IT security for medium-sized businesses — hands-on, pragmatic, and implementation-focused.


Service Area: Rhine-Neckar Metropolitan Region

My primary focus is on the Rhine-Neckar metropolitan region – one of Germany’s strongest economic areas with around 160,000 businesses. I prefer working directly on-site with companies looking to build their IT security in a pragmatic and sustainable way:

  • Mannheim & Ludwigshafen
  • Heidelberg & Rhine-Neckar district
  • Karlsruhe & region
  • Speyer, Worms & surroundings

Remote engagements across Germany are also welcome after an initial discovery call.


Service Overview

Everything is billed transparently by the hour — scope and expected volume are agreed upfront in writing; you only pay for the time actually spent.

AI & LLM Security

Advisory & hardening · hourly

Adopt generative AI and language models securely: prevent data leaks, eliminate shadow AI, mitigate prompt injections, and control RAG permissions.

  • Halt data leaks to public AI clouds (shadow AI mitigation)
  • Secure enterprise knowledge assistants (RAG) with least-privilege access
  • Security audits based on OWASP Top 10 for LLMs & prompt injection defense
  • Actionable workplace AI guidelines and preparation for the EU AI Act

Data Sovereignty & Cloud Independence

Architecture & strategy · hourly

Maintain true control over your corporate data: shield against the US CLOUD Act, eliminate vendor lock-in, and own your encryption keys.

  • Host critical workloads on European platforms (Hetzner, OVH, OTC) or on-premise
  • Own your encryption keys (BYOK/HYOK): data remains unreadable even in the cloud
  • Exit strategies & portable architectures using open standards and containers
  • Safeguard trade secrets, engineering IP, and sensitive client information

Security Consulting & Sparring

Flexible on demand · hourly

Pragmatic advice at eye level for management and IT leads: make solid security decisions without having to hire a full-time CISO.

  • Second opinions on quotes and proposals from external IT service providers
  • Securing Microsoft 365, cloud environments, and internal networks
  • Guidance on customer compliance questionnaires and cyber insurance requirements
  • Preparation for audits, NIS2 compliance, and baseline security standards

Security Audit

1–2 weeks · clear timeframe

A hands-on technical review of your cloud, server, and IT infrastructure: where do you actually stand, where are the real risks, and what gives you the highest leverage?

  • Configuration review of cloud environments (Azure/AWS), servers, and identities (IAM)
  • Actionable report with clear traffic-light prioritization
  • Concrete roadmap instead of 200 pages of automated scanner noise

Hardening & Security Foundation

Project-based · 2–4 weeks

Fix weaknesses and sustainably harden your infrastructure: repeatable baselines, ransomware resilience, and drift control.

  • Server and cloud hardening aligned with recognized standards (CIS)
  • Automation with Ansible so security doesn't decay after the next update
  • Tested backup & recovery concepts against ransomware attacks

Penetration Test

By agreed scope

The real-world proof of your defense: controlled attacks conducted like a real adversary to demonstrate which vulnerabilities are practically exploitable.

  • Testing of external perimeters, web applications, or internal networks
  • OSCP certified, transparent methodology following OWASP
  • Reproducible findings with proof of exploitation and patch re-verification

Incident & Threat Response

On-demand · incident or readiness

When an incident happens or when preparing for the worst: structured analysis, rapid containment, and safe recovery.

  • Active emergency response, triage, and system isolation
  • Forensic investigation across logs, cloud, and endpoints
  • Safe recovery and an actionable post-mortem remediation plan

SIEM & Security Operations

Setup & operational sparring

Maintain clear visibility of critical security events: centralized logging, actionable detection rules, and endpoint security without alert fatigue.

  • Centralized logging with Elastic, Splunk, or Microsoft Sentinel
  • Tuning Microsoft Defender for Endpoint / Business
  • Actionable runbooks for rapid incident response by your team

How does working together look like?

1

Intro call (free)

30-minute discovery call. You describe your situation, I explain how I work. For an initial technical assessment.

2

Scope & proposal

Based on our conversation I define a clear scope and send a written proposal with the agreed frame – billing is transparently by the hour.

3

Execution

I work in a structured way, communicate regularly and keep you in the loop — no black box.

4

Results & hand-over

Clear report, prioritized actions, usable documentation. Focused on what matters — directly actionable for your team.


Typical deliverables

  • Prioritized findings: Clear quick wins and actionable steps first
  • Roadmap: Transparent assessment of effort vs. security impact
  • Hardening baselines: Documented standards (optionally automated with Ansible)
  • Concise documentation: Pragmatic runbooks that work in everyday operations

Contact

For inquiries, an initial consultation (30 minutes free), or confidential messages, please use my central contact page.