Security consulting that does not stop at the recommendation
From establishing where you stand, through the management system, to running it day to day – advice and technology from the same people.
Where do I start?
The most common question in a first conversation. Find the situation that matches yours:
“We have no idea where we stand.”
Cyber Risk Check to DIN SPEC 27076 – two hours of conversation, then a prioritised report.
About the Cyber Risk Check“What can an attacker see from outside?”
Vulnerability management, starting with the free quick check of your domain.
About vulnerability management“We have to meet NIS2 or want a certificate.”
ISMS consulting and guidance towards ISO 27001 on an IT-Grundschutz basis.
ISO 27001 on an IT-Grundschutz basis“We would not even notice an attack.”
GUARDIANVIEW, our managed SIEM – detection while it is happening.
GUARDIANVIEW in detail“We lack somebody who takes care of it permanently.”
An external information security officer – accountability rather than a list of recommendations.
The external security officer
Information security is not a product you buy but an interplay of advice, technology and people. We cover that spectrum from one source – from a structured ISMS introduction through offensive security to raising your people's awareness. Vendor neutral, certified to ISO 27001 on the basis of IT-Grundschutz, and tailored to your sector.
Our fields in detail
Nine services that interlock. You rarely need all of them – but rarely only one.
Build it and prove it
Management systems, roles and obligations – everything that has to stand up to evidence in the end.
External security officer
We provide your information security officer and take responsibility for the process – including the duty to report to management.
The security officer as a serviceBSI IT-Grundschutz
Structured implementation of BSI standards 200-1 to 200-4. We model your information domain against the Kompendium's modules and guide the IT-Grundschutz check through to audit readiness.
IT-Grundschutz consultingISO 27001
From gap analysis through scope definition to the audit. We are certified to ISO 27001 on an IT-Grundschutz basis ourselves and know where effort arises and where it can be saved.
The route to the ISO 27001 certificateNIS2 compliance
Germany's NIS2 act has applied since December 2025 with no transition period. We first establish whether you are in scope at all, then implement the required risk management and reporting duties.
NIS2 obligations at a glanceCritical infrastructure
For operators of critical infrastructure: evidence obligations, attack detection systems and preparation for examination by the BSI.
The KRITIS umbrella act in briefTest and harden
Find out where you are exposed, then close the gaps.
Cyber Risk Check
A position assessment to DIN SPEC 27076 at a fixed price: 27 requirements, a prioritised report, pointers to applicable funding.
Cyber Risk Check to DIN SPEC 27076Vulnerability management
Check regularly what is visible from outside, and sort the findings by genuine urgency rather than by score.
Vulnerability management in detailCloud security
Configuring Microsoft 365, Azure and AWS securely – permissions, conditional access, logging and external sharing. The provider secures the platform; you secure the configuration.
Assess and harden Microsoft 365Penetration testing
A controlled attack on your systems, with written authorisation and clear abort criteria.
Penetration testing: process and valuePeople and operations
What has to keep running so the work above does not quietly expire.
Security awareness
Training and phishing simulations, measured by reporting rate and response time rather than click rate – because studies show the click rate barely moves.
Security awareness in practiceManaged SIEM
Attack detection during operations, run by us – without you having to build a SOC of your own.
GUARDIANVIEW, our managed SIEMHow we work
Three things that set us apart from consulting alone:
We deliver, not just advise.
A concept nobody implements has helped nobody. We stay involved through to operation – and operate it where you want us to.
We are vendor neutral.
We do not resell licences. What suits you is decided by your environment, not by our margin.
We also say no.
If a service would achieve nothing for you, you hear that beforehand. It occasionally costs us an engagement and saves you more.
Why SECURITYSQUAD?
100%
Certified ourselves
ISO 27001 on an IT-Grundschutz basis – we walked the road we guide you along.
360°
Advice and operation
Strategy and technology from the same people, without loss in handover.
From Germany
Operated in Germany, active across Europe, without dependence on US providers.