We analyze your actual risk profile, prioritize the measures based on their impact and effort required, and stay with you until they are implemented.
Certified NIS2 Consultants · Focus on Implementation
In many companies, the steps that need to be taken have long been laid out in writing. Little has been implemented, however, because no one provided guidance and because everything seemed equally urgent.
An audit provides a snapshot. Without someone to oversee implementation, it remains just a document, and the gap remains unaddressed.
A list of thirty equally weighted items leads to a stalemate. What matters most are the three measures that make the biggest difference.
Who isolates which systems, and who decides where the fuses come from? If you don't determine this in advance, you'll end up making decisions under pressure—and usually the wrong ones.
We guide you from the initial analysis through to measurable improvement. This isn't a one-time project, but a process with defined milestones.
Assessment, comparison with requirements, and prioritization by criticality.
Implementation in accordance with ISO 27001, from guidelines to documentation.
Who takes action in an emergency, how communication takes place, and how the recovery process works.
Timeline, responsibilities, and regular progress tracking.
Three people who are on the move
outnumber thirty who are standing still.
That is why our work does not end with the submission of the report, but with the verified implementation.
We work in cycles: analyze, prioritize, implement, measure. Then the next cycle begins at a higher level.
We understand your IT environment, your industry, the applicable requirements, and the measures you’ve taken so far. No questionnaire—just a conversation.
We conduct a structured assessment of your situation against the standards that apply to you. The result is a clear overview of your vulnerabilities, ranked by criticality.
Not a list of forty items, but a sequence: what comes first, why, how much effort it requires, and what the impact will be. With assigned responsibilities and realistic deadlines.
We provide technical and organizational support—from management systems and emergency plans to individual configurations. We keep working until it works, not just until the report is finished.
Regular meetings track progress, identify new risks, and adjust the roadmap to reflect changing requirements.
The gap between a good recommendation and an actually improved security situation lies in implementation. We handle both.
Both managing directors hold the WKO incite certification and have already implemented NIS2 in Austrian companies.
Not a sixty-page report, but a proposal that your management can understand and act on in ten minutes.
Configurations, documentation, contingency plans: We support the implementation process rather than handing it back to your IT department.
Implementation in accordance with Austrian law, using the local administrative structures. No checklist translated from another legal jurisdiction.
For small and medium-sized businesses, typically with 20 or more employees, across all industries. Particularly useful for companies that are subject to NIS2 or are preparing for ISO 27001 certification.
That depends on the company's size, locations, the complexity of its IT infrastructure, and the applicable requirements. For smaller companies, this can usually be quoted as a fixed price. During the initial consultation, we'll provide a reliable estimate.
Fundamentally, an audit provides a snapshot and a report. We analyze, prioritize based on urgency, and support the implementation. The goal is not the document itself, but an improved situation.
Yes, both managing directors. We provide support in analyzing gaps, planning corrective actions, documenting findings, and preparing for an audit.
Yes, when setting up the management system: from analysis through policies and documentation to preparing for the audit. The certification audit itself is conducted by an accredited body, not by us.
Who takes what actions in the first few minutes and hours, which systems are immediately isolated, how internal and external communication is handled, how the recovery process proceeds, and which departments need to be notified. These procedures are documented in writing, discussed with all parties involved, and, if desired, simulated in a drill.
At least once a year, and whenever there are significant changes to the IT system. A plan that has never been rehearsed is not a plan. We recommend an annual tabletop exercise in which those responsible work through a simulated emergency scenario together.
Only a test under real-world conditions will show whether they can actually be used.
Talk to a certified NIS2 consultant about your situation. There’s no obligation—you’ll receive an assessment rather than a quote.
We use cookies to operate this website and analyze its usage. You decide which categories to allow. You can adjust your settings at any time.