• Training on IT and information security
• Awareness of cyber risks
• Phishing and social engineering training
• Strengthening the security culture
• Regular learning campaigns
• Review of existing ISMS procedures and structures
• Comparing the existing management system with ISO 27001 / TISAX / KRITIS / B3S / NIS2 / DORA requirements
• Assessing the adequacy and effectiveness of technical and
• Documentation and audit report
• Recommending and prioritizing measures
• Detailed management report
(information security management system)
• Setting up / optimizing an information security management system
• According to ISO 27001, BSI IT-Grundschutz
• Reviewing suitable tool support for an integrated view of IT structure, processes, assets, risks, measures, reporting and document control
• Defining the scope (Statement of Applicability, SoA)
• Defining roles, processes and policies
• Integration into existing structures
• Implementing technical and organizational measures
• Coordinating certification by an accredited certification body
• Support during the certification audit and remediation of nonconformities
• Realistic attack simulations
• Analysis of system and network vulnerabilities
• Assessing the security posture
• Recommendations for protection
• Retest to verify effectiveness
• blu-Securitycheck
• Identifying and assessing risks
• Planning risk reduction measures
• Maintaining a risk register according to NIS2
• Regular review and adjustment
• Integration into the management system
• Gathering requirements from ISMS, BCM and compliance
• Market overview, vendor comparison and recommendation
• Designing the data model, roles and workflows
• Rollout, migration of existing content and training
• Support through to production
blu-Securitycheck
Identifiziere Schwachstellen und erhalte konkrete Handlungsempfehlungen für mehr IT-Sicherheit.