Remote for Germany

Cybersecurity for companies: find vulnerabilities, prevent attacks, handle incidents

Cybersecurity is no longer a luxury for small and medium-sized companies: ransomware, fake invoices by email and stolen credentials hit businesses of every size, and insurers, customers and laws such as NIS2 increasingly demand evidence. I bring the experience from operating infrastructure that is attacked every day into your company, with a clear view of what is real risk and what is scaremongering.

It starts with a cybersecurity check: I review your attack surface from the outside like an attacker and from the inside like an administrator, assess processes and access and deliver a prioritised action plan in plain language. On request I implement it from one source.

What is included

  • Cybersecurity check: external attack surface analysis (domains, servers, services, certificates, email security) and internal review of access, permissions, updates and backups
  • Vulnerability scans with OpenVAS and Nuclei plus manual review, security review of web applications according to the OWASP Top 10
  • Hardening of servers, firewalls, networks and workstations, patch management and update processes
  • Identities and access: multi-factor authentication, passkeys, password managers, separate admin accounts, offboarding processes
  • Email security against phishing and invoice fraud: SPF, DKIM, DMARC, filter rules and employee awareness
  • Logging and detection: central logging, alerting on suspicious logins, monitoring with Wazuh or Checkmk
  • Emergency plan and incident response: preparation, response to ransomware and data leaks, forensic preservation, recovery
  • Preparation for NIS2, ISO 27001 and cyber insurance requirements: gap analysis, action plan, documentation

Typical assignments

  • A law firm has its compliance with the requirements checked before taking out cyber insurance and closes the gaps within two weeks.
  • A manufacturing company falls under NIS2: gap analysis, action plan and implementation of the technical requirements.
  • After fake invoice emails, mailboxes are reviewed, forwarding rules removed, MFA and DMARC introduced.
  • Ransomware on a file server: isolation, restore from backups, root cause analysis and hardening, without ransom.

Process

  1. Request

    Describe your needs briefly via the form, WhatsApp or the live chat.

  2. Assessment

    Within one business day you receive an assessment with effort, price and a proposed date.

  3. Implementation

    I do the work personally, remotely via secured access or on site, and keep you updated throughout.

  4. Handover and invoice

    Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.

Questions about this service

Is a cybersecurity check a penetration test?

It contains elements of one: attack surface analysis, vulnerability scans and targeted manual checks. A full penetration test with exploitation of vulnerabilities is a separate project that I offer after the check when it makes sense.

Does NIS2 also affect small companies?

Directly affected are medium-sized and large companies in certain sectors, indirectly also their suppliers, because customers demand evidence. I check whether and how you are affected and implement the technical requirements.

What should we do in an acute incident?

Disconnect affected devices from the network, do not switch them off, do not delete anything and contact me. I help with containment, preserve evidence, restore operations and document the incident for insurance and authorities.

Remote for companies across Germany, alignment via video call, ticket or chat.

Ready to discuss your project?

Describe your project in a few sentences. You will receive an assessment with effort and price within one business day.