Skip to main content
Lukas Günther Teissl
IT Security & Cyber Security

Identify risks. Prioritise measures. Improve security sustainably.

I help companies assess technical and organisational risks systematically, harden access and systems, and improve response capability – pragmatically, transparently and in proportion to the actual risk situation.

Risk-based Technical + organisational Clearly documented
Understand the security situation

The greatest risks often arise at the interfaces.

Accounts, permissions, outdated systems, missing backups, unclear ownership and external services need to be assessed together. A single security tool does not create a resilient security structure.

Holistic perspective

Technical safeguards work best when processes, roles and recovery are as clearly defined as systems and access.

Potential areas of focus

From access to recovery: security as an integrated system.

The exact scope depends on your starting point. The following areas show which topics are typically considered together.

Inventory & risk

Capture systems, data, access, dependencies and relevant threats in a structured way.

Identity & access

Improve accounts, roles, MFA, password processes and least-privilege access transparently.

Hardening & updates

Review configuration, patch status, unnecessary services and secure defaults.

Backup & recovery

Review backup strategy, separation, protection and realistic recovery tests.

Logging & response

Make important events visible and define clear responsibilities for incidents.

Secure development

Consider input, sessions, access, secrets, error handling and deployment.

How I work

A clear process instead of security actionism.

The goal is not to generate as many measures as possible, but to make the right risks visible and implement improvements in a sensible order.

01

Understand the starting point

Systems, access, data, processes and dependencies are captured so that the actual risk situation becomes visible.

02

Classify risks

Not every weakness is equally critical. Relevance, likelihood and potential impact are prioritised sensibly.

03

Prioritise measures

Technical and organisational steps are put into a realistic order based on impact, effort and dependencies.

04

Support implementation

Suitable measures are implemented in practice, documented and reviewed where follow-up checks are useful.

Technology + organisation

Security problems are rarely purely technical.

A well-configured system helps little if permissions are unclear, backups are never tested or no one knows who makes decisions during an incident. That is why technical and organisational aspects are considered together.

Discuss the starting point
Technical layer
  • Identities, roles and MFA
  • System hardening and patch status
  • Backup, separation and recovery
  • Logging, secure development and deployment
Organisational layer
  • Clear responsibilities
  • Access and offboarding processes
  • Incident response paths
  • External services and dependencies
Transparent scope

No claims of absolute security and no unsupported certification promises.

Security measures reduce risk but do not eliminate it. In-depth penetration testing, specialist forensics or formal certification may require additional independent specialists depending on the project.

Frequently asked questions

What a serious security review can achieve.

Is everything secure after a review?

No. A credible security review identifies risk and improves controls but cannot guarantee absolute security.

Can existing web applications be reviewed?

Yes, within a clearly defined scope. Depending on depth, code review, configuration review or independent specialist testing may be appropriate.

What role do backups play?

Backups are central to resilience. It is not enough that copies exist; separation, retention, access protection and tested recovery also matter.

Is the organisational side also reviewed?

Yes. Access, roles, devices, offboarding, responsibilities and response paths can be just as important as technical safeguards.

Your enquiry

Briefly describe the current situation. A few concrete sentences are enough for an initial conversation.

Enter the characters shown in the image.

Your information will only be used to respond to your enquiry. The legal notice and terms apply.