DSGVO EU General Data Protection Regulation Fully implement the requirements of the GDPR and demonstrate your accountability at any time.
Record of processing activities under Art. 30 Data subject rights & deadlines automated Data breach notifications under Art. 33/34 Data processing agreements & deletion concept DSGVO in detail
NIS2 EU directive on cybersecurity Meet the extended due diligence and reporting obligations of the NIS2 directive for affected entities.
Risk management & measures Incident reporting channels & deadlines Supply chain security Evidence for authorities NIS2 in detail
ISO/IEC 27001 International ISMS standard Build a certification-ready information security management system and operate it efficiently.
Statement of Applicability (SoA) Risk treatment & Annex A controls Internal audit management Continuous improvement (PDCA) ISO/IEC 27001 in detail
BSI IT-Grundschutz BSI standard Work in a structured way according to IT-Grundschutz – from getting started through WiBA to full protection.
Structure analysis & protection requirements Modules & requirements Path to basic protection (WiBA) Derivation of measures and risks BSI IT-Grundschutz in detail
DORA EU Digital Operational Resilience Act Meet the DORA requirements for digital operational resilience for financial entities and their ICT providers.
ICT risk management Classification and reporting of ICT incidents Digital operational resilience testing ICT third-party risk DORA in detail
Ransomware Detect, contain, preserve evidence, recover Defending against an encryption attack is not a single feature but a chain of four steps that have to interlock.
Early warning through decoys that serve no operational purpose Detection of mass encryption, on the network and in Microsoft 365 Host isolation and account lockout with four-eyes approval Evidence bundle on the incident and a verified recovery Ransomware in detail
Cyber Resilience Act EU regulation for products with digital elements Meet the cybersecurity and reporting duties of the EU Cyber Resilience Act for products with digital elements.
Essential requirements from Annex I Vulnerability handling across the lifecycle Reporting duty: 24 hours, 72 hours, 14 days Declaration of conformity and technical documentation Cyber Resilience Act in detail
ISO/IEC 42001 Management system for artificial intelligence (AIMS) Run an AI management system to ISO/IEC 42001:2023 with a control catalog, AI risk assessment and impact assessment.
38 Annex A controls across nine control objectives AI risk assessment and AI impact assessment AI inventory with risk class under the AI Act Clause coverage 4 to 10 in the cockpit ISO/IEC 42001 in detail
PCI DSS Security standard for payment card data Manage the PCI DSS requirement catalog, your cardholder data environment and the quarterly ASV scans in one place.
12 requirements across six goal areas Cardholder data environment (CDE) with scan scope Quarterly ASV scans valid for 90 days Readiness comparison against attack surface management PCI DSS in detail