Skip to content

Security check · MFA · Firewall · SIEM · Backup 3-2-1 · Hardening

IT Security

Firewall, two-factor authentication, backups with restore testing and phishing protection, suited to everyday work.

Labeled fiber optic cables on a patch panel in a server room

Security that fits your business

Most incidents at companies are not targeted attacks, but an opened phishing email, a forgotten default login, or a backup that couldn't actually be restored when it mattered.

I set up the fundamentals that make the difference, and explain what each measure does. Legal advice, for example on the GDPR, isn't part of this; for that I refer you to a law firm or a data protection officer.

Why now?

According to the Bitkom study Wirtschaftsschutz 2026, 87 percent of companies surveyed were affected by attacks; attackers are using AI to craft convincingly realistic phishing emails. Since December 2025, the NIS2UmsuCG (NIS2 Implementation Act) has also been in force, and large clients pass its requirements down to suppliers by contract.

Sources: Bitkom, Wirtschaftsschutz 2026; NIS2UmsuCG, in force since 06.12.2025.

Service

What I set up

Firewall and network
Firewall configuration, separating guest Wi-Fi, office devices and servers, VPN for home office and field staff.
Access control
Roles and permissions based on least privilege, two-factor authentication for email and remote access, a password manager for the team.
Backup strategy
Separate copies, with at least one off-site or offline, and regular restore tests. A backup only counts once it has been restored.
Phishing protection
SPF, DKIM and DMARC for your domain, spam and attachment filtering, a short team briefing with real examples.
Updates and hardening
Security updates in fixed maintenance windows, disabling unnecessary services, replacing default passwords, securing remote access.
GDPR-related technical measures
Encryption of laptops and backups, logging, technical implementation of deletion periods. No legal advice: legal questions are handled by your law firm or data protection officer.
Security check with a traffic-light report
Access credentials, updates, backups, email, network and services visible from outside. Results as a risk-ranked list, in plain language.
Monitoring and alerts
Login attempts, brute-force attacks on remote access and suspicious changes are detected, blocked automatically and reported to your phone.
Evidence for clients
When a larger client asks questions about your IT security, for example as part of NIS2 supply-chain requirements, I prepare the technical answers and supporting evidence. Technical implementation, not legal advice.
One-page emergency plan
Who gets called, what gets shut down first, where the backup is. Printed and within reach, not just stored on the server that just failed.

Process

How it works

  1. Security check

    I check access credentials, updates, backups, email settings and the network, and record the results in a risk-ranked list.

  2. Action plan

    You receive the list with a recommendation on what to tackle first, what it costs and what you can do yourself.

  3. Implementation

    Step by step, without disrupting your business. Every change is documented and explained to the team.

  4. Regular review

    Security isn't a one-time state. With a maintenance flat fee, I keep checking the important points on an ongoing basis.

Who it's for

Who this is for

  • Businesses that process customer, patient or client data
  • Companies with home-office workstations and remote access
  • Owners who want clarity after an incident or a wave of phishing emails
  • Companies whose insurer or clients require minimum technical measures

IT Security

Frequently asked questions

Do you know whether your backup can actually be restored?

In the initial consultation, we go through the five points most often missing at companies. 30 minutes, free of charge.