GDPR, NIS2 and the checklists sent by big customers and insurers circle around a shared core, just phrased differently: who can reach which data, how risk gets evaluated, what the plan is when something goes wrong. Build that core properly once and it serves every audience. Our approach follows ISO 27001 principles, with the Austrian Information Security Handbook and BSI IT-Grundschutz as reference points.
Privacy from the engineering angle: an inventory of systems holding personal data, visibility rules, a workable routine for subject access and deletion requests, and a playbook for the opening hours of a data breach.
Rules, risk analysis and emergency procedures written after interviewing your people, not copied from a boilerplate. The outcome mirrors how the business truly runs and survives an auditor’s questions.
Nine services covering the layers of your IT, from user identities and laptops to network, software, databases, websites and outbound data. Few organisations need the full set at the same time; the risk review decides what is urgent and what can safely sit on next year’s list.
Useful if you pay for Business Premium yet use a fraction of it, or if an EDR purchase has been left in audit mode. We start with a pilot group, widen the circle step by step and flip to enforcement without halting work.
RDP no longer reachable from the internet, CCTV and visitor wireless moved into separate network zones, and the software supplier connecting with a named login plus MFA.
Settling who in BMD may edit vendor bank details, which service account the Shopware store uses for syncing, and where the payment gateway’s secret key is stored.
Automatic detection of social insurance numbers, IBANs and lab results in documents, a nudge before anything goes to a private mailbox, hard blocks reserved for grave cases. A works council, if you have one, is brought in at the start.
No more shared superuser, stored data encrypted in MySQL or SQL Server, an audit trail on patient and client tables, and stray export files hunted down and deleted.
A Cloudflare or cloud-native WAF calibrated weeks before the festive season, so credential stuffing and card-testing bots are filtered out while paying visitors shop undisturbed.
A leaked password stops being sufficient on its own: MFA for everyone, business data reachable only from Intune-managed hardware, and admin privileges removed from daily accounts.
A WireGuard or IPsec tunnel linking head office and depot, BitLocker across the laptop fleet with keys escrowed in Entra ID, and a dedicated encrypted route for payroll files heading to your accountant.
Internal and external scanning each month, ranked using CERT.at advisories and evidence of exploitation in the wild. Leaner reports, a higher rate of patches genuinely applied.
Configuration done in January drifts out of step by the autumn, as people join, programs change and attackers adapt. The four services below carry on once the implementation project is closed.
With money tight, getting the sequence right counts for more than picking a vendor. For organisations employing between 10 and 250 people, we recommend the path below, which shuts the usual ways in first.
In a video meeting we list the requirements you already face: clauses in customer contracts, the insurer’s form, your GDPR duties. From this we derive the proof you must be able to show and the places where the most sensitive information lives.
MFA everywhere, leftover accounts of people who have left deleted, protection against forged payment instructions. This is how many attacks on smaller firms begin, and closing it is inexpensive.
EDR set to block, essential hardening, remote access hidden behind a VPN and a backup that someone has successfully restored. This layer either stops ransomware or limits the damage.
With the technology in place, the policies can record reality instead of intentions. Extras follow where the risk warrants them: a WAF, DLP, tighter network zoning or SOC monitoring.
Put a price on seven days of downtime first. An online shop taking €4,000 daily, or a distribution centre unable to issue delivery notes, will often lose more during a short outage than reasonable security spending adds up to over years. That calculation, not anxiety about penalties, is the best guide to your budget and your priorities.
The NIS2 Directive defines the relevant sectors, headcount and turnover thresholds and a number of exceptions; a lawyer should confirm where you stand under Austrian law. What we notice in practice is the ripple effect: small suppliers outside the scope get security questionnaires from customers inside it. We help you prepare the technical responses and supporting evidence.
We read the questionnaire with you and split it three ways: items you can truthfully confirm today, items that need a little work, and items that amount to a separate project. MFA, documented access rights, an incident procedure and a fresh vulnerability scan tend to satisfy much of such a list. Should the client insist on ISO 27001 certification, we support your preparation for it.
Certainly. Insurers ask remarkably similar things: MFA, offline or immutable backups, EDR, patching discipline, awareness training. We establish where your answer is a genuine yes, where it is not yet, and what closing each gap before renewal would cost. Claiming a control you do not have may leave you uninsured at the very moment a claim arises.
Unplug affected computers from the network but leave them powered on, because shutting down wipes traces. Using an uncompromised device, reset the admin passwords and email support@apply.at, or helpme@apply.at under an existing contract. Where personal data may be involved, the 72-hour clock for notifying the data protection authority is already ticking. Reporting to CERT.at is also an option.
It is. Conversations happen in Microsoft Teams or Google Meet; configuration is done through an encrypted remote connection that records each session. If some piece of hardware needs a physical touch, a colleague of yours or your local service partner does it while we talk them through it. The schedule is agreed after the first review and written into our offer.
A client’s checklist, an upcoming policy renewal, NIS2 duties or a concrete suspicion. Once we have reviewed things remotely, you will know the gaps, the order to close them in and the likely effort.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.