From practice

How we reduce risk measurably

Security projects touch sensitive areas. That is why we present our work anonymised, the situation, approach and outcome remain transparent.

Our references

Take a look at some examples of how we solved challenges for our customers.

Fiduciary services
18 workplaces

From open remote access to controlled access

The terminal server was reachable directly from the internet and protected by a password only, the logs showed thousands of login attempts every day. We replaced the open access with a WireGuard VPN using multi-factor authentication, segmented the network and set up central log monitoring with alerting. Today no administrative service is publicly reachable, anomalies raise an automatic alert, and the security questionnaire from their largest client was passed.

Manufacturing
60 employees, 2 sites

Ransomware preparedness with tested backups

Backups had been running for years, but nobody had ever tested a restore, and two of the three backup targets were writable from the production network. We rebuilt the backup following the 3-2-1 rule, with immutable copies, a separate backup network, an offsite copy in Switzerland and documented quarterly restore tests. Recovery time for business-critical systems is now demonstrably under four hours.

Healthcare
Group practice, 12 people

Phishing defence and awareness

After a successful phishing attack on a staff account it was unclear which data had been exposed and which reporting obligations applied. Immediate containment and an incident review were followed by multi-factor authentication across the board, email hardening with DMARC and two awareness sessions with a subsequent phishing simulation. The click rate dropped from 31% to 4%, and no compromised accounts have been detected since.

Professional services
8 employees, fully remote

Working securely without an on-premise server

Passwords were shared in a spreadsheet, devices were unencrypted and cloud access was protected by a password only. We introduced a shared password manager, enabled multi-factor authentication for all services, encrypted the devices and drew up a lean written security concept. Access is now traceable and no shared password is in circulation, a foundation that also holds up in customer audits.

Out of consideration for our customers’ security we do not name them. On request we are happy to arrange reference contacts in a personal conversation.

Ready to reduce your risk?

Let us discuss where your business stands today and which measures will have the greatest effect.