CyberRisikoCheck to DIN SPEC 27076
A structured conversation rather than a tool run, for companies with no security department of their own. At the end, a report with prioritised recommendations.
A method for companies under fifty staff
The CyberRisikoCheck is described in DIN SPEC 27076 and was developed with the BSI, the German federal office for information security. It is aimed at small and mid-sized companies that have no security function of their own and for which a management system to ISO 27001 would be out of proportion.
The method is an interview along 27 requirements from six subject areas, held with the management and the person who looks after the IT. It takes one to two hours.
An order of work you can actually use
You receive a report with an assessment per subject area and a list of recommendations sorted by urgency: what belongs done immediately, what in the short term, what in the medium term, and what later.
Every recommendation is written so that a company without a security department can work from it. Each one names a concrete step and an estimate of what it costs.
The report also serves as a basis for funding applications, because it evidences the need.
What gets talked about
The requirements of the DIN SPEC cover the areas in which small companies have most of their gaps.
Organisation and people
Responsibilities, rules, awareness. Who decides on the day, and do staff know whom to turn to.
Technology and operations
Updates, malware protection, access and passwords, backup and recovery. Whether a backup exists, and whether anyone has ever restored from it.
Providers and contingency
Who looks after your IT, what the contract says, and what happens if that provider is unavailable. Alongside the question of what happens in the event of an attack.
How the check runs
A conversation of one to two hours, plus the write-up. DIN SPEC 27076 provides for no more than that, and no more is needed.
The appointment and who attends
At the table are the management and the person who looks after the IT. If a service provider runs your IT, they are welcome but not necessary.
The conversation
We work through the 27 requirements from six subject areas. The questions are written for people without specialist knowledge; where an answer is unclear, we record that rather than guess.
Write-up
An assessment per subject area and a list of recommendations sorted by urgency. Each one names a concrete step and an estimate of what it costs.
Walk-through
The report gets talked through, so that it is clear where to start. It also serves as a basis for funding applications, because it evidences the need.
Common questions about the CyberRisikoCheck
The effort is bounded by the method: a conversation of one to two hours, plus the write-up. Several German states offer funding that covers part of it.
No. The questions are written for people without specialist knowledge. It helps to have someone present who knows who looks after the IT.
No. The check looks at organisation and procedure, a penetration test at the technology. For a company with no security function of its own, the check is the more sensible first step, because it shows where to start at all.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.