We advise a global network of clients who are shaping the future.
Security Strategy & Organisation
This service area addresses the organisational embedding of IT security. The focus lies on roles and responsibilities, decision-making structures, and on how security objectives are defined and governed within the organisation. Typical topics include the development of a security strategy, the clarification of roles and responsibilities, and the assessment of existing structures at the management level.
Development of a security strategy at management level, starting from business objectives and the structures already in place. The assessment produces a target state and a sequence that fits the company's budget and capacity.
A structured review of organisational IT security: governance, roles, processes, decision paths and the level of security understanding in place. What is assessed is maturity, not technology.
Clarifying who takes which security decision and who prepares it. The result is an allocation of responsibility that holds up in daily work rather than only on the org chart.
A check of whether the company can act when it matters: who decides, who reports, who speaks externally. It covers roles, reporting lines and procedures, not technical recovery.
Governance, Risk & Compliance
This service area addresses the structured management of risks, policies and regulatory requirements. Support includes interpreting existing requirements, assessing risks from an organisational perspective, and developing practical governance and policy structures. The objective is to create a transparent and manageable GRC landscape without unnecessary bureaucracy.
An organisational view of the risk landscape, focused on business impact. The aim is a risk picture the management body can prioritise against.
Building or slimming down the policy set. Existing policies are reviewed, consolidated and brought to a volume that can actually be maintained.
A comparison of the existing organisation against the requirements of NIS2, in Austria the NISG 2026, as well as ISO 27001 or DORA. This service does not certify.
Not sure whether NIS2 applies to you? Take the free NIS2 scope check
Managing the risks that come with outsourced services and external providers. It covers ownership, contractual requirements and ongoing oversight.
Putting security documentation in order so it holds up under examination. Redundancies are removed, gaps named, ownership recorded.
Awareness, Training & Organisational Resilience
This service area focuses on the interaction between people, processes and decision-making behaviour. It assesses awareness levels, security culture and the organisation’s ability to prepare for and respond to security-relevant events. Services range from assessing the current state to designing appropriate awareness and resilience measures.
Establishing where security understanding actually stands, by role and by area. It is based on short interviews and a survey.
Training for staff or selected groups, remote or on site. Content and depth follow role and responsibility.
A concise briefing for executives and the management body. Security topics are put in context, risks explained plainly and decision options set side by side.
Anchoring security in communication, in how the organisation learns and in how it handles incidents. The aim is a culture where reports come early rather than late.
Continuous Advisory & Security Management Support
This service area is aimed at organisations requiring ongoing support in security and governance matters. Support is provided through regular exchanges or ad-hoc assistance in specific decision-making situations. The objective is to ensure continuity and consistency in managing security-related topics.
Ongoing support with a fixed monthly allowance. Topics are reviewed and prioritised regularly, without setting up a project each time.
For companies with continuous coordination needs in governance, risk and compliance. Includes document reviews and preparation for regulatory change.
Ad hoc support when a decision is due at short notice. No minimum term and no commitment.
Taking on clearly bounded organisational duties for a limited period, for example during a vacancy. Not operational and not technical.