Pillar B — IT Security
IT security rarely walks into a company by itself. Triggers tend to be: a major customer demands NIS2 evidence, a bank requires cyber-insurance documentation, a phishing incident happens, or the EU AI Act mandates documented AI-literacy training (in force since 2 February 2025). This pillar covers operational security — from phishing simulations through to disaster-recovery plans.
When this pillar fits
- NIS2 supplier-chain pressure from a directly regulated customer (Article 21 of the NIS2 Directive)
- Cyber insurance is rejected or demanding evidence
- AI literacy obligation under EU AI Act Article 4 — every company using AI tools commercially must train its staff
- Phishing incident or staff behaviour signalling training need
- ISO 27001 / TISAX preparation with security measures and disaster recovery as building blocks
Sub-services
| Service | Trigger | Price | Lead time |
|---|---|---|---|
| NIS2 quickcheck + contract coaching | major customer demands NIS2 evidence | EUR 790 | 2 weeks |
| Cyber insurance preparation | insurance demands evidence | EUR 1490 | 4 weeks |
| Security measures concept (GDPR Art. 32) | DPO mandate or ISO preparation | EUR 690 | 2 weeks |
| Phishing simulation programme (12 months) | recurring staff training | EUR 990–1890 / year | annual |
| Disaster recovery plan + tabletop exercise | ISO/TISAX or major-customer demand | EUR 2490 | 6 weeks |
| Emergency hotline 8/5 (4-hour weekday response) | solo / SME without IT department | EUR 89 / month | immediate |
| Emergency hotline 24/7 | shift-based SME | EUR 199 / month | immediate |
| AI literacy solo (60-min training + test + certificate) | solo professionals using AI tools | EUR 390–490 | 1 week |
| AI literacy team S/M/L | teams of 2 to 30+ | EUR 890–1890 | 2 weeks |
| Emergency triage (1-hour call) | active incident | EUR 290 | within 24 h |
→ Detail in Services overview.
Methodology
- BSI IT-Grundschutz — German federal IT security baseline; building blocks and control measures
- NIS2 minimum measures (Article 21 of the directive) — risk management, incident handling, supply-chain security
- EU AI Act Article 4 — AI literacy obligation for every company using AI tools (in force since 2025-02-02)
- NIST Cybersecurity Framework — frequently referenced by insurers
- MITRE ATT&CK — threat modelling for risk analyses
Differentiation
- vs. hardware vendors: I do not sell hardware; no commission conflicts
- vs. Big Four consultancies: more affordable, closer to SME reality
- vs. solo IT consultants without certifications: TÜV + CompTIA stack as a trust anchor
- vs. tool-focused cybersecurity startups: tool-agnostic, methodology-grounded
Credentials
- TÜV Rheinland IT Security Manager (BSI methodology)
- TÜV Rheinland IT Security Officer (operational implementation)
- CompTIA Security+ (foundation)
- CompTIA CySA+ (Cybersecurity Analyst — threat detection)
- CompTIA CSAP (Security Analytics Professional)
→ Detail in Certifications.
Discovery call
A discovery call clarifies the trigger (major customer, insurance, incident, compliance obligation), the right service and the delivery sequence. For active incidents: emergency triage within 24 hours.
→ Book a slot · or email alex@alex-sokolov.de