Penetration Testing & Vulnerability Assessment
We attack your systems in a controlled way before criminals do – and show you exactly where action is needed.
Learn moreTSBSec is your partner for cyber security and IT infrastructure in Kiel, Schleswig-Holstein and across Germany. We find vulnerabilities before attackers do – and keep your systems, data and people protected.
From the first analysis to ongoing operations: we cover the entire security lifecycle – as individual modules or as a complete package.
We attack your systems in a controlled way before criminals do – and show you exactly where action is needed.
Learn moreISO 27001, NIS2, GDPR, BSI IT-Grundschutz: we bring your security organisation to an auditable level.
Learn moreAround the clock: we monitor your systems, detect attacks early and respond before damage occurs.
Learn moreWhen it happens, every minute counts. We help with ransomware, data exfiltration and system compromise – fast and structured.
Learn moreMost successful attacks start with people. We turn your team into your strongest line of defence.
Learn moreSecure networks, hardened servers, protected cloud: we build and run the IT you can rely on.
Learn moreWith ransomware, data exfiltration or suspicious access, every hour counts. Contact us immediately – we prioritise your request and support containment, analysis and recovery.
We believe good IT security is not wizardry but craftsmanship: careful, traceable and tailored to your reality.
We explain risks so you can make decisions – with clear priorities instead of 200-page reports.
Not every company needs a fortress. We recommend what really protects you – and tell you what you can skip.
You have a dedicated contact who knows your business and is reachable when it matters.
We do not sell products, we deliver solutions. Our recommendations are based on your needs, not on commissions.
We get to know your business, your systems and your risks – free of charge and without obligation.
You receive a prioritised action plan with a transparent quote. No surprises.
We implement the measures – coordinated with your team and with minimal disruption to daily operations.
Security stays. We monitor, review and adapt whenever your business or the threat landscape changes.
With the NIS2 directive transposed into German law, far more companies than before are obliged to implement risk management, incident reporting and evidence of compliance – in affected sectors often from 50 employees or EUR 10 million in turnover. Management is personally responsible for implementation.
Two minutes, no sign-up – the assessment runs in your browser.
From craft businesses to logistics companies: we speak the language of the Mittelstand.
Our approach follows established frameworks – so results are comparable, traceable and usable for audits.
Practical articles on NIS2, phishing, emergency planning and secure cloud configuration – for management and IT.
The German NIS2 implementation act has applied since December 2025. Which companies qualify as important or essential entities, what the obligations are and where to start.
Read moreMost successful attacks start with an e-mail. Seven signs that help employees recognise phishing – and what to do when in doubt.
Read moreRansomware rarely strikes at a convenient time. A two-page emergency plan, clear roles and the right first steps decide between days and weeks of downtime.
Read moreOur focus is on small and mid-sized companies with roughly 10 to 500 employees – from craft businesses to logistics companies. We also serve municipalities, law firms and medical practices. What matters is not size, but that you want to take IT security seriously.
It depends on scope: a focused test of a single web application costs considerably less than testing the entire infrastructure. After a short initial call you receive a transparent quote with a clearly defined scope – no hidden costs.
If your company falls into one of the affected sectors and meets the thresholds: yes. Implementation usually takes several months. In a short call we check whether and how you are affected – free of charge.
Both. Penetration tests, audits and managed security are mostly delivered remotely. For workshops, training and infrastructure projects we are happy to come to you in Schleswig-Holstein and Hamburg.
Requests with the subject "URGENT" are handled immediately. During an ongoing attack you receive first recommendations right away so that no further damage occurs. An incident response retainer gives you guaranteed response times.
In about 30 minutes we clarify your situation, your biggest risks and the sensible next step. You get an honest assessment – even if it is that you currently need nothing.