It starts with a cybersecurity check: I review your attack surface from the outside like an attacker and from the inside like an administrator, assess processes and access and deliver a prioritised action plan in plain language. On request I implement it from one source.
What is included
- Cybersecurity check: external attack surface analysis (domains, servers, services, certificates, email security) and internal review of access, permissions, updates and backups
- Vulnerability scans with OpenVAS and Nuclei plus manual review, security review of web applications according to the OWASP Top 10
- Hardening of servers, firewalls, networks and workstations, patch management and update processes
- Identities and access: multi-factor authentication, passkeys, password managers, separate admin accounts, offboarding processes
- Email security against phishing and invoice fraud: SPF, DKIM, DMARC, filter rules and employee awareness
- Logging and detection: central logging, alerting on suspicious logins, monitoring with Wazuh or Checkmk
- Emergency plan and incident response: preparation, response to ransomware and data leaks, forensic preservation, recovery
- Preparation for NIS2, ISO 27001 and cyber insurance requirements: gap analysis, action plan, documentation
Typical assignments
- A law firm has its compliance with the requirements checked before taking out cyber insurance and closes the gaps within two weeks.
- A manufacturing company falls under NIS2: gap analysis, action plan and implementation of the technical requirements.
- After fake invoice emails, mailboxes are reviewed, forwarding rules removed, MFA and DMARC introduced.
- Ransomware on a file server: isolation, restore from backups, root cause analysis and hardening, without ransom.
Process
Request
Describe your needs briefly via the form, WhatsApp or the live chat.
Assessment
Within one business day you receive an assessment with effort, price and a proposed date.
Implementation
I do the work personally, remotely via secured access or on site, and keep you updated throughout.
Handover and invoice
Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.
Questions about this service
Is a cybersecurity check a penetration test?
It contains elements of one: attack surface analysis, vulnerability scans and targeted manual checks. A full penetration test with exploitation of vulnerabilities is a separate project that I offer after the check when it makes sense.
Does NIS2 also affect small companies?
Directly affected are medium-sized and large companies in certain sectors, indirectly also their suppliers, because customers demand evidence. I check whether and how you are affected and implement the technical requirements.
What should we do in an acute incident?
Disconnect affected devices from the network, do not switch them off, do not delete anything and contact me. I help with containment, preserve evidence, restore operations and document the incident for insurance and authorities.
Remote for companies across Germany, alignment via video call, ticket or chat.