Area 08 · Security

IT security

Imagine a Graz tax consultancy employing twelve people. Within one week, an important client mails over a security questionnaire, the broker handling the cyber policy asks for confirmation that every login is protected by a second factor, and a member of staff falls for a counterfeit parcel notification in the Austrian Post’s design. It looks like three issues, but it is really one: the practice must be able to demonstrate its safeguards, and those safeguards must actually hold. This area brings GDPR and NIS2 documentation together with the technical controls behind it, delivered entirely by remote session and video meeting.

15
security services on offer
NIS2
plus Austria’s NIS Act for essential and important entities
72 h
deadline for telling the DSB about a personal data breach
0
on-site appointments; we operate remotely

Obligations and proof

GDPR, NIS2 and the checklists sent by big customers and insurers circle around a shared core, just phrased differently: who can reach which data, how risk gets evaluated, what the plan is when something goes wrong. Build that core properly once and it serves every audience. Our approach follows ISO 27001 principles, with the Austrian Information Security Handbook and BSI IT-Grundschutz as reference points.

Talk it through

Technical safeguards

Nine services covering the layers of your IT, from user identities and laptops to network, software, databases, websites and outbound data. Few organisations need the full set at the same time; the risk review decides what is urgent and what can safely sit on next year’s list.

Security solution roll-out

Useful if you pay for Business Premium yet use a fraction of it, or if an EDR purchase has been left in audit mode. We start with a pilot group, widen the circle step by step and flip to enforcement without halting work.

Infrastructure security

RDP no longer reachable from the internet, CCTV and visitor wireless moved into separate network zones, and the software supplier connecting with a named login plus MFA.

Application security

Settling who in BMD may edit vendor bank details, which service account the Shopware store uses for syncing, and where the payment gateway’s secret key is stored.

Data loss prevention (DLP)

Automatic detection of social insurance numbers, IBANs and lab results in documents, a nudge before anything goes to a private mailbox, hard blocks reserved for grave cases. A works council, if you have one, is brought in at the start.

Database security

No more shared superuser, stored data encrypted in MySQL or SQL Server, an audit trail on patient and client tables, and stray export files hunted down and deleted.

Web application firewall (WAF)

A Cloudflare or cloud-native WAF calibrated weeks before the festive season, so credential stuffing and card-testing bots are filtered out while paying visitors shop undisturbed.

Access control and endpoint protection

A leaked password stops being sufficient on its own: MFA for everyone, business data reachable only from Intune-managed hardware, and admin privileges removed from daily accounts.

VPN and encryption

A WireGuard or IPsec tunnel linking head office and depot, BitLocker across the laptop fleet with keys escrowed in Entra ID, and a dedicated encrypted route for payroll files heading to your accountant.

Vulnerability scans

Internal and external scanning each month, ranked using CERT.at advisories and evidence of exploitation in the wild. Leaner reports, a higher rate of patches genuinely applied.

Watching and maintaining

Configuration done in January drifts out of step by the autumn, as people join, programs change and attackers adapt. The four services below carry on once the implementation project is closed.

A sensible order of work

With money tight, getting the sequence right counts for more than picking a vendor. For organisations employing between 10 and 250 people, we recommend the path below, which shuts the usual ways in first.

01

Collect the demands

In a video meeting we list the requirements you already face: clauses in customer contracts, the insurer’s form, your GDPR duties. From this we derive the proof you must be able to show and the places where the most sensitive information lives.

02

Logins and mail

MFA everywhere, leftover accounts of people who have left deleted, protection against forged payment instructions. This is how many attacks on smaller firms begin, and closing it is inexpensive.

03

Endpoints, network, backup

EDR set to block, essential hardening, remote access hidden behind a VPN and a backup that someone has successfully restored. This layer either stops ransomware or limits the damage.

04

Paperwork and oversight

With the technology in place, the policies can record reality instead of intentions. Extras follow where the risk warrants them: a WAF, DLP, tighter network zoning or SOC monitoring.

Put a price on seven days of downtime first. An online shop taking €4,000 daily, or a distribution centre unable to issue delivery notes, will often lose more during a short outage than reasonable security spending adds up to over years. That calculation, not anxiety about penalties, is the best guide to your budget and your priorities.

Frequently asked questions

The NIS2 Directive defines the relevant sectors, headcount and turnover thresholds and a number of exceptions; a lawyer should confirm where you stand under Austrian law. What we notice in practice is the ripple effect: small suppliers outside the scope get security questionnaires from customers inside it. We help you prepare the technical responses and supporting evidence.

We read the questionnaire with you and split it three ways: items you can truthfully confirm today, items that need a little work, and items that amount to a separate project. MFA, documented access rights, an incident procedure and a fresh vulnerability scan tend to satisfy much of such a list. Should the client insist on ISO 27001 certification, we support your preparation for it.

Certainly. Insurers ask remarkably similar things: MFA, offline or immutable backups, EDR, patching discipline, awareness training. We establish where your answer is a genuine yes, where it is not yet, and what closing each gap before renewal would cost. Claiming a control you do not have may leave you uninsured at the very moment a claim arises.

Unplug affected computers from the network but leave them powered on, because shutting down wipes traces. Using an uncompromised device, reset the admin passwords and email support@apply.at, or helpme@apply.at under an existing contract. Where personal data may be involved, the 72-hour clock for notifying the data protection authority is already ticking. Reporting to CERT.at is also an option.

It is. Conversations happen in Microsoft Teams or Google Meet; configuration is done through an encrypted remote connection that records each session. If some piece of hardware needs a physical touch, a colleague of yours or your local service partner does it while we talk them through it. The schedule is agreed after the first review and written into our offer.

Share what is expected of you and where you stand today

A client’s checklist, an upcoming policy renewal, NIS2 duties or a concrete suspicion. Once we have reviewed things remotely, you will know the gaps, the order to close them in and the likely effort.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.