Comprehensive IT modernization with a focus on ransomware resilience, Zero Trust, and Modern Workplace.
Arrange a call
phishing-resistant login with FIDO2/YubiKeys
Level 1 across all servers & clients, Level 2 for critical systems
Our client faced a comprehensive renewal of their IT – with the clear goal of increasing resilience against ransomware, consistently implementing security standards, and at the same time establishing a modern, centrally managed device and identity strategy. For a manufacturing company, ransomware is the central operational risk: attackers increasingly target the backups themselves, move laterally through the network, and take over accounts via compromised passwords. The new IT had to address these attack paths from the ground up — from the backup architecture and network segmentation to authentication. At the same time, endpoint management was to be modernized: standardized, automatically provisioned devices instead of manual one-off installations, a uniform and auditable hardening standard for servers and clients, and end-to-end detection and response capability across the entire environment.
Immutable Veeam Backup as an additional protective layer against backup manipulation and ransomware attacks. Network segregation of critical systems using micro-segmentation, including definition of necessary ports/communication paths ("Least Privilege" at the network level). Modern Workplace with Microsoft Intune: MDM rollout and device standardization, Autopilot for automated provisioning of new devices, Company Portal for software deployment and self-service. CIS Benchmark Hardening: Level 1 for Servers & Clients as a comprehensive baseline, Level 2 for critical systems with increased protection needs. Introduction of passwordless authentication (FIDO2) with YubiKeys to significantly reduce password-based risks. Implementation of CrowdStrike Complete for Managed EDR, Microsoft Defender for Identity (MDI) to detect AD attacks, and Wazuh as a SIEM solution.
The implemented measures significantly increased resilience against ransomware - in particular through immutable backups and consistent segmentation. A uniform, auditable security standard was established through the widespread application of the CIS Benchmarks. Endpoint management was modernized and enables automated provisioning. Passwordless login via FIDO2/YubiKeys substantially increases identity security. With the central security database (SIEM) as well as EDR and MDI, end-to-end detection and response capabilities are available.
„Ransomware resilience does not come from a product — but from layers: immutable backups, segmented networks, phishing-resistant identities.“
Security by Design
The project has been ongoing since January 2025. With EDR, Microsoft Defender for Identity, and Wazuh SIEM, end-to-end detection and response capability is in place and is now being sharpened in day-to-day operations — from evaluating the central security data basis to the continuous maintenance of the CIS baselines. New devices enter the managed environment fully automatically via Autopilot. The established security standard thus scales with the company without creating additional manual effort.
Service: Implementation & Migration
Let's make your next project a success together. Contact us for a non-binding initial consultation.