# NIS2, ISMS, business continuity, backup, identity and awareness: IT security for mid-sized companies

> Establish NIS2 scope, build information security, rehearse emergencies, prove recovery, order access rights and train staff. Security that holds when it matters.

URL: https://techport.ai/en/it-beratung/sicherheit-und-resilienz

---

1.  [IT Consulting](/en/it-beratung)/
2.  Security and Resilience

Foundation

# Security and Resilience

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

The question is no longer whether a company will be attacked, but what happens when it is. In its Wirtschaftsschutz 2025 study, the German digital association Bitkom puts the annual damage to the German economy from data theft, espionage and sabotage at 289.2 billion euros, the largest share of it from cyber attacks. It is no longer only large corporations that are affected, but the supplier with eighty employees, because that is the easier route into the customer's network.

Alongside this sits a set of obligations that has changed fundamentally in the last three years. Security has moved from a technical topic to a leadership topic, with personal responsibility for the management.

## Typical problems

*   It is unclear whether the company falls under the new obligations and nobody has checked it on the record.
*   There are backups but no successfully tested recovery.
*   Permissions have grown over years. Some former employees still have access.
*   The emergency plan sits as a file on the server that is encrypted in an emergency.
*   Security is treated as an IT task even though the liability sits with management.

## What we do in this field

We check with you, on the record, which obligations apply to your company and derive concrete measures from that. We build an information security management system that fits the size of the organisation and can be certified if needed. We write emergency plans and rehearse them rather than filing them. We test whether backups can actually be restored. We put identities and access rights in order. And we train staff so that they do not click at the decisive moment.

## Topics in this field

[Training and awarenessHow awareness works instead of annoying: show real attack patterns, train short and often, build a reporting culture, involve managers and make the effect measurable.](/en/it-beratung/sicherheit-und-resilienz/awareness-und-schulung)[Backup and recoveryBackups that hold when it matters: derive the requirements from the business, keep separate and immutable copies, test recovery regularly and document the evidence.](/en/it-beratung/sicherheit-und-resilienz/backup-und-wiederherstellung)[Emergency management and recoveryWhat happens when IT stops: determine critical processes and time targets, write the emergency plan, rehearse recovery, settle crisis communication and learn from exercises.](/en/it-beratung/sicherheit-und-resilienz/notfallmanagement)[Ordering identities and accessWho may do what and why: build an access concept, use roles instead of individual rights, introduce multi-factor authentication, automate joiners and leavers and review permissions regularly.](/en/it-beratung/sicherheit-und-resilienz/identitaeten-und-zugriffe)[Building information securityAn information security management system that fits your size: scope, risks, policies, evidence and the route to certification when customers require it.](/en/it-beratung/sicherheit-und-resilienz/isms-und-zertifizierung)[Focus topicNIS2 and cyber securityWhether your company falls under the new German BSI Act, which duties follow, how risk management, reporting and supply chain are implemented, and what applies personally to management.](/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit)

## Häufige Fragen

We are too small to be interesting. Is that true?

No. Attacks are largely automated and look for reachable weaknesses, not for well known names. Smaller companies are additionally attractive as a route into larger customers, which is exactly why customers increasingly ask for evidence before awarding a contract.

What is the most effective first step?

A tested recovery. Anyone who has a backup that is demonstrably restorable and kept separate from the rest of the network survives the most common emergency. Right after that come multi-factor authentication on everything reachable from outside, and an orderly procedure for updates.

## Let us talk about your situation

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
