Services

Consulting, audit and implementation from a single source

Six building blocks that work on their own or combined. What they share is the ambition to improve security measurably instead of producing documents.

Tailored security consulting

A security strategy that fits your business model – not the other way round.

I analyse your starting position, prioritise risks by business impact and develop a security strategy your team can actually implement. Instead of working through standard catalogues, I focus on the measures with the greatest effect.

Enquire about Tailored security consulting

Typical content

  • Security strategy and roadmap with clear priorities
  • Building and developing an ISMS
  • Risk management and management reporting
  • Sparring partner for management and IT leadership

Regulation & compliance

NIS2, CRA, DORA, ISO 27001 and the EU AI Act – translated into concrete measures.

Regulatory requirements are rarely the problem – translating them into everyday practice is. I clarify what actually applies to your company, which deadlines matter and which evidence you will have to present in the end.

Enquire about Regulation & compliance

Typical content

  • Applicability analysis for NIS2 and the Cyber Resilience Act (CRA)
  • Preparing and supporting ISO/IEC 27001 certification
  • Assessing the EU AI Act and the Cybersecurity Act (CSA)
  • Building audit-proof documentation and evidence

Gap analyses & audits

A reliable picture of where you stand – with nothing glossed over.

As an ISO 27001 Lead Auditor I assess infrastructure, processes and documentation against the relevant standard. You receive a prioritised list of gaps with an effort estimate – usable as a project plan, not as a ring binder.

Enquire about Gap analyses & audits

Typical content

  • Maturity assessment against ISO 27001, BSI IT-Grundschutz or NIS2
  • Internal audits and supplier audits
  • Prioritised list of measures including effort and ownership
  • Management summary for executives and supervisory bodies

Training & awareness

Security knowledge that is still there after the training.

Awareness does not work through fear, but through understanding. I develop formats for your audience – from a management briefing to a technical deep dive – using real cases instead of generic slides.

Enquire about Training & awareness

Typical content

  • Security awareness programmes and campaigns
  • Briefings for management and executives
  • Technical training for IT and development teams
  • Phishing simulations with meaningful follow-up

Interim management

Experienced security leadership on a temporary basis – effective from day one.

Whether a vacancy, a certification project or a growth phase: I take temporary responsibility as CISO or information security officer and hand over a working setup at the end – not a dependency.

Enquire about Interim management

Typical content

  • Interim CISO / information security officer
  • Taking over ongoing security projects
  • Building structures, roles and processes
  • Structured handover to an internal successor

Talks & speaking

Cybersecurity explained clearly – for expert audiences and management alike.

Keynotes and impulse talks on current threat landscapes, regulation and security culture. Hands-on, without buzzword bingo, and with concrete recommendations the audience can take away.

Enquire about Talks & speaking Formats and references

Typical content

  • Keynotes for conferences and industry events
  • Impulse talks for management meetings and advisory boards
  • Panel participation and moderation
  • Talks in German and English

Frequently asked questions

Good to know

Your question is not listed? Drop me a line – I usually reply within one working day.

Ask a question

Both. The six building blocks are deliberately cut so they work individually or combined. Many engagements start with a gap analysis or an initial consultation and only grow as needed.

Yes. I do not sell software and receive no commissions from vendors. Recommendations follow your situation alone – not partner programmes.

A gap analysis determines where you stand: how do you compare against a standard or regulation, and what is missing? A certification audit is carried out by an accredited body. I prepare you for that audit and accompany it, but I do not issue certificates myself.

Yes, as a speaker I give talks and impulse sessions – on NIS2, the CRA or awareness, for example. Get in touch with the occasion, audience and desired length.

Not sure which building block fits?

In the initial consultation we assess your situation together – free and without obligation.