Managed SOC & MDR: 24/7 protection as a service
Continuous, fully managed protection: technology, processes and a team of analysts around the clock, combined into one outsourced security operation. Faster detection, fewer false alarms and an audit trail your insurers and regulators will accept.
SOC as a Service
A 24/7/365 team of analysts monitors your environment, triages alerts and escalates verified incidents. Operated on proven SIEM platforms, with detection rules tailored to your business.
Managed Detection & Response (MDR)
Beyond pure monitoring: we actively contain threats on endpoints, identities and cloud workloads. Every incident comes with a report, indicators of compromise and clear remediation guidance.
Managed SIEM
We build and run your SIEM platform: log onboarding, parsing, use cases and ongoing tuning. You keep your data and licences. Ideal for NIS2, DORA and ISO 27001 without an in-house engineering team.
Managed EDR / XDR
Deployment, configuration and 24/7 operation of leading endpoint platforms. We tune rules, manage exceptions and respond on your behalf. Monthly health reports, quarterly tuning reviews.
Managed Email Security
Operation of your email security: anti-phishing, SPF/DKIM/DMARC, attachment sandboxing and impersonation protection. Especially important, since 91% of attacks start with a phishing email.
SOC Starter (for SMBs)
An 8x5 entry-level offering for small and mid-sized businesses: log ingestion, baseline detection rules, monthly reporting and an optional "Red Button" for emergencies. The pragmatic step from "we have antivirus" to measurable security.
Penetration Testing: we test your IT before attackers do
We simulate real attackers against your systems, applications and people, then deliver a prioritised, reproducible plan to fix exactly what we found. Not a scanner list, but proven exploitability.
Black / Grey / White Box
From a realistic outside attack (only a company name or IP), through the efficient grey box (the most common, cost-effective choice), to the deepest white-box test with source-code access before product launches.
Web Application Pentest
OWASP-aligned testing of web apps, APIs and authentication: OWASP Top 10, API Top 10, business-logic flaws and chained vulnerabilities that scanners miss. With proof-of-concept exploits and CVSS v4.0.
Mobile App Pentest
Static and dynamic analysis of iOS and Android apps including their backend APIs, along the OWASP MASVS/MASTG controls: insecure storage, weak transport, hard-coded secrets, jailbreak bypasses.
External & Internal Network Pentest
Adversarial testing of your internet-facing perimeter (VPN, firewalls, cloud edges) and assumed-breach testing from inside: Active Directory, lateral movement, sensitive file shares. Uncovers misconfigurations no scanner sees.
Wireless (Wi-Fi) Pentest
Testing of corporate and guest networks (WPA2/WPA3-Enterprise) for rogue access points, weak EAP configurations, evil-twin attacks and segmentation bypasses. Recommended for shared-tenancy offices.
Social Engineering & Phishing
Controlled phishing, vishing and pretexting campaigns that measure how your people, processes and detection respond, with scenarios that reflect the real threats facing your industry.
Incident Response & Digital Forensics: immediate help during cyberattacks
When an incident happens, we get you back to safe operations, and make sure you know exactly what happened, what was lost and how to prevent it next time.
Emergency Incident Response
Rapid containment, eradication and recovery during active incidents: ransomware, business email compromise, targeted intrusions. Following the SANS PICERL methodology, with a report for insurers, regulators and the board.
Digital Forensics
Forensically sound acquisition and analysis of disks, memory, mobile devices and cloud tenants. Findings documented to evidentiary standards, with an attacker timeline, indicators of compromise and an executive summary.
Compromise Assessment
The answer to one simple question: "Is someone in our environment right now?" Combining endpoint telemetry, log review, memory analysis and threat-intelligence matching. Ideal after M&A or unexplained anomalies.
Ransomware Recovery
End-to-end support: containment, scoping, negotiation advisory (where lawful), decryption and rebuild, plus a root-cause analysis so the same attack path cannot be reused.
Malware Analysis & Threat Hunting
Static and dynamic analysis of suspicious files in an isolated lab, with indicators of compromise and detection rules (YARA, Sigma). Plus hypothesis-driven threat hunting that finds what never triggered an alert.
