INFORMATION SECURITY

From cyber risks to digital resilience

From the checkup to the complete information security management system (ISMS): advice that adapts to your company, not the other way around.

  • BenefitsCertified experts and specialized lawyers
  • BenefitsProactive vulnerability analysis and effective NIS-2 compliance
  • BenefitsFor every size of company – from start-ups to conglomerates
Illustration: Information security at mip Consult
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Interdisciplinary team ✓ certified experts ✓ pragmatic implementation

See through complexity –
Building resilience

The digital threat landscape and ever-growing regulatory requirements present enormous challenges for companies. It is no longer enough to simply respond to incidents. Instead, proactive, systematic security management is required that meets legal requirements, closes technical vulnerabilities, and ensures the trust of customers and partners.

Services

Key points of our information security consulting

We provide resources and expertise pragmatically, in a hands-on manner, and in a way that is tailored to the needs of our clients.

Consultant

Marvin Süß

Consultant mip Consult GmbH

  • BenefitsInformation Security Consulting & External Information Security Officer (ISB)
    Comprehensive consulting services range from a baseline assessment, the creation of regulations and the implementation of employee training, to the establishment of a complete ISMS.
  • BenefitsEmergency management
    Clear escalation paths and documented reporting processes ensure that incidents can be quickly resolved and reported.
  • BenefitsTraining and awareness-raising
    We train your team practically using industry-specific scenarios in phishing detection, secure handling of customer data, and risk awareness.
  • BenefitsNIS-2 Consulting
    End-to-end solution for your NIS-2 compliance: Legal impact analysis, development of implementation plans with active support for implementation, and auditing of your supply chain.
  • BenefitsTechnical and organizational measures
    Implementation or project support for the introduction of a holistic ISMS, as well as technical and organizational measures (TOM) to protect your data and systems.
  • BenefitsInformation security checkup
    Inventory of your information security and advice for
    Management and security officers.
  • BenefitsControl and Auditing
    Systematic review of the implementation and effectiveness of your measures, including audits of your critical suppliers.
  • BenefitsExternal WebScan and internal VA scan
    Analysis of your publicly accessible infrastructure from an attacker's perspective and systematic identification of technical security vulnerabilities in your internal systems and networks.
our approach

So Start your information security consulting with us

We look forward to working with you. Please do not hesitate to contact us.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together we understand the current state, risks, and goals – both technically and organizationally.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting contract, our information security experts will begin the consulting process.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together, we understand the current state, risks, and goals – both technically and organizationally. Often, an advanced information security checkup is useful to assess the current situation.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting agreement, our information security experts begin the consulting process – usually with a kick-off meeting including a presentation of all the participants.

Prices & Packages

Our packages for your
Information Security Consulting

In all packages

Multilingual support

Personal contact person

Certified information security experts

Light

For small businesses

from 1.250€

/Month

net

  • External Information Security Officer (ISB)
  • Conducting a needs analysis and risk assessment
  • Creation of an information security policy
  • Drawing up a plan of action
  • Expert guidance and advice on establishing an ISMS
  • Access to ISMS templates
  • Contactability by phone or email

Pro

Popular

For growing companies

from 2.400€

/Month

net

All services from Light, plus:

  • Permanent contact person with representation
  • Monitoring and control of the ISMS
  • Consulting and support in the drafting of guidelines
  • Concrete recommendations for optimizing the process
  • Audit preparation
  • Training
  • Response times within one business day
  • Monthly status reports
  • An annual internal audit

Individual

For individual requirements

individual

Offer
upon request

  • Tailored to your exact requirements
  • Consulting as needed

Lawyers from Eggert & Partner Lawyers · Service in Germany · All prices are net excluding VAT.

Frequently asked questions

What is information security management?

The data protection management solely considers personal data for which appropriate technical and organizational measures must be implemented in accordance with Article 32 of the GDPR. The information security management, on the other hand, considers all data, all processing processes, and all processing systems, regardless of whether they relate to individuals.

The need for information security management arises not primarily from legal regulations (exceptions include KRITIS, NIS2-affected companies, and financial institutions affected by DORA), but from an individual assessment of one’s own risk or threat. Only those who know what information they need for what purpose and what the consequences would be if that information were lost or fell into the wrong hands can take appropriate measures to reduce the existing risks.

Typically, information security consulting includes:

  • Inventory and analysis: Information security checkup as well as identification of your critical assets and analysis of where requirements need to be met – from unprotected supply chains to a lack of risk assessments to incomplete documentation.
  • Establishing an ISMS: Project support for the implementation of a holistic information security management system, as well as consulting for management and security managers.
  • Technical and organizational measures: Implementation of technical data protection, in particular technical and organizational measures (TOM), as well as NIS2-compliant solutions such as zero-trust architectures and end-to-end encryption.
  • Training and awareness raising: Training your team in phishing detection, secure handling of customer data, and risk awareness – practically using industry-specific scenarios.
  • Continuous review: Regular checks are essential to ensure the effectiveness of your measures – many companies only discover vulnerabilities after external audits or security incidents.

The legally required technical data protection measures protect not only personal data but also other company data. There is a connection between the technical data protection measures and those of information security. Our experts in data protection and information security are happy to assist you in implementing technical and organizational measures or in establishing a holistic information security management system.

Is my company affected by NIS2?

German legislation implementing the directive provides for the classification of affected companies as „important“ or „particularly important“ institutions. An estimated 40,000 companies in Germany fall under the NIS-2 directive. From 50 employees or from 10 million euros in revenue or balance sheet value, the directive can apply to companies. Many online self-assessment checks only provide general results, which often overlook essential details. We thoroughly examine,
whether your company falls within the scope of the new regulations – the result of our legal analysis provides you with certainty and can serve as a powerful argument in dealings with clients and authorities.


When does a company need information security advice?

The need for information security management arises primarily not from legal regulations (exceptions include KRITIS, NIS2 affected companies, and financial institutions affected by DORA), but from an individual assessment of one’s own risk or threat.

The impact of NIS2 on an organization depends on its cybersecurity maturity: highly regulated industries such as healthcare may already meet many of the requirements, while less regulated sectors could face major challenges. Even organizations that are not directly affected by NIS2 could feel its impact if they are suppliers or partners of regulated companies. These companies must demonstrate the security of their supply chain.


Support me sofortdatenschutz.de with all your questions about Information security?

Our experts in data protection and information security are happy to assist you in implementing technical and organizational measures or in establishing a holistic information security management system.


Other services

Information security services,
that suits your company.