Kiel · Schleswig-Holstein · Germany-wide Mon–Fri 9–17 CET
+49 15778716239 info@tsbsec.de

Security Audits & Compliance

ISO 27001, NIS2, GDPR, BSI IT-Grundschutz: we bring your security organisation to an auditable level.

Regulatory requirements keep growing – with the NIS2 directive now transposed into national law, many mid-sized companies are obliged to run systematic risk management. We analyse your current state, identify gaps against the relevant standards and guide you pragmatically through implementation. No paper tigers – measures that work in daily operations.

Who is this for?Companies in scope of NIS2, those needing ISO 27001 evidence for customers – or anyone who simply wants to know where they really stand.
Process

How we work together

1

Applicability & target

We clarify which requirements apply to you – NIS2, ISO 27001, GDPR, customer demands – and which level makes sense.

2

Gap analysis

Through interviews and document review we compare your current state with the requirements and rate every gap by risk.

3

Roadmap & implementation

You receive a prioritised action plan. On request we implement policies, processes and technical measures together with you.

4

Evidence & audit

We prepare you for external audits, support the certification process and keep the system current afterwards.

FAQ

Questions about this service

Do we need ISO 27001 certification or is aligning with the standard enough?

It depends on your customers and regulation. Many SMEs do well with a lean ISMS without a certificate; if you respond to tenders or must provide NIS2 evidence, certification pays off. We tell you honestly what is worth it.

How long does NIS2 implementation take?

Three to twelve months depending on your starting point. BSI registration and reporting processes can be set up quickly; risk management and supply-chain security take longer. We start with the measures that reduce the most risk.

Can you act as our information security officer?

Yes. As an external information security officer we run your ISMS on an ongoing basis, report to management and act as the contact for customers and auditors.

Let's talk about your needs.

In a free initial consultation we clarify scope, approach and cost – no obligation, on equal terms.

Book an initial consultation

Related services

Penetration Testing & Vulnerability Assessment

We attack your systems in a controlled way before criminals do – and show you exactly where action is needed.

Learn more

Managed Security & Monitoring

Around the clock: we monitor your systems, detect attacks early and respond before damage occurs.

Learn more

Incident Response & Digital Forensics

When it happens, every minute counts. We help with ransomware, data exfiltration and system compromise – fast and structured.

Learn more