Audits & IT checks
Assess cyber security – independent, understandable, effective
How secure is your company really? Our independent audits give you an honest, well-founded assessment – clearly presented and focused on what matters for your decisions. We work with recognised standards such as ISO 27001, VdS 10000, DIN SPEC 27076 as well as BSI Grundschutz, ISO 27002 or the CIS Controls. This gives you the basis to classify cyber risks correctly and steer investments purposefully.
Because nobody can assess themselves objectively, we bring in the neutral outside view. We identify weaknesses, point out risks and prioritise measures by effort and relevance. As management or department lead you quickly know what really matters.
Our services cover various audit types, which we present clearly and understandably:
Technical audits
You want to know whether your IT is resilient to common attacks according to the state of the art? We assess your technical security measures against common standards, such as the CIS Critical Security Controls, in areas such as:
- Review of network security, system hardening and user permissions
- Assessment of backup and contingency concepts
- Analysis of security policies, processes and technical measures
- Assessment of cloud security and hybrid infrastructures
Compliance audits
As a first, practical and low-threshold standard, the BSI developed the Cyber Risiko Check to DIN SPEC 27076 for small and medium-sized companies – the beginner badge among information security certifications.
Internal audits
If you want your ISMS certified to ISO 27001, you must carry out regular independent internal audits. As the ISMS team is usually already busy with build-up and operation, the ISMS audit is often outsourced. An internal audit reveals potential deviations in good time – before they surface in the certification audit.
- Audit report for targeted preparation for external assessments
- Assessment of conformity with ISO 27001:2022
- Review of the effectiveness of processes and controls
GAP analyses
You want to know what effort a BSI C5 certification or compliance with new requirements such as NIS2 will mean for you? With a structured GAP analysis we show you the current state, identify gaps and provide a clear roadmap to close them.
Delivery
We define the focus and scope of the assessment individually with you – in a no-obligation first call. We prepare all results so that you as management can understand them immediately. Your departments receive concrete, prioritised recommendations for action.
Not sure where you stand?
In a first call we clarify your situation and what makes sense as a next step. No obligation, no cost.