Consulting

Security architecture that holds.

We provide experienced security consultants for project work — remote across the DACH region, the EU and worldwide. The consulting builds on the same assessments our attack surface and SIEM analyses deliver, turning findings into architectures, processes and measures that hold. For organisations with their own SOC, a small team, or no security staff at all.

15+ years of security practice in regulated industries and critical infrastructure · Graydaxe Cybersecurity GmbH, Berlin
TARGET ARCHITECTURE — EXTRACT
IdentityIdentity & access management, passwordless, PKI, Active Directory hardening
NetworkZero trust architecture, segmentation and tiering, IT and OT
DetectionSIEM architecture, use case design, incident detection & response
CloudSecure architectures for AWS, Azure and Kubernetes, container security, CI/CD
Illustrative example · layers, not a customer architecture

Areas of focus

From the design through to operations.

IT and OT

Security architecture

Zero trust architectures, network segmentation and tiering, identity & access management, passwordless (FIDO2, Windows Hello), PKI, Active Directory hardening.

Build and run

SIEM, SOC and detection

Design and build of SIEM architectures for organisations without an existing SIEM, building and leading security operations centres, use case design, incident detection & response, threat hunting.

Process

Vulnerability & exposure management

Identification, assessment and prioritisation of vulnerabilities — including the results from attack surface monitoring.

Evidence

ISMS and compliance

Pragmatic implementation and development of an ISMS to ISO/IEC 27001; mapping to NIS2, KRITIS (§ 8a BSIG), DORA/BaFin (BAIT, MaRisk) and BSI IT-Grundschutz.

Platform

Cloud and DevSecOps

Secure architectures for AWS, Azure and Kubernetes; container security, CI/CD, infrastructure as code.

New

AI security

Securing AI-supported and data-driven applications: safe integration, LLM risks, governance.


Ways in

Three formats, building on each other.

Each format stands on its own. The results of one feed into the next.

INTRO

Awareness and orientation workshop

Framing the current threat landscape and typical attack scenarios, core principles such as zero trust, framework-based approaches for mid-sized companies, definition of the target state.

Result and scopeWorkshop presentation, a scope recommendation and acceptance criteria for the next steps · one workshop day plus preparation
BASIS

Readiness assessment

A structured review of security maturity against defined requirements from ISO/IEC 27001, NIST and best practice — with interviews, document review and implementation checks.

Result and scopeA readiness report with maturity, gaps and prioritised measures, plus a results session · typically one working week
STANDARD

Architecture, design, optimisation

Design, optimisation and technical support of security architectures across IT, cloud and OT domains, along the areas of focus above.

Result and scopeDeliverables are agreed per project and scope · billed by effort

Foundation

Standards we hold ourselves to.

StandardsISO/IEC 27001 · NIST CSF, SP 800-53, 800-207, 800-82 · BSI IT-Grundschutz and C5 · NIS2 · DORA · KRITIS (§ 8a BSIG) · MITRE ATT&CKCertifications in the teamCISSP · CISA · AWS Certified Solutions ArchitectEngagementRemote across the DACH region, the EU and worldwide

How we work together

Consultants are provided as a service through Graydaxe Cybersecurity GmbH. On request we introduce suitable consultants anonymously; profiles, availability and terms are provided on request.


Before that

It starts with a finding.

Architecture can be planned without knowing where you stand — it just will not hold. If you already run a SIEM or other security tools, start with their assessment; the results feed straight into the consulting. If you do not yet run one, start with the readiness assessment and build on its result.

To the SIEM and security tool assessment →

FAQ

Frequently asked questions

How are the consultants provided?

As a service through Graydaxe Cybersecurity GmbH — remote across the DACH region, the EU and worldwide. On request we introduce suitable consultants anonymously.

Do you work without a prior assessment?

Yes. Consulting does not require an assessment. If one exists, we build on those facts instead of gathering them again.

Do we need a security team of our own?

No. We work with in-house SOCs, with small teams, and with organisations that have no security staff at all.

What does an engagement cost?

Intro and Basis have a fixed scope. Standard is billed by effort. Profiles, availability and terms are provided on request.


What are you working on right now?

Tell us what is coming up — architecture, building a SIEM, ISMS or cloud. We will tell you whether and how we can help.