IT security

IT security for suppliers and manufacturers

Cyber security has become a contract question, not an IT question. We record the actual state of your websites, shops and servers, sort the findings by risk, and implement the measures.

From the audit to a hardened system.

Three steps that build on each other. The first one can be booked on its own, and that is where most companies start. This page goes further than the short version on the home page.

Audit

We record what is actually there, including the systems nobody has on a list any more.

  • Websites, shops and servers, reachable from outside and from within
  • Patch level of the operating system, the CMS and every plugin in use
  • Who has access to what, and which accounts still work after someone left
  • Findings written down and sorted by risk, not by how easy they are to fix

Hardening

We close the gaps in the order the audit put them in, at a time you set.

  • Updates, and a routine that keeps them coming
  • Access rights cut back to what a role needs, with two factor login
  • Encryption in transit and at rest, and backups that have been restored at least once
  • A web application firewall in front of the site, servers hardened against the CIS benchmarks, the industry standard for secure server configuration

Verification

We check that the work held, and we stay reachable when a customer asks you for proof.

  • A retest against the findings, so every item is either closed or explained
  • Monitoring that reports an outage or a failed backup before a customer notices
  • A repeat on a fixed schedule, usually once or twice a year
  • Security questionnaires answered with evidence instead of a promise

The rules that put this in your contracts.

None of them names your website. All of them reach it through the companies that buy from you.

Maritime suppliers

IACS UR E26 and E27

Classification societies require cyber resilience for ships contracted for construction on or after 1 July 2024. E26 covers the vessel, E27 the systems and equipment on board and their suppliers.

Supply chain

NIS2

In force since 6 December 2025, the German implementation act puts around 29,500 companies in 18 sectors under BSI supervision. Securing the supply chain is a named duty, so the rules reach smaller suppliers as a security questionnaire from their largest customer.

Buyer requirement

ISO 27001

Buyers ask suppliers for a certificate. It comes from an accredited body. We deliver the gap analysis, the technical measures and the documentation in front of it.

Two references from regulated environments.

Both were security mandates, not web projects.

Melitta online shop shown on a desktop display and a smartphone
IT Security

Melitta: three years of group security work. Hundreds of websites and thousands of services audited, Cloudflare Enterprise rolled out across the brand domains, and servers hardened against the CIS benchmarks. On top of that came secured build pipelines, a content security policy across every web property and regular penetration tests.

Security auditCloudflare EnterpriseCIS hardening
A security dashboard on a monitor and a phone
IT Security

Oldenburgische Landesbank: a gap analysis against ISO 27001 and BSI IT-Grundschutz during a bank acquisition. Several thousand control points assessed line by line, evidenced and prepared for the audit, together with the technical documentation, monitoring and the incident response plan. Day to day work in the security operations centre was part of the mandate: data exports were reviewed and released case by case, and staff were trained on phishing mails and tested with our own phishing simulations.

ISO 27001BSI IT-GrundschutzGap analysis
Security work sits next to the rest of what we do: the internal tools we build, the websites and shops in front of them and the service and support that keeps them current. The full list of client projects is on the references page.

What you get in writing.

An audit ends in documents you can hand on, not in a verbal summary.

A report sorted by risk

Every finding with what it is, what someone could do with it and how likely that is. The order is the risk, so the first page is the one worth reading first.

A plan with the effort against it

Each measure with the work it takes and what it costs, split into what we do and what your own people do. You decide what gets done and in which order.

Evidence for customer audits

What was checked, what was changed and when it was verified, written so it goes straight into the next security questionnaire.

Questions we get asked.

We are a small supplier. Is NIS2 our problem at all?

Directly, most likely not. Around 29,500 companies fall under the German act, as a rule from 50 employees or 10 million euro in turnover. Indirectly it reaches much further, because a customer in scope has to secure its own supply chain and passes the requirements on by contract. In practice that shows up as a security questionnaire from your largest customer.

Does an audit stop production?

No. We read, we scan from the outside and we look at configurations. Nothing is switched off and nothing is changed while the actual state is recorded. Changes belong to the hardening step, at a time you set, and each one has a way back.

How long does it take?

A first audit of a website, a shop and the server behind them takes a few days. Larger estates take longer, mostly because of how many systems nobody has a list of. You get the number in writing before anything starts.

We already have an IT service provider. Does that clash?

It does not. Most of what an audit turns up is work for the people who run your systems every day, and the report is written so they can pick it up. Where you want us to do a part ourselves, we do it and hand back the documentation.

Can you certify us to ISO 27001 or E27?

No, and nobody should promise that. A certificate is issued by an accredited body or a classification society. What we do is the work in front of it: the gap analysis, the technical measures and the evidence trail, which is the part that usually takes the longest.

What does a NIS2 supplier security audit cost?

You get a written estimate before you commit, based on how many systems are in scope. No retainer is attached to it, and an audit does not oblige you to have the measures done by us.

Start with the actual state.

Tell us what is in scope and you get a written estimate for the audit. If it is easier to talk it through first, take a slot.