Do we really need Zero Trust?
If your employees work remotely, use cloud services, or process sensitive data: yes. Zero Trust is not a trend, but the answer to a changed threat landscape.
Answers on NIS2 compliance, critical infrastructure protection, BSI Grundschutz, ISO 27001, Zero Trust architecture, Microsoft Defender and SOC build-up across DACH.
If your employees work remotely, use cloud services, or process sensitive data: yes. Zero Trust is not a trend, but the answer to a changed threat landscape.
Yes, we accompany you from the gap analysis through implementation to audit preparation. Many of our clients have successfully certified with our support.
If you use our Managed Security Services, we react immediately. We analyze the incident, contain it, and support you in recovery. For everyone else, we offer incident response on demand.
NIS2 covers entities in 18 defined sectors (energy, health, finance, transport, digital services and others). Under section 28 BSIG: particularly important entities from 250 employees or more than EUR 50 million turnover plus more than EUR 43 million balance sheet total; important entities from 50 employees or with turnover and balance sheet total each above EUR 10 million. Suppliers and service providers may be affected indirectly through the supply chain. In Germany the directive is implemented through the NIS2UmsuCG, in force since 6 December 2025.
The German NIS2 implementation act (in force since 6 December 2025) provides for fines of up to €10 million — or up to 2% of total turnover where turnover exceeds €500 million — for particularly important entities, and up to €7 million or 1.4% for important entities. Management additionally bears a statutory duty to approve and supervise the risk-management measures and is liable for breaching it.
A complete NIS2 compliance program typically takes 6–12 months: gap analysis 3–4 weeks, prioritized quick wins 2–3 months, structural measures (governance, risk management, incident response, supply chain security) 4–9 months. We focus first on the largest compliance gaps.
Classical security relies on perimeter protection: everything inside the internal network is considered trustworthy. Zero Trust reverses this principle — every access is verified, regardless of location. Based on identity, device state and context. Particularly important for remote work, cloud services and SaaS — where the classical perimeter no longer exists.
Managed Services are proactive: we monitor, optimize, and act before problems arise. Classic support only reacts when something is broken. This saves you downtime and stress.
Our response times are defined in the contract and depend on the criticality. We respond to critical incidents within minutes, not hours.
No, we complement it. Managed Services relieve your team of routine tasks so they can focus on strategic issues. We work as an extension of your team.