Service directory
What do you want to achieve?
Choose your situation. We show you the services that match your goal.
Search results
No matching service found.
Try a different term or choose one of the situations.
Suitable services
-
IT-Grundschutz consulting
Introduce IT-Grundschutz, start with Basic Protection and prepare for certification.
-
VDA ISA / TISAX® consulting
TISAX® consulting for automotive suppliers: quick check, ISMS implementation and assessment preparation with secuvera.
-
ISO 27001 consulting
Build an ISMS: introductory workshop, gap analysis, risk management and audit support.
-
ISO 42001 consulting
ISO 42001 consulting for your use of AI: gap analysis, management system, internal audits and audit preparation.
-
BCM consulting
Business impact analysis, emergency and restart plans, exercises and training.
-
Internal audits
Internal audits with independent auditors, a preceding document review and a quality-assured report.
-
ISMS certification and IS audit
Certify your ISMS or have it reviewed in an IS audit: experienced auditors for ISO 27001 and IT-Grundschutz.
-
CISO as a service
CISO as a service: ISMS maintenance, security committee, management report and awareness training.
-
Security concepts for defence and classified information
Audit-ready security concepts for Bundeswehr projects and processing classified information: analysis, modelling and evidence with secuvera.
Suitable services
-
CRA consulting
CRA workshop, gap analysis and implementation of risk assessment, PSIRT and security testing.
-
NIS2 & KRITIS consulting
Determine whether you are in scope, compare measures and evidence, carry out KRITIS audits.
-
C5 consulting
Assess maturity and C5 gaps, map existing measures and prepare for the audit.
Suitable services
-
Penetration test
Testing networks, Active Directory, web applications, APIs, apps, OT and AI systems for vulnerabilities.
-
Breach and attack simulation
Breach and attack simulation: testing client protection, Active Directory and hybrid identities with Entra ID for attack paths.
-
AI pentest
Testing chatbots, assistants and LLM integrations for prompt injection, data leakage and unauthorised access, in the context of the whole application.
-
Red teaming
Targeted attack simulation, testing of the SOC response and joint purple teaming.
-
WBRT® – White Box Red Teaming
WBRT® with secuvera: developing and documenting attack scenarios in a joint workshop and deriving next measures.
-
Source code analysis / SAST
Reviewing source code, validating findings manually and integrating SAST into CI/CD and development processes.
-
Cyber Security Check
Cyber Security Check with experienced assessors: evaluating your security status, classifying deficiencies and determining next measures.
-
DDoS simulation and load tests
DDoS simulation and load tests at application level: real internet traffic, personal support and an individual report.
-
Cloud security assessment
Cloud security assessment for Azure, AWS, Google Cloud, Kubernetes and Microsoft 365: reviewing configurations and processes.
-
OSINT analysis
OSINT analysis by secuvera: researching your public attack surface, assessing relevant findings and documenting them in an individual situation report.
Suitable services
-
Common Criteria / EUCC consulting
Kickstarter workshop, Security Target and manufacturer coaching for your certification according to Common Criteria or EUCC.
-
Common Criteria / EUCC evaluation
Product evaluation according to Common Criteria and EUCC by our BSI-recognised, DAkkS-accredited evaluation facility.
-
IEC 62443 consulting & evaluation
IEC 62443-4-1, component evaluations according to 4-2, threat analyses and security concepts for plants.
-
Accelerated Security Certification
Evaluating product, cryptography and installation guide for the BSZ procedure.
-
BSI TR-03161: health applications
BSI TR-03161 for health applications: quick check, evaluation and coordination with the BSI by a recognised evaluation facility.
-
BSI TR-03185: development processes
BSI TR-03185: gap analysis and audit of secure development and update processes with secuvera.
-
BSI TR-03174: financial applications
BSI TR-03174 for financial applications: pre-evaluation, security evaluation and coordination with the BSI with secuvera.
-
Product approval for classified information
Product approval for classified information: evaluation, manufacturer documentation and coordination with the BSI with secuvera.
-
Consulting for product manufacturers
IT security consulting for product manufacturers: classify requirements, select the right evaluation procedure and prepare the evidence.
-
5G security and campus network audits
5G security for campus networks and mobile network products: security requirements, assessment and preparation of evidence with secuvera.
-
BSI IT Security Label
IT Security Label of the BSI: classify requirements, test connected devices according to ETSI EN 303 645 and prepare evidence for the application.
-
Security expert report for gaming machines
Security expert reports for gaming machines for PTB type approval: BSI-recognised evaluation facility, specific checklist and CC methodology.
-
Cybersecurity tests for digital products
Cybersecurity tests for digital products: modular testing for CRA, RED, IEC 62443 and product quality.
Suitable services
-
OWASP Top 10 workshop
OWASP Top 10 with real-world examples: recognising the most common security risks in web applications.
-
OWASP Advanced workshop
Building on the basic module: finding vulnerabilities in web applications yourself, with testing tools and an exercise in OWASP Juice Shop.
-
OWASP API Security workshop
The ten most common security risks for APIs: methodology of the OWASP API Security Top 10, web API fundamentals, introduction to Burp.
-
OWASP App Security workshop
OWASP Mobile Top 10 with technical examples and countermeasures, tips for developers and how app penetration tests work.
-
OWASP SAMM workshop
Security development lifecycle, secure development with OWASP SAMM, threat modelling, security by design, secure coding guidelines.
-
IEC 62443 for the CRA in practice
Four modules on IEC 62443, product requirements, secure development and hands-on TARA.
Suitable services
Choose what you want to achieve. You will then find the right consulting, testing or training here.
How we support you
Depending on your situation, we support you with consulting, technical testing, audits, product evaluation or training. Consulting means, for example: building an ISMS based on ISO/IEC 27001 or IT-Grundschutz, implementing NIS2 or preparing a cloud service for C5. On the technical side, we test applications, networks and organisations with penetration tests and red teaming. As a BSI-recognised evaluation facility, we evaluate products under Common Criteria, EUCC and Technical Guidelines.
Choose your situation above or search the directory. If you are not sure which service fits, we will clarify this together in an initial consultation.