Information security & auditHamburg. Working Germany-wide.

Clarity in security.Confidence to move.

ISO 27001KRITISNIS2

I turn complex requirements into a clear plan and an information security system that works in practice.

Arrange an initial call30 minutes. Free and non-binding.
For the systems your business depends on.
Explore what we can achieve

10+years of
ISMS experience

50+audits
conducted

15+organisations
supported

The right support.
At the right point.

A complete ISMS or a specific challenge. I start where you are and focus on what will move you forward.

Senior expertise.
One person accountable for the work.
Know where you stand

I compare your current setup with the requirements, find the gaps and give you a prioritised action plan. Internal audits bring an independent view before your external assessment.

Gap analysis / Compliance / Internal audits
Build a system that works

We build your ISMS with clear responsibilities, practical processes and documentation your team can use. Existing management systems become part of the structure.

ISMS development / Integrated management systems
Stay in control as you grow

I make risks visible, define proportionate measures and help you keep responsibilities and regulatory requirements manageable over time.

Risk management / Governance, Risk & Compliance

A clear path.
A steady hand.

You always know where you stand, what comes next and who is taking care of it.

Let’s find your starting point30 minutes. Free and non-binding.
  1. First, a conversation.

    We discuss your situation, your goal and whether we’re a good fit. No sales pressure.

  2. Then, a clear picture.

    Together, we assess where you stand, which requirements apply and what needs attention first.

  3. Practical progress.

    We put policies, processes and measures into practice at a pace your organisation can sustain.

  4. Ready for the next step.

    An internal audit and final refinements prepare you for certification or assessment.

Wherever you are.
Let’s start there.

From founders to regulated operators, I adapt the scope and pace to your situation. A single project or ongoing support.

Regulated environments
First structure

Freelancers & founders

You need a clean setup for information security: pragmatic, affordable and able to grow with you.

Room to grow

SMEs & growing companies

You’re facing a certification or customer requirement and want to meet it without the chaos.

Regulated environments

Larger & regulated organisations

KRITIS, IT Security Catalogue, data protection: you have to meet legal requirements and need reliable expertise, on a project basis too.

Support when it matters

Teams under audit pressure

An audit is coming up, or no one owns security internally. I step in, focused and without a long ramp-up.

Lydieth Triana

Expertise is personal.

Lydieth Triana, information security consultant and auditor
Lydieth TrianaInformation security consultant & auditorMeet me on LinkedIn

I help organisations make information security work in practice — and demonstrate it with confidence.

My focus is energy and IT: ISO 27001, KRITIS evidence, the IT Security Catalogue (EnWG) and customer audits. I also support manufacturers navigating new requirements from digitalisation and AI.

How I work
“Security should protect your work, not slow it down.”

We work as equals. I translate standards and legal requirements into practical steps, with the technical precision they demand.

You work directly with me. For larger projects, I bring in my trusted partner network.

The Triana journal

A clearer perspective.

Practical thinking on information security, audits and the work behind them.

Explore the journal

Editorial previews

A few things
you might ask.

The questions that almost always come up in the first call, answered up front.

Have another question?
Is ISO 27001 worth it for smaller companies?

Yes. Even without certification, a structured ISMS creates clarity about risks and responsibilities. I size it to fit your organisation, rather than overloading you with enterprise processes.

How long does certification take?

It depends on your starting point and scope. After the gap analysis you get a realistic timeline in clear stages, rather than a vague guess.

What does working together cost?

I work flexibly, per project or ongoing. After the free initial call you receive a transparent proposal that matches the scope. No hidden costs.

What if no one internally owns security?

I take on or support that role, as much or as little as you need. For larger implementations I bring my partner network.

Can you take on individual topics?

Yes. Whether a gap analysis, an internal audit or support at a specific point: we start exactly where things are stuck.

Are we affected by NIS2?

NIS2 extends cybersecurity obligations to many companies. We clarify specifically whether and how strongly you are affected, and derive what needs to be done.

Available for your next step

Good security
starts with
a conversation.

Tell me where you stand. We’ll find the right starting point in a free, non-binding 30-minute call.

Prefer to get in touch directly?
info@triana-consulting.de
Based in Hamburg
Germany-wide & remote

Tell me a little about your company.

I’ll get back to you to discuss how I can help. Fields marked * are required.