Skip to main content
Lukas Günther Teissl
Additional expertise · IT Security & Cyber Security

IT security as a transparent process — not an absolute promise.

I help companies identify technical and organisational risk, set priorities and implement practical controls. No system is “100% secure”; what matters is risk awareness, appropriate controls and the ability to respond.

The greatest risks often arise at the handovers.

Accounts, permissions, outdated systems, missing backups, unclear ownership and external services need to be assessed together. A single security tool does not create a resilient security structure.

Security is addressed through clear ownership, realistic threats and effective measures — not dramatic scare tactics.

Potential areas of focus

Potential areas of focus

Inventory & risk

Capture systems, data, access, dependencies and relevant threats.

Identity & access

Improve accounts, roles, MFA, password processes and least privilege.

Hardening & updates

Review configuration, patch status, unnecessary services and secure defaults.

Backup & recovery

Assess backup strategy, separation, testing and realistic recovery targets.

Logging & response

Make important events visible and define incident responsibilities.

Secure development

Consider input, sessions, access, secrets, error handling and deployment.

How I work

A clear process with transparent responsibilities.

Starting point

Capture objectives, existing documents, systems and stakeholders.

Review

Structure requirements, risks, gaps and open decisions.

Prioritise

Order next steps by relevance, dependencies and effort.

Coordinate

Separate my own work clearly from external specialist services.

Document

Record decisions, responsibilities and outcomes transparently.

Transparent scope

No absolute security and no unsupported certification claims

Security measures reduce risk but do not eliminate it. In-depth penetration testing, specialist forensics or formal certification may require additional independent specialists depending on the project.

Frequently asked questions

Frequently asked questions

Is everything secure after a review?

No. A credible security review identifies risk and improves controls but cannot guarantee absolute security.

Can existing web applications be reviewed?

Yes, within a clearly defined scope. Depending on depth, code review, configuration review or independent specialist testing may be appropriate.

What role do backups play?

Backups are central to resilience. It is not enough that copies exist; separation, retention, access protection and tested recovery also matter.

Does the review include employees?

Access, roles, phishing awareness, devices and offboarding processes can form part of the assessment.

Your enquiry

Briefly describe the current situation. A few concrete sentences are enough for an initial conversation.

Enter the characters shown in the image.

Your information will only be used to respond to your enquiry. The legal notice and terms apply.