Cyber defense is about leadership, not just technology.

Cyber defense, cyber security, and cyber resilience are now key issues in IT management and personal liability. What matters is not whether attacks occur, but whether your company can detect them, respond in a controlled manner, and safely restore operations.

The Triad

Cybersecurity reduces the likelihood of an incident. Cyber defense minimizes the damage. Cyber resilience keeps you operational.

I develop strategies and programs that work in everyday life: with governance, clear responsibilities, and robust metrics. Not certificates to file away, but proven resilience in the face of crises.

01

Security: Reduce the Attack Surface

Hardening, identities, access controls, segmentation, patch and vulnerability management as an operational discipline. Define and protect crown jewels.

02

Detecting and Responding to Attacks

For an attack to be detected, the company must record and analyze the right traces. I ensure that suspicious activities are detected early, properly classified, and addressed according to a clear emergency plan—with full transparency until it is determined how the incident occurred.

03

Restart: Business Continuity

Backup strategy, recovery, disaster recovery, crisis management. Restore tests instead of romanticizing backups. Realistic and verified RTO and RPO.

04

NIS2 / KRITIS / Regulation

Regulatory requirements as part of responsible architecture, not as an isolated compliance exercise.

05

Governance & Responsibility

RACI: Who decides, who is responsible, who delivers? Risk register, policies, exception processes, auditability.

06

Supply Chain & Third Parties

In the supply chain, the partner with the least security is the primary target. Risks associated with suppliers and service providers are managed.

Procedure

From Risk to Manageability

Phase 1 · 30–45 days

Situation Overview & Priorities

  • Risk and Maturity Profile (Current Status)
  • Crown Jewels and Critical Processes
  • Gap Analysis: Protection, Detection, Resilience
  • Top 10 Action Plan, Including Quick Wins

Phase 2 · 60–120 days

Stabilization

  • Hardening, Identity, Patch/Vulnerability Process
  • Logging Fundamentals, SOC Use Cases, Alerting
  • Incident Response: Roles, Runbooks, Drills
  • Backup/Restore: Tests, RTO/RPO, Emergency Operations

Phase 3 · ongoing

Governance & Operations

  • Operating Model: Responsibilities, SLAs
  • KPIs and Reporting: Security as a Management Tool
  • Managing the Supply Chain and Third Parties
  • Audits and Verifiability

Phase 4 · Culture

Scaling

  • Security by Design in Projects
  • Awareness as a Leadership Topic
  • Systematically Reduce Technical Debt
  • Roadmap for 12–24 Months

Documents

Proven resilience in times of crisis

48 hours

Ransomware Recovery

Restore operations within 48 hours following a ransomware incident.

VS-A

High-Security Environment 2026

Leadership of a task force focused on approved system solutions for classified information across all classification levels.

NIS2

Critical Infrastructure

Resilience program to address (state-sponsored) threat scenarios and ensure operational capability in the event of an emergency.