Services
Consulting, audit and implementation from a single source
Six building blocks that work on their own or combined. What they share is the ambition to improve security measurably instead of producing documents.
Tailored security consulting
A security strategy that fits your business model – not the other way round.
I analyse your starting position, prioritise risks by business impact and develop a security strategy your team can actually implement. Instead of working through standard catalogues, I focus on the measures with the greatest effect.
Enquire about Tailored security consultingTypical content
- Security strategy and roadmap with clear priorities
- Building and developing an ISMS
- Risk management and management reporting
- Sparring partner for management and IT leadership
Regulation & compliance
NIS2, CRA, DORA, ISO 27001 and the EU AI Act – translated into concrete measures.
Regulatory requirements are rarely the problem – translating them into everyday practice is. I clarify what actually applies to your company, which deadlines matter and which evidence you will have to present in the end.
Enquire about Regulation & complianceTypical content
- Applicability analysis for NIS2 and the Cyber Resilience Act (CRA)
- Preparing and supporting ISO/IEC 27001 certification
- Assessing the EU AI Act and the Cybersecurity Act (CSA)
- Building audit-proof documentation and evidence
Gap analyses & audits
A reliable picture of where you stand – with nothing glossed over.
As an ISO 27001 Lead Auditor I assess infrastructure, processes and documentation against the relevant standard. You receive a prioritised list of gaps with an effort estimate – usable as a project plan, not as a ring binder.
Enquire about Gap analyses & auditsTypical content
- Maturity assessment against ISO 27001, BSI IT-Grundschutz or NIS2
- Internal audits and supplier audits
- Prioritised list of measures including effort and ownership
- Management summary for executives and supervisory bodies
Training & awareness
Security knowledge that is still there after the training.
Awareness does not work through fear, but through understanding. I develop formats for your audience – from a management briefing to a technical deep dive – using real cases instead of generic slides.
Enquire about Training & awarenessTypical content
- Security awareness programmes and campaigns
- Briefings for management and executives
- Technical training for IT and development teams
- Phishing simulations with meaningful follow-up
Interim management
Experienced security leadership on a temporary basis – effective from day one.
Whether a vacancy, a certification project or a growth phase: I take temporary responsibility as CISO or information security officer and hand over a working setup at the end – not a dependency.
Enquire about Interim managementTypical content
- Interim CISO / information security officer
- Taking over ongoing security projects
- Building structures, roles and processes
- Structured handover to an internal successor
Talks & speaking
Cybersecurity explained clearly – for expert audiences and management alike.
Keynotes and impulse talks on current threat landscapes, regulation and security culture. Hands-on, without buzzword bingo, and with concrete recommendations the audience can take away.
Enquire about Talks & speaking Formats and referencesTypical content
- Keynotes for conferences and industry events
- Impulse talks for management meetings and advisory boards
- Panel participation and moderation
- Talks in German and English
Frequently asked questions
Good to know
Your question is not listed? Drop me a line – I usually reply within one working day.
Ask a questionNot sure which building block fits?
In the initial consultation we assess your situation together – free and without obligation.