We advise a global network of clients who are shaping the future.

Security Strategy & Organisation

In Short

This service area addresses the organisational embedding of IT security. The focus lies on roles and responsibilities, decision-making structures, and on how security objectives are defined and governed within the organisation. Typical topics include the development of a security strategy, the clarification of roles and responsibilities, and the assessment of existing structures at the management level.

Security Strategy & Target State

Development of a security strategy at management level, starting from business objectives and the structures already in place. The assessment produces a target state and a sequence that fits the company's budget and capacity.

Result
Security target state · prioritised roadmap over 6 to 24 months · roles and responsibilities model
Organisational Security Assessment

A structured review of organisational IT security: governance, roles, processes, decision paths and the level of security understanding in place. What is assessed is maturity, not technology.

Result
Maturity rating across governance, processes, roles, risk and awareness · prioritised recommendations · summary for the management body
Roles, Responsibilities & Governance Setup

Clarifying who takes which security decision and who prepares it. The result is an allocation of responsibility that holds up in daily work rather than only on the org chart.

Result
Security operating model · role descriptions with interfaces · RACI for security and GRC
Organisational Incident Readiness

A check of whether the company can act when it matters: who decides, who reports, who speaks externally. It covers roles, reporting lines and procedures, not technical recovery.

Result
Gap list covering roles, reporting lines and escalation · immediate measures · 90-day plan

Governance, Risk & Compliance

In Short

This service area addresses the structured management of risks, policies and regulatory requirements. Support includes interpreting existing requirements, assessing risks from an organisational perspective, and developing practical governance and policy structures. The objective is to create a transparent and manageable GRC landscape without unnecessary bureaucracy.

Risk Management & Decision Support

An organisational view of the risk landscape, focused on business impact. The aim is a risk picture the management body can prioritise against.

Result
Risk profile with business impact · catalogue of measures · risk overview as a working file the company keeps
Policy & Governance Framework

Building or slimming down the policy set. Existing policies are reviewed, consolidated and brought to a volume that can actually be maintained.

Result
4 to 12 policies depending on scope · governance model with ownership · review and update process
Regulatory Readiness & Gap Analysis

A comparison of the existing organisation against the requirements of NIS2, in Austria the NISG 2026, as well as ISO 27001 or DORA. This service does not certify.

Result
Gap analysis per requirement · prioritised plan of measures · roadmap with owners and dates
Third Party & Outsourcing Governance

Managing the risks that come with outsourced services and external providers. It covers ownership, contractual requirements and ongoing oversight.

Result
Provider assessment by criticality · governance check of outsourcing oversight · catalogue of measures
Documentation & Auditability

Putting security documentation in order so it holds up under examination. Redundancies are removed, gaps named, ownership recorded.

Result
Inventory with version, owner and validity · redundancies and gaps · proposal for a lean document set

Awareness, Training & Organisational Resilience

In Short

This service area focuses on the interaction between people, processes and decision-making behaviour. It assesses awareness levels, security culture and the organisation’s ability to prepare for and respond to security-relevant events. Services range from assessing the current state to designing appropriate awareness and resilience measures.

Awareness & Needs Assessment

Establishing where security understanding actually stands, by role and by area. It is based on short interviews and a survey.

Result
Awareness level per role · topic prioritisation · twelve-month training plan
Security Awareness Trainings

Training for staff or selected groups, remote or on site. Content and depth follow role and responsibility.

Result
One to two hour session · materials the company keeps and reuses · practical guidance for daily work
Executive Awareness & Decision Support

A concise briefing for executives and the management body. Security topics are put in context, risks explained plainly and decision options set side by side.

Result
30 to 60 minute briefing · basis for decisions · prioritisation recommendation
Resilience & Security Culture

Anchoring security in communication, in how the organisation learns and in how it handles incidents. The aim is a culture where reports come early rather than late.

Result
Communication concept · training and measures plan · set of materials

Continuous Advisory & Security Management Support

In Short

This service area is aimed at organisations requiring ongoing support in security and governance matters. Support is provided through regular exchanges or ad-hoc assistance in specific decision-making situations. The objective is to ensure continuity and consistency in managing security-related topics.

Monthly Advisory

Ongoing support with a fixed monthly allowance. Topics are reviewed and prioritised regularly, without setting up a project each time.

Result
Regular review meeting · prioritisation of open topics · questions answered in between
Extended Advisory & GRC Support

For companies with continuous coordination needs in governance, risk and compliance. Includes document reviews and preparation for regulatory change.

Result
Structured GRC support · document reviews · preparation for regulatory change
Security Sparring & Decision Support

Ad hoc support when a decision is due at short notice. No minimum term and no commitment.

Result
Basis for a decision within days · options set out clearly · a stated recommendation
Interim Security Management

Taking on clearly bounded organisational duties for a limited period, for example during a vacancy. Not operational and not technical.

Result
Cover for policy ownership, risk owner support or governance steering · written handover at the end

Contact Us

Message received

Together for your cybersecurity

Thank you!

Your message has been successfully sent.
We will get back to you shortly.
An error occurred.
Please check your input and try again.