Cybersecurity › Consulting & Risk Management
Consulting & Risk Management

A strategy that doesn'tend up in a drawer
.

We analyze your actual risk profile, prioritize the measures based on their impact and effort required, and stay with you until they are implemented.

Certified NIS2 Consultants · Focus on Implementation

The Problem

The report is in the cabinet.
The gaps are still there.

In many companies, the steps that need to be taken have long been laid out in writing. Little has been implemented, however, because no one provided guidance and because everything seemed equally urgent.

A recommendation is not the same as implementation

An audit provides a snapshot. Without someone to oversee implementation, it remains just a document, and the gap remains unaddressed.

If everything is critical,
, then nothing is critical

A list of thirty equally weighted items leads to a stalemate. What matters most are the three measures that make the biggest difference.

In an emergency, there is no plan

Who isolates which systems, and who decides where the fuses come from? If you don't determine this in advance, you'll end up making decisions under pressure—and usually the wrong ones.

Services

From the initial assessment
to a well-rehearsed emergency plan.

We guide you from the initial analysis through to measurable improvement. This isn't a one-time project, but a process with defined milestones.

Risk Analysis

Assessment, comparison with requirements, and prioritization by criticality.

Management System

Implementation in accordance with ISO 27001, from guidelines to documentation.

Emergency Planning

Who takes action in an emergency, how communication takes place, and how the recovery process works.

Implementation Support

Timeline, responsibilities, and regular progress tracking.

Analysis
  • Assessment of Existing Infrastructure
  • Verification against the requirements that apply to you
  • Threat Landscape for Your Industry and Company Size
Strategy
  • Measures Sorted by Impact and Effort
  • Roadmap with Clear Responsibilities
  • Budget and Capacity Planning
Implementation
  • Support with technical implementation
  • Regular Review of Progress
  • Documentation as evidence for auditors

Three people who are on the move
outnumber thirty who are standing still.

That is why our work does not end with the submission of the report, but with the verified implementation.

Procedure

From the initial consultation
to measurable improvement.

We work in cycles: analyze, prioritize, implement, measure. Then the next cycle begins at a higher level.

Initial Consultation and Assessment

We understand your IT environment, your industry, the applicable requirements, and the measures you’ve taken so far. No questionnaire—just a conversation.

1–2 hours

Risk Analysis

We conduct a structured assessment of your situation against the standards that apply to you. The result is a clear overview of your vulnerabilities, ranked by criticality.

1–2 weeks

Action Plan

Not a list of forty items, but a sequence: what comes first, why, how much effort it requires, and what the impact will be. With assigned responsibilities and realistic deadlines.

1 week

Implementation Support

We provide technical and organizational support—from management systems and emergency plans to individual configurations. We keep working until it works, not just until the report is finished.

by scope

Review and Further Development

Regular meetings track progress, identify new risks, and adjust the roadmap to reflect changing requirements.

quarterly
Why ITanic

Consulting that doesn't end
once the report is delivered.

The gap between a good recommendation and an actually improved security situation lies in implementation. We handle both.

Certified NIS2 Consultants

Both managing directors hold the WKO incite certification and have already implemented NIS2 in Austrian companies.

A Basis for Decision-Making Instead of File Folders

Not a sixty-page report, but a proposal that your management can understand and act on in ten minutes.

Results Instead of Recommendations

Configurations, documentation, contingency plans: We support the implementation process rather than handing it back to your IT department.

Austrian Context

Implementation in accordance with Austrian law, using the local administrative structures. No checklist translated from another legal jurisdiction.

Frequently Asked Questions

What companies want to know beforehand.

What size of company is this consulting service intended for?

For small and medium-sized businesses, typically with 20 or more employees, across all industries. Particularly useful for companies that are subject to NIS2 or are preparing for ISO 27001 certification.

How much does a risk analysis cost?

That depends on the company's size, locations, the complexity of its IT infrastructure, and the applicable requirements. For smaller companies, this can usually be quoted as a fixed price. During the initial consultation, we'll provide a reliable estimate.

How is this different from an IT audit?

Fundamentally, an audit provides a snapshot and a report. We analyze, prioritize based on urgency, and support the implementation. The goal is not the document itself, but an improved situation.

Are you really certified NIS2 consultants?

Yes, both managing directors. We provide support in analyzing gaps, planning corrective actions, documenting findings, and preparing for an audit.

Do you also provide assistance with ISO 27001 certification?

Yes, when setting up the management system: from analysis through policies and documentation to preparing for the audit. The certification audit itself is conducted by an accredited body, not by us.

What does a ransomware emergency plan include?

Who takes what actions in the first few minutes and hours, which systems are immediately isolated, how internal and external communication is handled, how the recovery process proceeds, and which departments need to be notified. These procedures are documented in writing, discussed with all parties involved, and, if desired, simulated in a drill.

How often should the emergency plan be reviewed?

At least once a year, and whenever there are significant changes to the IT system. A plan that has never been rehearsed is not a plan. We recommend an annual tabletop exercise in which those responsible work through a simulated emergency scenario together.

Understanding the risks is the first step.

Only a test under real-world conditions will show whether they can actually be used.

View security tests

Know what to do.
And actually do it.

Talk to a certified NIS2 consultant about your situation. There’s no obligation—you’ll receive an assessment rather than a quote.

Free and with no obligationCertified NIS2 consultantsConsulting and implementation from a single source