Skip to content

Consulting

Advisory that lives on in the platform

Every engagement lands in your KaitoSec workspace. Findings, decisions and evidence stay with you, not in a PDF. You run the system yourself afterwards.

Our core principle

Consulting that makes you independent

Every analysis, decision and follow-up task is documented where your team will continue the work. Knowledge remains findable after the engagement, and responsibility transfers to your organisation in a controlled way.

01

Consulting without platform

The outcome is a document. You organise the continuation separately.

02Recommended

Consulting plus platform

Outcome, owners and future reviews remain workable

03

Platform without consulting

You operate independently. Expert support joins only where needed.

Service catalog

L-015 days

Gap Analysis

Structured assessment of your information security posture with a clear action plan.

  • Day 1: Kick-off, scope definition, document review
  • Day 2 to 3: Interviews (IT, management, departments), process analysis
  • Day 4: Gap assessment, measure prioritization
  • Day 5: Report creation, closing presentation

L-026 to 9 months

ISMS Implementation Support

Building your Information Security Management System from the ground up, step by step.

  • Month 1: Kick-off, scope, context of organization (Ch. 4)
  • Month 2: Risk assessment, Statement of Applicability
  • Month 3: Policy creation (core policies)
  • Month 4: Measure planning, responsibilities
  • Month 5: Awareness training, incident process
  • Month 6: Internal audit, management review
  • Month 7+: Close gaps, audit preparation

L-034 weeks

Certification Support

Targeted preparation for your ISO 27001 certification audit. Mock audit and remediation included.

  • Week 1: Document review, evidence check
  • Week 2: Mock audit (simulated audit day)
  • Week 3: Close gaps, remediation
  • Week 4: Stage 1 audit support (optional Stage 2)

L-04Ongoing

vCISO (Virtual CISO)

Your external information security officer. The scope scales with your need.

L-051 to 2 weeks

Internal Audit

Independent review of your ISMS for conformity and effectiveness. Mandatory under ISO 27001.

L-063 to 5 days

NIS2 Readiness Check

Assessment of your obligations and action items under the NIS2 Directive.

L-07Weekly, 2 hours

Resilience Café

Weekly 2-hour practitioner workshop. You bring one open question and leave with a working answer. Free for KaitoSec customers, capped at five participants per session so every seat gets fifteen minutes of focused attention.

  • Submit your question on Monday
  • Live working session on Thursday
  • Notes and follow-ups land in your workspace

L-080.5 to 1 day

Management Review

We run the annual review ISO 27001 and ISO 22301 require together with you. Half a day of structured agenda, run inside your KaitoSec workspace so the inputs, outputs and improvement actions stay on record.

  • Inputs: audit findings, risks, incidents, KPIs
  • Walk-through with management
  • Decisions and actions logged in the platform

L-09Per module

Training Packages

Awareness, admin and specialist modules delivered remote or on-site, 30 minutes to two hours per module. Priced per module, not per participant, with the content tailored to your scope before delivery.

  • End-user and awareness: M1, M8
  • Admin and security officer: M2 to M7
  • Specialist and partner: M9, M10

Terms

Remote day rate from €1,150. Fixed-price packages for gap analysis, NIS2 check and certification support, vCISO retainers from €576/month.

Travel costs: 2nd class rail, hotel for overnight stays (up to 150 EUR/night), no flights within DACH region. Alternatively: flat travel fee per on-site day.

Payment terms: 14 days after invoice receipt (standard, per T&C § 8).

Scope

We are not a certification body and may not conduct the certification audit ourselves (conflict of interest per ISO 17021). We support the customer up to and during the audit as a point of contact. The auditor comes from an accredited body (e.g. TUV, DQS, BSI).

What we do

  • Gap analyses & risk assessments
  • ISMS setup & policy creation
  • Employee training & awareness
  • Internal audit & mock audit
  • Certification support as point of contact
  • Ongoing CISO advisory (vCISO)
  • NIS2 readiness checks

What we don't do

  • Conduct certification audits ourselves
  • Penetration testing / technical security testing
  • Legal advice (we are happy to refer)
  • Data protection consulting as primary service (cooperation possible)

What should remain workable after the engagement?

We clarify the starting point, internal owner and smallest useful scope. Both sides then know whether consulting, platform or a combination fits.