Complete IT Renewal with Security by Design
Comprehensive IT modernization with a focus on ransomware resilience, Zero Trust, and Modern Workplace.
Arrange a call
- Company size
- SME
- Region
- Germany
- Industry
- Manufacturing
- Project duration
- ongoing since January 2025
phishing-resistant login with FIDO2/YubiKeys
Level 1 across all servers & clients, Level 2 for critical systems
The challenge
Our client faced a comprehensive renewal of their IT – with the clear goal of increasing resilience against ransomware, consistently implementing security standards, and at the same time establishing a modern, centrally managed device and identity strategy. For a manufacturing company, ransomware is the central operational risk: attackers increasingly target the backups themselves, move laterally through the network, and take over accounts via compromised passwords. The new IT had to address these attack paths from the ground up — from the backup architecture and network segmentation to authentication. At the same time, endpoint management was to be modernized: standardized, automatically provisioned devices instead of manual one-off installations, a uniform and auditable hardening standard for servers and clients, and end-to-end detection and response capability across the entire environment.
Inside the rollout
Immutable Veeam Backup as an additional protective layer against backup manipulation and ransomware attacks. Network segregation of critical systems using micro-segmentation, including definition of necessary ports/communication paths ("Least Privilege" at the network level). Modern Workplace with Microsoft Intune: MDM rollout and device standardization, Autopilot for automated provisioning of new devices, Company Portal for software deployment and self-service. CIS Benchmark Hardening: Level 1 for Servers & Clients as a comprehensive baseline, Level 2 for critical systems with increased protection needs. Introduction of passwordless authentication (FIDO2) with YubiKeys to significantly reduce password-based risks. Implementation of CrowdStrike Complete for Managed EDR, Microsoft Defender for Identity (MDI) to detect AD attacks, and Wazuh as a SIEM solution.
The implemented measures significantly increased resilience against ransomware - in particular through immutable backups and consistent segmentation. A uniform, auditable security standard was established through the widespread application of the CIS Benchmarks. Endpoint management was modernized and enables automated provisioning. Passwordless login via FIDO2/YubiKeys substantially increases identity security. With the central security database (SIEM) as well as EDR and MDI, end-to-end detection and response capabilities are available.
„Ransomware resilience does not come from a product — but from layers: immutable backups, segmented networks, phishing-resistant identities.“
Results at a glance
- Passwordless authentication
- 100 %
- phishing-resistant login with FIDO2/YubiKeys
- CIS Benchmark hardening
- Two levels
- Level 1 across all servers & clients, Level 2 for critical systems
- Detection layers
- Three systems
- CrowdStrike EDR, Defender for Identity, and Wazuh SIEM
Security by Design
Learnings
- Immutable backups are the last line of defense — they belong at the beginning of every ransomware strategy, not at the end.
- Micro-segmentation means least privilege at the network level: critical systems communicate only via defined ports and communication paths.
- Passwordless authentication with FIDO2/YubiKeys is practicable in the mid-market — and reduces password-based risks more effectively than any password policy.
- CIS Benchmarks make security auditable: Level 1 as a comprehensive baseline, Level 2 specifically for critical systems.
What's next
The project has been ongoing since January 2025. With EDR, Microsoft Defender for Identity, and Wazuh SIEM, end-to-end detection and response capability is in place and is now being sharpened in day-to-day operations — from evaluating the central security data basis to the continuous maintenance of the CIS baselines. New devices enter the managed environment fully automatically via Autopilot. The established security standard thus scales with the company without creating additional manual effort.
Service: Implementation & Migration
Ready for your Customer Story?
Let's make your next project a success together. Contact us for a non-binding initial consultation.