Inventory & risk
Capture systems, data, access, dependencies and relevant threats in a structured way.
I help companies assess technical and organisational risks systematically, harden access and systems, and improve response capability – pragmatically, transparently and in proportion to the actual risk situation.
Accounts, permissions, outdated systems, missing backups, unclear ownership and external services need to be assessed together. A single security tool does not create a resilient security structure.
Technical safeguards work best when processes, roles and recovery are as clearly defined as systems and access.
The exact scope depends on your starting point. The following areas show which topics are typically considered together.
Capture systems, data, access, dependencies and relevant threats in a structured way.
Improve accounts, roles, MFA, password processes and least-privilege access transparently.
Review configuration, patch status, unnecessary services and secure defaults.
Review backup strategy, separation, protection and realistic recovery tests.
Make important events visible and define clear responsibilities for incidents.
Consider input, sessions, access, secrets, error handling and deployment.
The goal is not to generate as many measures as possible, but to make the right risks visible and implement improvements in a sensible order.
Systems, access, data, processes and dependencies are captured so that the actual risk situation becomes visible.
Not every weakness is equally critical. Relevance, likelihood and potential impact are prioritised sensibly.
Technical and organisational steps are put into a realistic order based on impact, effort and dependencies.
Suitable measures are implemented in practice, documented and reviewed where follow-up checks are useful.
A well-configured system helps little if permissions are unclear, backups are never tested or no one knows who makes decisions during an incident. That is why technical and organisational aspects are considered together.
Discuss the starting pointSecurity measures reduce risk but do not eliminate it. In-depth penetration testing, specialist forensics or formal certification may require additional independent specialists depending on the project.
No. A credible security review identifies risk and improves controls but cannot guarantee absolute security.
Yes, within a clearly defined scope. Depending on depth, code review, configuration review or independent specialist testing may be appropriate.
Backups are central to resilience. It is not enough that copies exist; separation, retention, access protection and tested recovery also matter.
Yes. Access, roles, devices, offboarding, responsibilities and response paths can be just as important as technical safeguards.
Briefly describe the current situation. A few concrete sentences are enough for an initial conversation.