Security & Governance
BSI baseline, NIS2, audit trails.
We think security from the start: not as afterthought documentation, but as part of the architecture.
Was wir in diesem Feld konkret machen
- 01Security concepts aligned with BSI baseline protection and ISO 27001
- 02Role, permission and access models
- 03Audit trails, logging architecture, forensic traceability
- 04NIS2 readiness
- 05Security in AI systems (model governance, policy enforcement)
Concept, implementation, evidence
We justify security measures so that they can be defended in an audit. It starts with taking stock: risk analysis before the list of measures.
- 01
Security concepts & risk analysis
We develop and evaluate security concepts along BSI IT-Grundschutz: protection needs, risk analysis, planning of measures, fitted to the organisation, not the textbook.
- 02
System hardening
Operating systems, services and access are hardened along recognised baselines, from base configuration to encrypted communication.
- 03
Audit preparation & support
We prepare and accompany internal and external audits, with orderly evidence.
- 04
Incident preparedness
Being prepared for severe security incidents: defined procedures for analysis, containment and remediation, structured root-cause work afterwards. The experience behind this comes from leading real incident taskforces.
- 05
NIS2 & regulatory readiness
We translate requirements from NIS2 and BSI IT-Grundschutz into actionable measures, prioritised by risk.
- 06
Compliance workflows
Recurring evidence and control duties are automated so that compliance runs alongside daily work instead of slowing projects down.
Systems that pass audit instead of being documented after the fact.
From practice
Security you can prove
Baseline-protection-oriented work means: assessment and protection needs first, then hardening. At the end stands evidence that stands up to an audit.
[✓] access: key-based, second factor for administration [✓] logging: central, tamper-proof [✓] base hardening: system templates, deviations documented [~] contingency: restart drill scheduled (Q4) [ ] supply chain: assessment of external services open
An invented status, deliberately not all green: an honest measure plan also shows what is still open. That is exactly what an auditor expects.
From practice
Governance the system applies to itself
Governance view from the monitoring of our own agent system: memory entries with review duty, audit counters and an integrity check across the protected files of the framework.
Our own systemHave a concrete project in mind?
Tell us briefly the starting point, goal and constraints. In a first call we will then clarify whether we are a fit.
Your enquiry goes straight to managing director Markus Hentrich, not into a ticket system.