Skip to content
aprivas
03Services

Security & Governance

BSI baseline, NIS2, audit trails.

We think security from the start: not as afterthought documentation, but as part of the architecture.

Typische Leistungen

Was wir in diesem Feld konkret machen

  • 01Security concepts aligned with BSI baseline protection and ISO 27001
  • 02Role, permission and access models
  • 03Audit trails, logging architecture, forensic traceability
  • 04NIS2 readiness
  • 05Security in AI systems (model governance, policy enforcement)
Fields of work

Concept, implementation, evidence

We justify security measures so that they can be defended in an audit. It starts with taking stock: risk analysis before the list of measures.

  • 01

    Security concepts & risk analysis

    We develop and evaluate security concepts along BSI IT-Grundschutz: protection needs, risk analysis, planning of measures, fitted to the organisation, not the textbook.

  • 02

    System hardening

    Operating systems, services and access are hardened along recognised baselines, from base configuration to encrypted communication.

  • 03

    Audit preparation & support

    We prepare and accompany internal and external audits, with orderly evidence.

  • 04

    Incident preparedness

    Being prepared for severe security incidents: defined procedures for analysis, containment and remediation, structured root-cause work afterwards. The experience behind this comes from leading real incident taskforces.

  • 05

    NIS2 & regulatory readiness

    We translate requirements from NIS2 and BSI IT-Grundschutz into actionable measures, prioritised by risk.

  • 06

    Compliance workflows

    Recurring evidence and control duties are automated so that compliance runs alongside daily work instead of slowing projects down.

Nutzen

Systems that pass audit instead of being documented after the fact.

From practice

Security you can prove

Baseline-protection-oriented work means: assessment and protection needs first, then hardening. At the end stands evidence that stands up to an audit.

measures/status_2026-08.txt
[✓] access: key-based, second factor for administration
[✓] logging: central, tamper-proof
[✓] base hardening: system templates, deviations documented
[~] contingency: restart drill scheduled (Q4)
[ ] supply chain: assessment of external services open

An invented status, deliberately not all green: an honest measure plan also shows what is still open. That is exactly what an auditor expects.

From practice

Governance the system applies to itself

Governance view from the monitoring of our own agent system: memory entries with review duty, audit counters and an integrity check across the protected files of the framework.

Two monitoring panels: memory status with counters for active and review-due entries and audit entries; framework integrity reporting all files OK, 204 protected filesOur own system
Real screenshot from our operations. Our own automation is under supervision too: integrity checked, reviews scheduled, everything counted.
Contact

Have a concrete project in mind?

Tell us briefly the starting point, goal and constraints. In a first call we will then clarify whether we are a fit.

Your enquiry goes straight to managing director Markus Hentrich, not into a ticket system.