Sicherheit in einer Welt,
die keine garantiert.
Security in a world that
guarantees none.

Cyberangriffe, Spionage, neue Regulierung – die Bedrohung wächst. Wir bauen Managementsysteme, die Ihr Unternehmen schützen. In Deutschland und der Schweiz. Für den Mittelstand. Cyberattacks, espionage, new regulation – the threat is growing. We build management systems that protect your organisation. In Germany and Switzerland. For mid-sized companies.

NIS-2 ist da.
DSGVO & revDSG gelten im DACH-Markt.
Wo stehen Sie?
NIS-2 is here.
GDPR & revFADP apply in the DACH market.
Where do you stand?

Seit 2025 gilt NIS-2 in Europa. Fast alle Unternehmen mit mehr als 50 Mitarbeitenden in Sektoren wie Energie, Transport, Gesundheit, digitale Infrastruktur, verarbeitendes Gewerbe, Lebensmittel oder Abfallwirtschaft sind betroffen – viele wissen es noch nicht. Die nationalen Datenschutzgesetze betreffen ausnahmslos jedes Unternehmen.

Since 2025, NIS-2 applies in Europe. Nearly all companies with more than 50 employees in sectors like energy, transport, healthcare, digital infrastructure, manufacturing, food or waste management are affected – many don't know it yet. National data protection laws apply to every single company.

Die Strafen sind empfindlich, die Anforderungen komplex. Aber ein Managementsystem für Informationssicherheit und Datenschutz aufzubauen muss weder Jahre dauern noch ein Vermögen kosten – wenn man es richtig angeht.

Penalties are severe, requirements complex. But building a management system for information security and data protection doesn't have to take years or cost a fortune – if you approach it right.

Die nachweisliche Einhaltung von Standards wird für viele Branchen zum kritischen Erfolgsfaktor. Ausschreibungen setzen ein Zertifikat nach ISO 27001 voraus, Kunden fragen in Lieferantenbewertungen danach. Mit einem zertifizierten ISMS erfüllen Sie die gesetzlichen Pflichten und erschließen zugleich neue Chancen. Steht eine Ausschreibung an oder fragt ein Kunde nach einem Zertifikat, sprechen Sie uns an.

Demonstrable compliance with standards is becoming a critical success factor in many industries. Tenders require ISO 27001 certification, and customers ask for it in supplier assessments. With a certified ISMS you meet your legal obligations and open up new opportunities at the same time. If a tender is coming up or a customer asks for a certificate, get in touch.

Ihr Compliance-Status in 3 Minuten Your compliance status in 3 minutes

Finden Sie heraus, wo Handlungsbedarf besteht – und welche Schritte Sie als Nächstes gehen sollten. Find out where action is needed – and which steps to take next.

NIS-2 – VorprüfungPre-screening
NIS-2 Compliance
DSGVO / GDPR Compliance
revDSG / revFADP Compliance

Informations­sicherheit und Datenschutz verankern. Passend für Ihre Organisation. Embed information security and data protection. Tailored to your organisation.

Die meisten Unternehmen starten ihr ISMS mit Excel-Listen und Word-Vorlagen. Wer es ernst meint, landet bei teuren GRC-Plattformen oder individualisierten Lösungen, die Einarbeitung und eigene Compliance-Experten voraussetzen. Beides bremst.

Most companies start their ISMS with spreadsheets and Word templates. Those who get serious end up with expensive GRC platforms or custom solutions that require onboarding and in-house compliance experts. Both slow you down.

Wir sind Organisationsexperten, die Managementsysteme aufbauen. Nicht mit PowerPoint-Schlachten, sondern mit Menschlichkeit, einem klaren Prozess und einem eigenen Tool.

We are organizational experts that build management systems. Not with PowerPoint battles, but with humanity, a clear process and our own tool.

