Foundation

    Security and Resilience

    By Redaktion techport.ai, IT-Beratung · Last updated on

    The question is no longer whether a company will be attacked, but what happens when it is. In its Wirtschaftsschutz 2025 study, the German digital association Bitkom puts the annual damage to the German economy from data theft, espionage and sabotage at 289.2 billion euros, the largest share of it from cyber attacks. It is no longer only large corporations that are affected, but the supplier with eighty employees, because that is the easier route into the customer's network.

    Alongside this sits a set of obligations that has changed fundamentally in the last three years. Security has moved from a technical topic to a leadership topic, with personal responsibility for the management.

    Typical problems

    • It is unclear whether the company falls under the new obligations and nobody has checked it on the record.
    • There are backups but no successfully tested recovery.
    • Permissions have grown over years. Some former employees still have access.
    • The emergency plan sits as a file on the server that is encrypted in an emergency.
    • Security is treated as an IT task even though the liability sits with management.

    What we do in this field

    We check with you, on the record, which obligations apply to your company and derive concrete measures from that. We build an information security management system that fits the size of the organisation and can be certified if needed. We write emergency plans and rehearse them rather than filing them. We test whether backups can actually be restored. We put identities and access rights in order. And we train staff so that they do not click at the decisive moment.

    Topics in this field

    Häufige Fragen

    We are too small to be interesting. Is that true?

    No. Attacks are largely automated and look for reachable weaknesses, not for well known names. Smaller companies are additionally attractive as a route into larger customers, which is exactly why customers increasingly ask for evidence before awarding a contract.

    What is the most effective first step?

    A tested recovery. Anyone who has a backup that is demonstrably restorable and kept separate from the rest of the network survives the most common emergency. Right after that come multi-factor authentication on everything reachable from outside, and an orderly procedure for updates.

    Let us talk about your situation

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.