster Recovery

    Backup and disaster recovery

    Backup on the 3-2-1 principle including Microsoft 365, encrypted and immutable backups, documented restore tests and defined recovery times.

  8. Security Awareness

    Security awareness

    Training and phishing simulations so staff recognise attacks and react correctly.

  9. Notfallplan und Incident Response

    Incident plan and response

    Who does what when something happens: contacts, locking accounts, recovery, communication and reporting obligations.

Technology

What I work with — and why.

Which components make sense depends on risk, environment and how much protection is needed.

Sophos Endpoint & MDR
Endpoint protection with EDR/XDR; MDR adds an analyst team that assesses incidents around the clock and steps in.
Sophos Firewall
Next-generation firewall with segmentation, VPN and Synchronized Security with endpoint protection.
Microsoft Defender & Conditional Access
Protection for identities, devices and email within Microsoft 365, with access rules by user, device and risk.
Hornetsecurity
Email security, backup for Microsoft 365 and security awareness training with phishing simulations.
Bitdefender
Endpoint protection as an alternative, depending on the environment and requirements.
AvePoint
Backup and governance for Microsoft 365, SharePoint and Teams.
Proxmox Backup Server
Backup of virtual servers with verification and targeted restore.
How it works

How a project usually runs.

  1. 01

    Analysis

    Risk analysis and inventory: what is there, what is active, what is missing?

  2. 02

    Prioritise

    An action plan ordered by risk and effort, matched to your budget and to what insurers or clients require.

  3. 03

    Build

    A gradual rollout, agreed with your staff, so security works in everyday use.

  4. 04

    Operate

    Monitoring, updates, reporting and regular review, because both threats and your environment keep changing.

Frequent questions

What clients want to know in advance.

Not finding what you want to know? Ask me directly.

Requirements vary, but multi-factor authentication, verified offline backups, endpoint protection with detection, patch management and an incident plan are generally expected. I document the current state and close the gaps.

Directly, NIS2 mainly affects larger companies in certain sectors. Indirectly it affects many suppliers, because affected clients ask for evidence about the security of their supply chain. I help assess where you stand and produce that evidence.

MFA is the most important first step, but modern phishing techniques get around simple methods. Conditional Access, managed devices, email protection and awareness belong with it, so the measures work together.

Not every one. MDR makes sense when nobody in the company can assess security alerts promptly and an outage would be expensive. I assess that with you based on size, data and risk.

Want to talk through a specific project?

Send me a couple of lines about it, or just call. You reach me directly, no call centre.

Discuss your project