Information Security Consulting

Security on a solid foundation. We guide you from the initial analysis step to the tailored implementation of your security strategy. Ensuring requirements become resilient processes—not just documents that look good in an audit.

Request ConsultationAll Services

Information Security

Consulting

Frameworks

ISO 27001, BSI IT-Grundschutz, NIS2

Services

3 specific consulting areas

Starting Point

In-depth gap analysis

Outcome

Prioritized action plan

When You Need Us

Very few companies seek information security consulting without a specific reason. Most often, there is a concrete trigger:

  • A customer requires proof of ISO 27001 or BSI IT-Grundschutz compliance in a supplier audit, and the deadline is already set.
  • You are not sure whether NIS2 applies to you and need a reliable assessment rather than guesswork.
  • Your cyber insurance provider asks questions about measures that you cannot readily answer.
  • Information security rests on a single person who is primarily responsible for IT and handles security on the side.
  • Policies exist, but no one can say whether they are actually lived in day-to-day operations.
  • Following a security incident, isolated measures finally need to become a cohesive system.

Which Framework Fits You

Three frameworks appear most frequently in practice, and they answer different questions.

ISO 27001

An international standard for an information security management system (ISMS). Relevant when customers or partners require certification, often in B2B business and with an international focus.

BSI IT-Grundschutz

A German framework with a highly specific catalog of measures. Relevant for public-sector clients, government agencies, and companies operating around public administration, and as a practical starting point beyond it.

NIS2

An EU directive, implemented nationally, obliging specific sectors to implement minimum measures and reporting obligations. Relevant as soon as your company falls into the affected sectors and size categories, regardless of whether you are aiming for certification.

The frameworks are not mutually exclusive. NIS2 is often the legal obligation in the background, while ISO 27001 or BSI IT-Grundschutz provide the structured path to meet it.

Where to Start

Your Situation Recommended Starting Point
Customer requires certification ISO 27001 or BSI IT-Grundschutz
Unclear whether NIS2 applies NIS2 Consulting for applicability assessment
Public sector client BSI IT-Grundschutz Consulting
Security ownership lacks organizational structure CISO as a Service
No formal requirements yet, but a diffuse sense of uncertainty Gap analysis without framework commitment

When in doubt, we begin with the gap analysis regardless of the target framework. It shows the current status and makes choosing the right framework easier afterward.

What We Do and What You Receive

Service What You Receive
Gap Analysis Gap report with target-vs-actual comparison against the relevant framework, including protection needs assessment
Risk Assessment Risk register with classification, responsibilities, and treatment decisions per risk
Action Planning Prioritized action plan based on risk and effort, with assigned responsibilities and a realistic timeframe
Policy Development Fully drafted set of policies tailored to your organization rather than boilerplate templates
Training Workshops and briefings to ensure security does not depend on isolated individuals
Audit Support Preparation, support during the audit, and an executive summary of key results

Our Focus Areas

Implementation of the IT-Grundschutz Compendium, from structural analysis to the action plan.

External security responsibility with a dedicated contact person and a clear time budget.

Assessment of applicability and implementation of obligations under the NIS2 directive.

How Consulting Works

1

Current State Assessment

We record your systems, processes, and existing measures and compare them against the framework relevant to you.

2

Prioritization

Dogether, we define what is needed in the short term and what can follow in the medium term.

3

Implementation Support

We guide the implementation and are on hand as your point of contact without taking decisions out of your hands.

4

Audit & Fine-Tuning

We prepare you for audits, accompany you on-site upon request, and refine measures based on the results.

How Long It Takes

Initial certification according to ISO 27001 or BSI IT-Grundschutz is not a weekend project. As a rough guide:

  • Gap analysis: a few weeks, depending on the size and complexity of the organization.
  • Implementation up to certification readiness: usually several months up to a year, depending on how much is already in place.
  • The certification itself: conducted by an independent, accredited body. We prepare and accompany you; the certificate is issued by that body.
  • Maintenance: ongoing internal audits and recertification typically after three years, with annual surveillance audits in between.

The exact timeframe depends heavily on the starting point. You will receive a realistic estimate following the gap analysis.

Why It Is Worth It

Improve IT Security

A structured approach protects your infrastructure sustainably instead of treating individual symptoms.

Ensure Compliance

Meet regulatory requirements and build trust with customers, partners, and auditors.

Reduce Risks Efficiently

Target attack surfaces effectively instead of investing everywhere at once.

Hands-on Technical Expertise

We come from penetration testing. Our measures are aligned with what attackers actually do, not with what is easiest to document.

Information Security Consulting

Tell us what triggered your inquiry. In an initial conversation, we assess the framework and identify the next steps.

  • Assessment regarding ISO 27001, BSI, or NIS2
  • Start with an in-depth gap analysis
  • Prioritized action plan
  • Resilient processes instead of audit documents

Frequently Asked Questions

What clients want to know before working together.

No. We prepare you for the audit; the certificate is issued by an independent, accredited certification body. This separation is required by standard.

Not always. Sometimes a structured gap analysis with an action plan is sufficient if no customer or regulation explicitly requires certification. We do not automatically recommend the most extensive process.

Then we verify whether they fit the selected framework and are actually practiced in everyday operations, rather than starting from scratch.

Yes, the scope scales with size. A gap analysis for a small business is correspondingly more compact.

We assess applicability and obligations from a technical perspective. The legally binding evaluation in individual cases belongs in the hands of your legal counsel.

The work does not end there. Internal audits, updating the risk register, and annual surveillance audits continue; we can support this upon request.