NIS2 & Cybersecurity

IT security for your business –
without panic, with a plan.

The NIS2 directive and the Cyber Resilience Act set new requirements for small businesses. We show you what really matters – and how to implement it step by step.

Step by Step

Your roadmap to a secure business

Security is not a one-time project, but a continuous process. This 6-step plan sets you on the right path.

1. Inventory

What IT systems, data, and processes do you have? Who has access to what? A clear inventory is the foundation for everything else.

2. Risk Analysis

Which systems are critical? Where are the biggest vulnerabilities? A structured risk analysis shows where you need to act first.

3. Access Control & Passwords

Multi-factor authentication, secure password policies, and the principle of least privilege protect you against the most common entry point for attackers.

4. Backup & Emergency Plan

Regular backups following the 3-2-1 rule and a documented emergency plan are your insurance against ransomware and system failures.

5. Updates & Patch Management

Outdated software is the most common entry point for attackers. A systematic update process for all systems – including routers and IoT devices – closes known vulnerabilities.

6. Employee Awareness

Phishing is the most common way attackers get in. Regular training and clear procedures for emergencies are your most cost-effective security investment.

Self-Assessment

Where does your business stand?

Honestly check which of these points have already been implemented in your business. Every open point represents a need for action.

All accounts use multi-factor authentication (MFA)

Email, cloud services, VPN – everywhere sensitive data is accessible.

Daily backups are created automatically and tested regularly

A backup that has never been tested is not a backup.

Software and operating systems are updated promptly

Including routers, firewalls, and all networked devices.

Employees have been trained on phishing & IT security in the past year

One-time training isn't enough – attackers keep evolving.

An emergency plan exists for the event of an attack

Who gets notified? What gets shut down immediately? Where is the backup restore procedure documented?

Access rights follow the principle of least privilege

Each employee only has access to what they need for their role.

External service providers and suppliers with IT access have been vetted for security

Supply chain attacks are on the rise – your suppliers are also a risk.

Are there points where you're unsure or see gaps? We help you close them systematically.

Schedule a Security Check

What you want: peace of mind.

When your IT is secure, you no longer need to fear every email with a suspicious attachment, get frustrated about employee passwords, or break into a sweat over system failures on weekends. You can focus on your business – because someone is watching over your IT.

Security check for your business

We analyse your current IT situation and show you concretely where action is needed – and what truly matters for a business of your size.