Cyber defense is about leadership, not just technology.
Cyber defense, cyber security, and cyber resilience are now key issues in IT management and personal liability. What matters is not whether attacks occur, but whether your company can detect them, respond in a controlled manner, and safely restore operations.
Cybersecurity reduces the likelihood of an incident. Cyber defense minimizes the damage. Cyber resilience keeps you operational.
I develop strategies and programs that work in everyday life: with governance, clear responsibilities, and robust metrics. Not certificates to file away, but proven resilience in the face of crises.
01
Security: Reduce the Attack Surface
Hardening, identities, access controls, segmentation, patch and vulnerability management as an operational discipline. Define and protect crown jewels.
02
Detecting and Responding to Attacks
For an attack to be detected, the company must record and analyze the right traces. I ensure that suspicious activities are detected early, properly classified, and addressed according to a clear emergency plan—with full transparency until it is determined how the incident occurred.
03
Restart: Business Continuity
Backup strategy, recovery, disaster recovery, crisis management. Restore tests instead of romanticizing backups. Realistic and verified RTO and RPO.
04
NIS2 / KRITIS / Regulation
Regulatory requirements as part of responsible architecture, not as an isolated compliance exercise.
05
Governance & Responsibility
RACI: Who decides, who is responsible, who delivers? Risk register, policies, exception processes, auditability.
06
Supply Chain & Third Parties
In the supply chain, the partner with the least security is the primary target. Risks associated with suppliers and service providers are managed.