What does a security audit cost? How the price is formed – and what a good offer looks like

“How much does a security audit cost?” – I hear that question almost as often as “Do we even need one?”. The honest answer upfront: There is no serious fixed price – and that is a good thing. Here is why audit effort varies so much, how prices actually form, and what a good offer looks like. What drives the effort of an audit A security audit is not a standard product. Four factors decide how much work goes into it: ...

2026-09-15 · 4 min · 660 words · Stefan

Security Audit vs. Penetration Test: The Difference – and Which One Is the Right First Step

“Should we get an audit or a pentest?” – the question comes up again and again, and honestly: the answer is less often “simply both” than you might think. The two approaches answer different questions. Understand that, and you also know where to start. What a security audit checks A security audit is a systematic technical assessment: I look at your configurations, architectures, processes, and settings – cloud setup, Linux and container environments, access rights, secrets, monitoring. The goal is to find and assess known vulnerabilities, misconfigurations, and design problems. ...

2026-09-14 · 3 min · 575 words · Stefan

What Does a Pentest Cost? How the Price Is Built Up – and What to Look for in a Proposal

“What does a pentest cost?” is the most common question after “what is a pentest?” – and it is a fair one. The honest answer up front: there is no serious fixed price. Anyone offering you pentests “from” a certain amount is calculating at a risk – yours. Here is how prices for security services actually come about, and how to recognise a good proposal. Why there is no fixed price A pentest (or a security audit) is not a standard product like a firewall license. The effort depends on things that differ completely from business to business: ...

2026-09-14 · 3 min · 579 words · Stefan

Ransomware: Will your backups hold up when it hits?

The good news first: most ransomware cases are not decided during the attack, but during recovery. Companies with usable backups and a rehearsed recovery get away with a bad weekend. Those without end up negotiating ransom demands. The difference lies in a handful of decisions made in advance – and that is what this article is about. Why attackers go for your backups first Modern ransomware groups don’t just encrypt blindly. They work systematically: escalate privileges first, then locate the backup infrastructure – backup servers, NAS shares, cloud backups – and eliminate the backups first. On top comes the second extortion stage: data is copied before encryption and used as leverage (double extortion). Your backups only help if they survive the encryption – and having your data leaked changes nothing about your reporting obligations. ...

2026-09-13 · 3 min · 471 words · Stefan

Does NIS2 apply to you? The 5-minute check for your company

“Does NIS2 apply to us?” — lately I hear this question from almost every mid-sized company in my region. Understandable: the directive covers far more businesses than its predecessor, and the uncertainty about what exactly applies is huge. The good news: whether you’re probably in scope can be narrowed down with three questions. That’s what this article is about. What NIS2 is — and where Germany stands now The NIS2 Directive ((EU) 2022/2555) is the successor to the first NIS Directive and requires member states to make cybersecurity mandatory for essential and important entities. At its core: organised risk management, reporting of significant incidents, and management responsibility. ...

2026-09-12 · 4 min · 663 words · Stefan

Understanding and Implementing DNSSEC Correctly

DNS is one of the most critical infrastructure components on the internet – and simultaneously one of the most vulnerable. DNSSEC (Domain Name System Security Extensions) was developed to close fundamental security gaps in DNS. Despite its importance, DNSSEC is often misunderstood or incorrectly implemented. What is DNSSEC and Why Does it Matter? Classic DNS has a fundamental problem: there’s no way to verify whether a DNS response actually comes from the authoritative nameserver or has been manipulated by an attacker. This enables attacks such as: ...

2026-02-20 · 4 min · 740 words · Stefan