We take on what we can actually do.
Cloud environments on AWS and Azure, identity, cyber governance. If your need sits outside that, we say so early and point you to someone better suited. The restriction is the reason we have depth in these fields.
A boutique consultancy that sits across from management as an equal and restricts itself to a few fields — cloud, identity, governance, programme and project leadership. We do not merely describe security there, we own and deliver it. The incident should never happen; if it does, management knows whom to call. Secureskies takes on few engagements and clients at a time — each with a senior owner from the first conversation to the handover.
Not a mission statement — three rules for how we scope, staff and end an engagement. We state them in every first conversation, not least because they sometimes mean we decline.
Cloud environments on AWS and Azure, identity, cyber governance. If your need sits outside that, we say so early and point you to someone better suited. The restriction is the reason we have depth in these fields.
Anyone brought in has to take effect where the work is stuck — in the project team, in the stream, in the steering committee. Whoever holds the first conversation leads the engagement and is back at the table for the handover. That is why we take on few engagements and clients at a time.
We were brought in so that something runs differently than it would without us: a decision gets made, a cutover holds, a programme succeeds, engineering and delivery know-how is added. Our measure is the result that stays with you.

Henning Schulze has worked in IT infrastructure since 2009 — after qualifying as an IT specialist in systems integration, first as a systems engineer and lead architect at a Hamburg IT systems house, for Citrix environments serving more than 3,000 users: VDI, SSO, terminal services.
Programme responsibility followed from 2012: at Panasonic Europe the M&A integration of three automotive subsidiaries across EMEA — a €3.7m budget, 12–18 FTE, 3,000 endpoints, coordination between Hamburg and Osaka. Then a new data centre with full migration of 150 physical servers and 900 VMs in 14 months and a greenfield infrastructure in the Middle East in nine months; the Open University MBA in parallel. From 2017 at Hamburg’s largest e-commerce company the large infrastructure and security programmes: the incident remediation after a cyber attack across more than 1,000 servers with a €4m budget, 30+ FTE, six streams and the krbtgt reset, the O365 rollout for 7,000 users and the Microsoft 365 pilot for the group with a decision paper for the board.
From 2021 to 2025 at Rackspace Germany: AWS insourcing for a top-5 container shipping line with 73 production workloads, building the AWS operations team in India with 23 roles and 600+ hours of knowledge transfer; multi-cloud security for private banks and a lottery with PKI, security dashboard and IR playbooks. Since 2026, programme lead for the global AD consolidation at a world market leader in construction machinery — alongside managing Secureskies GmbH.
Secureskies GmbH was founded in 2023 to offer clients and partners technical expertise and leadership capability in large programmes and projects. Those positions built the Hamburg network of mid-sized companies, auditors and private banks that Secureskies works with today.
At Hamburg’s largest e-commerce company we saw what an active compromise does to a company — and what management is missing in that moment.
More than 1,000 servers were affected. Remediation ran fifteen months, across six streams with over thirty people: Active Directory secured on the ESAE tiering model, privileged access workstations for every domain admin, 300 DMZ servers hardened, 600 mailboxes moved to the cloud, and finally the krbtgt reset against golden and silver tickets — the moment where one mistake would have reopened the entire infrastructure.
The technical questions were solvable. The rest was harder. Who explains to the board which risk is still open today? Who decides which stream takes priority when operations and security contradict each other? Who keeps providers, insurers, regulators and your own organisation pointed the same way? That was no longer an engineering task. That was leadership under uncertainty.
That is where Secureskies GmbH came from. A boutique consultancy that sits across from management as an equal, restricts itself to the fields where it makes the difference and delivers value — cloud, identity, governance, programme and project leadership — and does not merely describe security there but owns and delivers it. The incident should never happen. If it does, management should know whom to call.
Hardening of 1,000+ servers, AD security on the ESAE tiering model, PAW rollout, Exchange migration and execution of the krbtgt reset. Six streams, reporting line to VP, CISO, CIO, CDO.
Complete transition of externally operated AWS workloads into an in-house operating model: governance framework, 73 production workloads, AWS operations team built in India with 23 roles, 600+ hours of structured knowledge transfer.
PKI architecture, security metrics for management dashboards, incident response playbooks and migration from data centre to cloud across AWS and Azure.
Programme leadership for the migration and consolidation of the global AD domains and for building a new high-security network for development. Governance, steering committee, risk control, international rollout.
Post-merger IT integration: 3,000 endpoints, VoIP for 1,200 users, VPN harmonisation for 2,500 users. Coordination between Hamburg and Osaka.