Skip to content

Services

Turn requirements into an operating model your team can carry.

Choose the entry point for your situation: define scope and build, bring existing data across, enable owners or stabilise ongoing operations.

Four pillars

The right entry point depends on the starting state

Each service delivers a defined outcome and can connect with the other building blocks.

Consulting

Decisions with context and handover

Gap analysis, build, audit preparation or vCISO: findings, rationale and next steps land in the workspace and remain with your team.

  • Scope and gap analysis
  • Prioritised implementation plan
  • Internal and external review preparation
  • Optional vCISO rhythm

Learn more

Onboarding

A guided start with a clear handover

From scope and roles to the first usable working state. The scope follows your data, maturity and desired guidance.

  • Setup, scope and accountability
  • First usable working state
  • Review and handover to operations
  • Optional: accelerated path with aiio

Learn more

Migration

Out of the legacy system

HiScout, verinice, eramba, SAVe or Secfix. We move assets, risks, controls and documents into KaitoSec, structured and traceable.

  • Inventory and export feasibility
  • Structured import of assets, risks, controls
  • Mapping to frameworks (ISO 27001, BSI, NIS2)
  • Sign-off and decommission of the legacy tool

Learn more

Training

Know-how that stays in the house

Awareness, admin and security officer practice, standards deep-dives. Modules booked individually or as a bundle, remote or on site.

  • End-user and awareness (M1, M8)
  • Admin and security officer (M2 to M7)
  • Standards deep-dive, incl. NIS2, TISAX, DORA (M10)
  • KaitoSec admin training M2 (included with onboarding)

Learn more

Typical path

How customers get going

Not every team needs every building block. The path follows scope, existing work and the next mandatory date.

01

Gap analysis

Stocktake against ISO 27001, BSI IT-Grundschutz or NIS2, with a prioritised action plan.

02

Onboarding

One guided working day from setup to the first operational workflow and handover.

03

Migration or build

We port your legacy ISMS data or build from scratch, mapped to your frameworks.

04

Training and handover

The team is enabled and the security officer is in the saddle. You decide what comes next: self-service, quarterly review or a vCISO mandate.

Which entry point fits you?

Bring your starting state, target operating model and next review or decision date. We define the appropriate service.