Four pillars of
cyber security.
Security is not a product but a sequence: first know what needs protecting, then assess, then harden, then practise for what happens when it happens anyway. Our cyber security services follow that sequence — each available on its own, each with defined outcomes.
Define first,
then respond.
The four pillars build on each other. Assess without a target picture and you get a list with no order. Harden without assessing and you harden the wrong thing. Respond without having practised and you lose the hours that notification deadlines are made of.
Design:
what comes first.
Build the security programme, the strategy and the capabilities — before tools are bought.
Strategy & Roadmap Development
From the risk picture to the order of actions.
Read the service →DesignProgramme & Capability Development
Turning a roadmap into a working programme.
Read the service →DesignATT&CK Assessments
Assess your defences from the attacker’s point of view.
Read the service →DesignMicrosoft DLP Engineering
Set up Purview so that it protects without getting in the way.
Read the service →Evaluate:
where it is open.
Find the weaknesses, attack paths and unmet obligations before an attacker or an auditor does.
NIS2 Maturity Assessment
An assessment against the duties of the German NIS2 implementation act.
Read the service →EvaluateDORA Preparation
For financial entities and their ICT service providers.
Read the service →EvaluateKRITIS §8a BSIG
Preparing and supporting the evidence submission for operators of critical infrastructure.
Read the service →EvaluateMicrosoft Cloud Security Assessment
Microsoft 365, Entra ID and Azure reviewed as one system.
Read the service →EvaluateISO 27001
Gap analysis, ISMS build, support through to the audit.
Read the service →EvaluateEU Cloud & AI Act Readiness
Cloud switching rights, sovereignty tiers and AI duties in one picture.
Read the service →EvaluatePenetration Testing
Not just finding issues — showing what an attacker can do with them.
Read the service →EvaluateArchitecture Assessments
Whether the design holds — before it is built, or before it breaks.
Read the service →Harden:
close the open.
Configure identity, Microsoft cloud and servers so that known attack techniques lead nowhere.
Active Directory Security Assessment
Review the identity backbone before an attacker takes it over.
Read the service →HardenMicrosoft 365 Hardening Review
Configure the tenant the way Microsoft does not ship it.
Read the service →HardenMicrosoft Cloud Hardening Review
Azure subscriptions and Entra ID hardened against known attack paths.
Read the service →HardenHardening & Remediation Services
Closing findings with engineering, not with another list.
Read the service →Respond:
when it happens.
Contain incidents, preserve evidence, meet notification deadlines — and have the organisation practise beforehand.
Incident Response & Computer Forensics
Contain, investigate, recover — with evidence that holds up.
Read the service →RespondThreat Hunting
Actively looking for what your alerts never raised.
Read the service →RespondPlaybook Development
So that nobody has to improvise in an incident.
Read the service →RespondTabletop Exercises
Play the crisis through while it is still an exercise.
Read the service →