Freelancers & founders
You need a clean setup for information security: pragmatic, affordable and able to grow with you.
I turn complex requirements into a clear plan and an information security system that works in practice.
10+years of
ISMS experience
50+audits
conducted
15+organisations
supported

A complete ISMS or a specific challenge. I start where you are and focus on what will move you forward.
I compare your current setup with the requirements, find the gaps and give you a prioritised action plan. Internal audits bring an independent view before your external assessment.
We build your ISMS with clear responsibilities, practical processes and documentation your team can use. Existing management systems become part of the structure.
I make risks visible, define proportionate measures and help you keep responsibilities and regulatory requirements manageable over time.
You always know where you stand, what comes next and who is taking care of it.
Let’s find your starting point30 minutes. Free and non-binding.We discuss your situation, your goal and whether we’re a good fit. No sales pressure.
Together, we assess where you stand, which requirements apply and what needs attention first.
We put policies, processes and measures into practice at a pace your organisation can sustain.
An internal audit and final refinements prepare you for certification or assessment.
From founders to regulated operators, I adapt the scope and pace to your situation. A single project or ongoing support.

You need a clean setup for information security: pragmatic, affordable and able to grow with you.
You’re facing a certification or customer requirement and want to meet it without the chaos.
KRITIS, IT Security Catalogue, data protection: you have to meet legal requirements and need reliable expertise, on a project basis too.
An audit is coming up, or no one owns security internally. I step in, focused and without a long ramp-up.

I help organisations make information security work in practice — and demonstrate it with confidence.
My focus is energy and IT: ISO 27001, KRITIS evidence, the IT Security Catalogue (EnWG) and customer audits. I also support manufacturers navigating new requirements from digitalisation and AI.
“Security should protect your work, not slow it down.”
We work as equals. I translate standards and legal requirements into practical steps, with the technical precision they demand.
You work directly with me. For larger projects, I bring in my trusted partner network.
Practical thinking on information security, audits and the work behind them.
Explore the journalEditorial previews
The questions that almost always come up in the first call, answered up front.
Have another question?Yes. Even without certification, a structured ISMS creates clarity about risks and responsibilities. I size it to fit your organisation, rather than overloading you with enterprise processes.
It depends on your starting point and scope. After the gap analysis you get a realistic timeline in clear stages, rather than a vague guess.
I work flexibly, per project or ongoing. After the free initial call you receive a transparent proposal that matches the scope. No hidden costs.
I take on or support that role, as much or as little as you need. For larger implementations I bring my partner network.
Yes. Whether a gap analysis, an internal audit or support at a specific point: we start exactly where things are stuck.
NIS2 extends cybersecurity obligations to many companies. We clarify specifically whether and how strongly you are affected, and derive what needs to be done.
Tell me where you stand. We’ll find the right starting point in a free, non-binding 30-minute call.