IT security for medium-sized businesses — hands-on, pragmatic, and implementation-focused.
Service Area: Rhine-Neckar Metropolitan Region
My primary focus is on the Rhine-Neckar metropolitan region – one of Germany’s strongest economic areas with around 160,000 businesses. I prefer working directly on-site with companies looking to build their IT security in a pragmatic and sustainable way:
- Mannheim & Ludwigshafen
- Heidelberg & Rhine-Neckar district
- Karlsruhe & region
- Speyer, Worms & surroundings
Remote engagements across Germany are also welcome after an initial discovery call.
Service Overview
Everything is billed transparently by the hour — scope and expected volume are agreed upfront in writing; you only pay for the time actually spent.
AI & LLM Security
Advisory & hardening · hourly
Adopt generative AI and language models securely: prevent data leaks, eliminate shadow AI, mitigate prompt injections, and control RAG permissions.
- Halt data leaks to public AI clouds (shadow AI mitigation)
- Secure enterprise knowledge assistants (RAG) with least-privilege access
- Security audits based on OWASP Top 10 for LLMs & prompt injection defense
- Actionable workplace AI guidelines and preparation for the EU AI Act
Data Sovereignty & Cloud Independence
Architecture & strategy · hourly
Maintain true control over your corporate data: shield against the US CLOUD Act, eliminate vendor lock-in, and own your encryption keys.
- Host critical workloads on European platforms (Hetzner, OVH, OTC) or on-premise
- Own your encryption keys (BYOK/HYOK): data remains unreadable even in the cloud
- Exit strategies & portable architectures using open standards and containers
- Safeguard trade secrets, engineering IP, and sensitive client information
Security Consulting & Sparring
Flexible on demand · hourly
Pragmatic advice at eye level for management and IT leads: make solid security decisions without having to hire a full-time CISO.
- Second opinions on quotes and proposals from external IT service providers
- Securing Microsoft 365, cloud environments, and internal networks
- Guidance on customer compliance questionnaires and cyber insurance requirements
- Preparation for audits, NIS2 compliance, and baseline security standards
Security Audit
1–2 weeks · clear timeframe
A hands-on technical review of your cloud, server, and IT infrastructure: where do you actually stand, where are the real risks, and what gives you the highest leverage?
- Configuration review of cloud environments (Azure/AWS), servers, and identities (IAM)
- Actionable report with clear traffic-light prioritization
- Concrete roadmap instead of 200 pages of automated scanner noise
Hardening & Security Foundation
Project-based · 2–4 weeks
Fix weaknesses and sustainably harden your infrastructure: repeatable baselines, ransomware resilience, and drift control.
- Server and cloud hardening aligned with recognized standards (CIS)
- Automation with Ansible so security doesn't decay after the next update
- Tested backup & recovery concepts against ransomware attacks
Penetration Test
By agreed scope
The real-world proof of your defense: controlled attacks conducted like a real adversary to demonstrate which vulnerabilities are practically exploitable.
- Testing of external perimeters, web applications, or internal networks
- OSCP certified, transparent methodology following OWASP
- Reproducible findings with proof of exploitation and patch re-verification
Incident & Threat Response
On-demand · incident or readiness
When an incident happens or when preparing for the worst: structured analysis, rapid containment, and safe recovery.
- Active emergency response, triage, and system isolation
- Forensic investigation across logs, cloud, and endpoints
- Safe recovery and an actionable post-mortem remediation plan
SIEM & Security Operations
Setup & operational sparring
Maintain clear visibility of critical security events: centralized logging, actionable detection rules, and endpoint security without alert fatigue.
- Centralized logging with Elastic, Splunk, or Microsoft Sentinel
- Tuning Microsoft Defender for Endpoint / Business
- Actionable runbooks for rapid incident response by your team
How does working together look like?
Intro call (free)
30-minute discovery call. You describe your situation, I explain how I work. For an initial technical assessment.
Scope & proposal
Based on our conversation I define a clear scope and send a written proposal with the agreed frame – billing is transparently by the hour.
Execution
I work in a structured way, communicate regularly and keep you in the loop — no black box.
Results & hand-over
Clear report, prioritized actions, usable documentation. Focused on what matters — directly actionable for your team.
Typical deliverables
- Prioritized findings: Clear quick wins and actionable steps first
- Roadmap: Transparent assessment of effort vs. security impact
- Hardening baselines: Documented standards (optionally automated with Ansible)
- Concise documentation: Pragmatic runbooks that work in everyday operations
Contact
For inquiries, an initial consultation (30 minutes free), or confidential messages, please use my central contact page.