Frequently asked questions about IT security consulting and how I work.
What does a security audit cost?
It depends on the scope – every company is set up differently, so I calculate by effort. In the free intro call we define the frame (scope, expected volume, duration), you get a written proposal, and billing is transparently by the hour — you only pay for the time actually spent.
Does a small business like mine really need this?
Yes — smaller companies are often attractive targets precisely because they have fewer protections than large enterprises. Ransomware, phishing, and compromised cloud credentials hit them particularly hard.
Also: if you’re a supplier to larger companies, you’ll increasingly face security requirements from your customers (supply chain, NIS2 pass-through, ISO 27001 requirements).
Does NIS2 apply to my company?
Possibly. Since October 2024, NIS2 covers significantly more companies than its predecessor — including many businesses in sectors like energy, transport, healthcare, IT services, and more.
My NIS2 Readiness Check first clarifies whether you’re even affected, and if so, what needs to be done. As a first step, try the free NIS2 self-assessment.
What’s the difference between a security audit and a penetration test?
Security Audit / Security Review: I look at configurations, architectures, processes, and settings — without active attacks. I identify known vulnerabilities, misconfigurations, and design issues. Great as a first step.
Penetration test (pentest): Active attack against systems to find and exploit vulnerabilities. Requires more preparation, a clear scope, and legal groundwork.
For most companies, a security audit is the more sensible first step — and significantly cheaper than a full pentest.
How can I be sure my data is safe with you?
I work with non-disclosure agreements (NDAs) and comply with GDPR. Data I access during an audit is only used for the defined purpose and deleted afterwards.
Can I book you for single hours?
Yes — for quick consulting, architecture reviews, or as a technical sparring partner, I also offer hourly consulting. This falls under my Security Consulting & CISO Sparring offering and is billed transparently by the hour.
Do you work remotely or on-site?
Both. Most audits and consulting work fine remotely. For workshops or awareness training I’m happy to come on-site — primarily in the Rhine-Neckar metropolitan region, but available across Germany on request.
How quickly can you start?
I respond to inquiries within 24 hours at the latest. Projects usually start within 1–3 weeks of engagement. Get in touch or book a call directly.