Your situation

Cyber Security Check: assessing your security status

You need an independent assessment of your information security without immediately starting a full certification project? With the Cyber Security Check (BSI/ISACA guideline), you receive an overview of your measures and the need for action at a fixed price.

Free of charge and without obligation.

  • Co-authors of the Cyber Security Check V2
  • BSI-certified for IS consulting and IS audit
  • Cyber Security Practitioners (CSP) on the team
Top view of the sand table with the word CYBERSICHERHEIT (cybersecurity), surrounded by several people and the blue Vera figure
Cyber Security Check: your security status at a glance.

Your situation

You want to know where your organisation stands on cybersecurity – without starting an ISMS project straight away?

Is your company secure, insecure or somewhere in between? Management needs an independent assessment, you want to prioritise measures or record the status before a larger project. A full approach according to BSI IT-Grundschutz or ISO/IEC 27001 is often too big for this question.

The Cyber Security Check guideline (in German) was developed by ISACA Germany Chapter e.V. together with experts from the BSI. With just a few external assessment days and comparatively little internal effort, you receive an overview of your security measures – automatically prioritised and mappable to BSI IT-Grundschutz, ISO/IEC 27001, COBIT and PCI DSS. BSI Standard 200-2 names the check as one way of assessing an ISMS (information security management system) using a maturity model.

We carry out the check at a fixed price with certified Cyber Security Practitioners. For plants and process control, we offer the Cyber Security Check for industrial plants (CSC-OT), which secuvera helped to develop.

Services & results

A standardised procedure based on the guideline

With just a few external assessment days and little internal effort, you receive an overview of your security measures and your need for action, based on the guideline by ISACA Germany Chapter and the BSI. The results are prioritised and can be mapped to BSI IT-Grundschutz, ISO/IEC 27001, COBIT and PCI DSS; the check is carried out by certified Cyber Security Practitioners.

The Cyber Security Check follows a defined procedure and is non-invasive – the assessment does not in itself create any risk for your operations. It focuses on the logical security of information; on request, we also include physical security.

Placing the order: naming the assessor

The greatest risk of a Cyber Security Check lies in a possible lack of experience on the part of the assessor. You should therefore insist that the intended assessor is named when the proposal is submitted – and on the right to withdraw from the contract if the assessor changes.

Determining cybersecurity exposure

We clarify the area under review, your starting situation and your organisation’s cybersecurity exposure. This determines the focus areas of the assessment.

Focus areas of the assessment

An agreed scope and a basis for setting priorities.

Reviewing documents, preparing the on-site assessment

We review the existing documents and prepare the assessment on site: interviewees, dates and the systems to be considered.

On-site assessment

On site, we assess your security measures using the methods provided for in the guideline:

  • Interviews
  • Configuration reviews
  • Observations at the assessed site
  • Document analysis
  • Data analysis
  • Written surveys, if applicable

Follow-up and report

We classify the observations as security recommendations, security deficiencies or serious security deficiencies and recommend measures based on the control objectives defined in the guideline. On request, we support you in implementing the countermeasures.

Your report with recommendations for action

A report with classified deficiencies, prioritised recommendations and starting points for measures.

Our expertise

We have been offering the Cyber Security Check since 2014, shortly after ISACA and the BSI published the guideline. Sebastian Fritsch and Tobias Glemser from our team contributed to version 2 of the guideline as authors. In iX (issue 4/2015), the Cyber Security Practitioners Sven Supper and Tobias Glemser described in the article “Selbstdiagnose – Der Cyber-Sicherheits-Check: Hilfe zur Selbsthilfe” how the method can be used for self-assessment of information security.

secuvera contributed to the development of the “Cyber Security Check for industrial plants” (CSC-OT) by ISACA Germany Chapter. The methodology contains references to IEC 62443 and to BSI standards; since 2022, we have been assessing plants and processes using this approach.

Because the experience of the assessor determines the quality of the check, we use experienced staff certified as Cyber Security Practitioners.

Getting started

Narrowing down the area to be assessed

Clarify the starting point and objective

Tell us which organisational units are to be considered and which security processes are already in place. We clarify which documents and contacts are needed for the assessment.

Agree on additional topics

The CSC focuses on the logical security of information in an organisation. On request, physical security can also be examined and included in the assessment.

Request a Cyber Security Check
Dividers fixing a position on the world map
Scope clearly defined, results ready to use straight away.

Defining what the check can tell you

Scope and validity relate to the area under review. The check replaces neither a penetration test nor a certification.

Questions about the Cyber Security Check

Is the Cyber Security Check a penetration test?

No. The check uses interviews, configuration reviews, observations, and document and data analysis. Active attack simulation is not part of the methodology. If you want to test whether technical vulnerabilities can be exploited in practice, a different testing method is required.

How much internal effort does a Cyber Security Check involve?

The methodology is designed to determine your position with just a few external assessment days and comparatively limited internal effort. The specific effort depends on the area under review, the documents and the contacts needed.

What does the Cyber Security Check report contain?

The observations are classified as security recommendations, security deficiencies or serious security deficiencies. You also receive recommendations based on the control objectives of the guideline. This helps to prioritise the subsequent improvements.

Can the results feed into an existing ISMS?

Yes. The results can be related to IT-Grundschutz and ISO/IEC 27001, among others. This means the check can also provide an external assessment and pointers for further development in an organisation with existing security processes.

Does the check pose risks to our ongoing operations?

Carrying out the check does not in itself create any risk: the check is non-invasive and uses interviews, configuration reviews, observations, and document and data analysis. The greatest risk lies in an inexperienced assessor – so ask for the assessor to be named in the proposal.

Articles on this topic (in German)

All 6 articles on the topic (in German)

How can we support you with the Cyber Security Check?