Increasing legal and regulatory requirements necessitate sweeping security measures and structures that are designed for the ongoing assessment of risks and the implementation of corrective measures where necessary.

We advise you on compliance with legal and regulatory requirements, as well as on the establishment of management systems to ensure long-term conformity.

Standards and regulations supported by us

  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • ISO 22301
  • IEC62443
  • BSI IT-Grundschutz
  • NIST Cyber Security Framework
  • EPD-TOZ
  • GxP Compliance
  • GAMP 5
  • COBIT
  • PCI-DSS
  • IKT-Minimalstandard
  • FINMA Rundschreiben
  • OWASP
  • PTES
  • Generelle IT-Kontrollen (ITGC)
  • Datenschutz (DSG)
  • GDPR
  • CSA CAIQ
  • BSI C5
  • Weisungen und Kreisschreiben Bundesamt für Sozialversicherung (BSV)
  • SWIFT

Risk management

Risk management helps in the continuous identification of risks, their systematic assessment and processing, as well as in the transparent and comprehensive communication of residual risks. We join with you to define or optimize your risk management processes, including the following areas:

  • Establishment or optimization of risk management
  • Definition of processes for the identification, assessment, processing and communication of risks
  • Preparation of risk analyses for projects or organizations
  • Methodical and content support or the organization of workshops for risk identification and assessment
  • Handling of risk management activities

Compliance assessment & management

Our security specialists review the fulfilment of legal and regulatory requirements within the framework of the compliance assessment. Structured as a gap analysis, you receive an independent assessment of current implementation levels, as well as a set of recommendations to ensure compliance. We will gladly support you in the assessment of requirements defined by relevant laws or regulations and collaborate with your specialists to ensure an optimized structure, thus creating a solid foundation for effective and efficient implementation. Where necessary, our security specialists translate the requirements into the current information security management system or establish a suitable policy.

Minimum ICT standard

The minimum ICT standard is a comprehensive framework for protecting your organization against cyber risks.

We support you in determining the maturity level of your organization. By assessing the status quo in the regard to the minimum ICT standard, we evaluate whether you are already compliant or vulnerabilities continue to exist. If the latter applies, we develop a pragmatic action plan that equips you to establish a security process within your organization and hence to comply with the minimum ICT standard in the long term.

Cloud Security Assessment

In our Cloud Security Assessment we examine the security level of your organization with a focus on cloud security. We assess the processes for supporting and maintaining information security in this area. The assessment takes into account industry-specific requirements and international best practices such as the Cloud Security Alliance (CSA) or C5 of the BSI. Based on our interviews and technical verifications, we assess the maturity of your security level and provide you with an overall report and specific recommendations for improvement.

Support for certification

We support you in building and certifying data protection and information security management systems according to ISO/IEC 27001, EPDG and VDSZ. In this regard, we ensure ideal preparation for upcoming certification and accompany the audits until successful completion of the certification process.