Incident Response Retainer
A pre-negotiated contract that guarantees availability, SLA and pricing before an incident occurs. Unused hours go into tabletop exercises, playbook reviews or compromise assessments. Response time from days to hours.
Cybersecurity Audits & Compliance
Independent, evidence-based assessments that prepare you for regulators, customers, and insurers - and that actually improve your security posture along the way.
NIS2 Readiness Assessment
Gap analysis of your current security programme against the NIS2 Directive's ten risk-management measures and incident-reporting requirements. We deliver a prioritised roadmap, evidence templates, and a remediation plan mapped to your operational reality. Essential for the 40,000+ German entities now falling under NIS2.
DORA Compliance (Financial Sector)
Assessment and implementation support for the EU Digital Operational Resilience Act - covering ICT risk management, incident reporting, resilience testing, and third-party risk. We help banks, insurers, payment institutions, and their critical ICT providers meet the January 2025 obligations. Includes optional Threat-Led Penetration Testing (TLPT) aligned to TIBER-EU.
ISO/IEC 27001 Audit & Implementation Support
Pre-certification gap assessments, ISMS implementation support, and internal audits aligned to ISO/IEC 27001:2022 and ISO/IEC 27002:2022. We document Statements of Applicability, risk treatment plans, and control evidence in formats your certification body will accept. Pragmatic, not bureaucratic - controls are designed to actually work, not just to pass the audit.
TISAX Assessment Preparation
Tailored support for automotive suppliers preparing for TISAX assessment levels AL1, AL2, and AL3. Coverage includes information security, prototype protection, and data protection control objectives per the latest VDA ISA catalogue. Essential for any tier-1, tier-2, or tier-3 supplier serving the German automotive industry.
BSI IT-Grundschutz Audit
Assessment against the BSI IT-Grundschutz Compendium - the German federal baseline for information security. Suitable for organisations in the KRITIS scope, public-sector suppliers, and any company aligning to a recognised German standard. Outputs include modelling, gap analysis, and risk-treatment recommendations.
GDPR Technical Audit
Technical and organisational measures (TOM) review against Article 32 of the GDPR. We test what is actually implemented, not just what is documented - covering encryption, pseudonymisation, access controls, logging, and breach detection. Valuable in advance of supervisory-authority inquiries or as part of data-processor due diligence.
Industrial / OT Cybersecurity
Protection for the systems that run factories, plants, utilities, and logistics - where availability and safety are non-negotiable.
OT Risk Assessment (IEC 62443)
Risk assessment of your operational technology environment aligned to IEC 62443-3-2, with zones-and-conduits modelling and Security Level (SL) target definition. Considers safety, availability, and uptime constraints that IT-only assessments routinely miss. Outputs are usable by both engineering and security teams.
ICS / SCADA Penetration Testing
Carefully scoped, safety-aware penetration testing of industrial control systems, PLCs, HMIs, and engineering workstations. We use passive techniques where appropriate and design test windows to avoid disruption to production. Includes specific recommendations for Purdue Model segmentation and protocol-aware monitoring.
OT Network Segmentation Design
Design and validation of segmentation between IT and OT, between Purdue Levels, and between production cells. We translate IEC 62443 zones-and-conduits theory into specific firewall, switch, and data-diode configurations. Particularly relevant for manufacturers preparing for NIS2 and for KRITIS-regulated operators.
OT Incident Response Readiness
Tabletop exercises, playbook development, and IR-team training tailored to OT environments where shutting down a host can shut down a factory. We work with both your IT security team and your plant engineering team to align response decisions. Builds the muscle memory needed before a real OT incident - when there is no time to learn.
Methodology aligned with NIST CSF 2.0, NIST SP 800-61 & SP 800-115, ISO/IEC 27001*, SANS, MITRE ATT&CK, OWASP, CIS Controls, BSI IT-Grundschutz and TIBER-EU. * aligned with the standard; ISO/IEC 27001 certification of the GmbH in preparation.