Benennung Appointment

Externer Informations­sicherheits- und Datenschutz­beauftragter External Information Security and Data Protection Officer

Als Mandat statt Festanstellung übernehmen wir die Rolle des Informationssicherheits- und des Datenschutzbeauftragten für Ihre Organisation. Wir führen die Managementsysteme, berichten an die Geschäftsleitung und sind Ansprechpartner für Behörden, Auditoren und Mitarbeitende. Die Pauschale richtet sich nach der Größe Ihrer Organisation. As a mandate instead of a permanent hire, we take on the role of information security officer and data protection officer for your organisation. We run the management systems, report to management and act as the point of contact for authorities, auditors and staff. The flat fee is based on the size of your organisation.

Gespräch vereinbaren Schedule a call →
  • Größenbasierte Flatrate – günstiger als Personal.
  • Kein Recruiting, keine Einarbeitung, keine Lohnnebenkosten.
  • Zwei zertifizierte Experten: Vertretung bei Ferien/Krankheit inklusive.
  • Kurzfristiger Start, auch als Überbrückung bis zur Besetzung.
  • Size-based flat rate – cheaper than staff.
  • No recruiting, no onboarding, no payroll costs.
  • Two certified experts: cover for holidays/sick leave included.
  • Quick start, also as a bridge until the position is filled.
Beratung Consulting

ISMS- / DSMS-Aufbau ISMS / DSMS Implementation

Die Erfüllung neuer Compliance-Anforderungen ist für Organisationen oft anspruchsvoll. Wir führen Ihr ISMS oder DSMS individuell ein – von der Gap-Analyse über die Risikoanalyse bis zur Zertifizierungsbegleitung. Workshops, Schulungen, Audit-Begleitung – alles aus einer Hand. Meeting new compliance requirements is often demanding for organisations. We implement your ISMS or DSMS individually – from gap analysis through risk assessment to certification support. Workshops, training, audit support – all from a single source.

  • Gap-Analyse & Implementierung
  • Risikoanalyse & -management
  • Workshops & Schulungen
  • Zertifizierungsbegleitung
  • Gap analysis & implementation
  • Risk analysis & management
  • Workshops & training
  • Certification support
Gespräch vereinbaren Schedule a call →
Kevin Gerber
Kevin Gerber LinkedIn
ISO/IEC 27001 Auditor APMG APMG ISO/IEC 27001 Auditor

Kevin hat als Gründer und Geschäftsführer in MedTech, Digital Health und Compliance-SaaS über ein Jahrzehnt Erfahrung darin, regulatorisch anspruchsvolle Produkte und Prozesse aufzubauen. Er weiß, wie interdisziplinäre Teams unter Compliance-Druck funktionieren – und wie man sie durch einen Zertifizierungsprozess führt, ohne den Betrieb zu lähmen. As a founder and CEO in MedTech, Digital Health and Compliance SaaS, Kevin has over a decade of experience building regulated products and processes. He knows how cross-functional teams operate under compliance pressure – and how to guide them through certification without paralysing operations.

Benjamin Luther
Benjamin Luther LinkedIn
ISO/IEC 27001 Lead Auditor & Implementer CBT CBT Cert

Als ehemaliger Profisportler und serieller Unternehmer hat Ben Unternehmen in Finance, Biotech, Digital Health und Commerce gegründet und geführt. Diese Breite an Branchen- und Führungserfahrung macht ihn zum idealen Sparringspartner für Geschäftsführer, die ein Managementsystem nicht nur einführen, sondern auch leben wollen. As a former professional athlete and serial entrepreneur, Ben has founded and led companies in finance, biotech, digital health and commerce. This breadth of industry and leadership experience makes him the ideal sparring partner for executives who want to not just implement a management system, but truly live it.

Bereit für Klarheit? Ready for clarity?

Unverbindliches Erstgespräch – wir analysieren Ihren Stand und zeigen Ihnen den kürzesten Weg zur Compliance. No-obligation initial consultation – we analyse where you stand and show you the shortest path to compliance.

Keine Cookies! No Cookies!

Diese Webseite sammelt nichts, bäckt nichts und lässt nichts bei dir. Deshalb gibt es auch nichts einzuwilligen. Mehr Datenschutz geht nicht. This website collects nothing, bakes nothing and leaves nothing behind. There’s nothing to consent to. Privacy doesn’t get better than this.