IT security
Technical testing and hardening of applications, networks, cloud and processes by certified testers.
Verifiable, reproducible, vendor-independent.
Automated scanners find the obvious. We test by hand and evidence every finding. Three principles govern the work.
Testing by hand
Chaining several small weaknesses into real access is something a person finds, not a scanner. Every finding comes with reproduction steps you can follow.
The regulatory trigger
NIS2 widens the circle of affected operators, DORA binds the financial sector. We place the requirements plainly and align scope and evidence with them.
Vendor-independent
We sell no security products. Our assessment is tied to no manufacturer and follows your risk alone.
Five categories for IT.
The same structure as in OT, aimed here at applications, networks, cloud and processes. One sentence to place each; the detail is on its own page.
- Penetration testing and assessments Web, network, cloud, API, red teaming, OSINT.
- SOC, SIEM and monitoring Design, SIEM engineering, detection.
- Cyber exercises and crisis management Red, blue and purple team, tabletop, business continuity.
- Compliance and consulting NIS2, DORA, ISO 27001, DevSecOps.
- Training Awareness, phishing simulation, live hacking.
One test, one report you can work from.
How a test runs in practice, and what ends up in your hands, is shown by a completed case study from the retail sector.
Security architecture for a railway interlocking landscape
Six months of testing on an interlocking landscape, without intervening in live traffic. The result was a risk assessment with a zone and conduit model rather than a list of scanner findings.
Read the case studyWhat IT security can be measured against.
These frameworks set the scope of a test and the evidence it has to produce. The formal classification is one you make with your own compliance people.
NIS2
EU directive on cyber resilience, with a wider circle of operators.
DORA
Digital operational resilience in the financial sector.
ISO 27001
Management system for information security.
OWASP
Testing standard for web applications and APIs.
BSI
IT-Grundschutz and German national requirements.
Questions about IT security.
Cybersecurity, also called IT security, is the practice of protecting computer systems and networks against attack. The aim is to keep data and systems confidential, intact and available.
That means making sure only authorised people can reach data and systems, that data stays correct and complete, and that systems are available when they are needed: preventing unauthorised access, unauthorised change and denial of service.
It covers several kinds of measure: technical protection such as firewalls, malware scanners and intrusion detection; training people on the ways attacks arrive; regular backups, so that recovery after an attack is quick; and a plan for the day it happens.
Several, and they work in different ways.
Malware. Viruses, trojans and ransomware infect systems and damage or steal data. Viruses replicate themselves; trojans hide inside harmless-looking programs; ransomware encrypts data and demands payment for the key.
Phishing. Attackers pose as someone trusted to obtain credentials or other confidential information, by an email that looks convincingly like a bank or an authority, or by telephone.
Social engineering. Attackers use human psychology to get around security measures: they build trust in order to manipulate, or mislead people into making a mistake.
Zero-day attacks. Attacks on weaknesses for which no patch exists yet. They are dangerous precisely because no fix is available, and speed of response is what counts.
Ransomware. Attackers encrypt data and demand payment. The cost lands twice: in the payment and in the interruption to operations. If customer data is taken as well, reputational damage comes on top.
Supply chain attacks. Attackers use weaknesses at a supplier. They are hard to defend against, because a company rarely has direct influence over a supplier's security, and because one compromised supplier can reach several companies at once.
Cloud attacks. Cloud environments open attack paths of their own, and their security needs watching continuously rather than once.
Phishing. The attacks keep getting better made, which is why they remain among the largest risks.
A penetration test is a controlled attack on your own systems. Instead of producing a list of theoretical weaknesses, it establishes what an attacker could actually do with them: which systems are reachable from there, which data can be read, how far the path goes.
The value lies in that chain. Single weaknesses are rarely the problem; what becomes dangerous is the combination of several small ones that together make a way in.
Cyber defence is the running operation: detecting attacks, assessing them and stopping them while they happen. It means continuous monitoring of systems and networks, evaluation of events in a SIEM, and a team that reacts to what stands out.
The difference from a penetration test: the test says where the gaps are. Cyber defence says whether someone is going through one right now.
Awareness training teaches people to recognise the attacks that aim at people rather than at technology: phishing mail, manipulated phone calls, a pretext at reception.
It matters because a large share of successful attacks starts there. A firewall can be configured; a convincingly written email to a person who does not read it as an attack goes straight past it.
Know where you stand.
Work out a guide figure in the calculator, or talk to us directly. We will say frankly which test fits your situation.