IT security for SMEs: improve pragmatically instead of postponing

Cyberattacks no longer target only large corporations. Encrypted servers, stolen data, operations at a standstill — for mid-sized companies the risk is real, while time, budget and specialist knowledge for security are often missing.

On top of that comes growing external pressure: NIS2, security requirements from large customers along the supply chain, and cyber insurers demanding minimum standards.

I support companies in improving their IT security in a structured, proportionate way — not with fear and product sales, but with a clear view of processes, systems and the risks that actually matter.

What I help with

IT security does not start with tools, it starts with an overview. I help with:

  • Taking stock: which systems, data and access rights actually exist?
  • Identifying and prioritising risks — what would truly threaten the business, what is tolerable?
  • Implementing the basics with the biggest leverage: access control, updates, backups, email security
  • Assessing and answering external requirements: NIS2, customer audits, cyber insurance
  • Building incident readiness: what happens on day X — and who does what?
  • Considering security in digitalization and automation projects from the start (security by design)

For me, security is not an afterthought — it is part of every digitalization and architecture engagement.

Who this is for

This service is particularly useful for:

  • mid-sized companies without a dedicated security team
  • companies affected by NIS2 or asked by customers for security evidence
  • management teams that want to know where they really stand on IT security
  • companies that want to think digitalization and security together rather than one after the other

How we work together

01

Gain an overview

Together we map which systems, data, access rights and dependencies exist — often completely in one place for the first time.

02

Assess risks

Not every gap is equally critical. I prioritise by realistic damage to your business, not by the length of a checklist.

03

Prioritise measures

The basics with the biggest leverage come first: access control, updates, backups, email security, recovery capability.

04

Support implementation

Your IT team or service provider implements the measures — I structure, verify and translate between management and technology.

05

Keep it up

Security is not a project with an end date. We establish a simple rhythm of review, practice and adjustment.

If it becomes clear that systems need fundamental restructuring, this often also involves software architecture and technical project leadership.

What companies gain from this

The result is not a thick report for the drawer, but:

  • a realistic picture of your own security posture
  • prioritised measures instead of endless recommendation lists
  • solid answers for customers, auditors and insurers
  • a clear plan for the worst case
  • security built into processes instead of blocking them

Why crozzIT

My background

Since 2024 I have been working as an enterprise architect at a statutory health insurer — a critical-infrastructure (KRITIS) organisation where IT security and regulation are part of everyday work. Before that, more than ten years of backend and cloud architecture at companies like Zalando, Klarna and IONOS.

My approach

I am not a pentest provider and I do not sell security products. My contribution is the architect’s perspective: understanding how business, processes and systems interconnect — and anchoring security where it actually works.

Frequently asked questions

Are we even affected by NIS2?
Roughly speaking: companies with 50+ employees or €10M+ revenue in certain sectors may be affected — directly or indirectly as a supplier. An initial assessment is usually possible in a short conversation.
Do you also do penetration tests?
No. For pentests I work with specialised providers — I help commission them sensibly and put the results into context.
We have an IT service provider — is that not enough?
IT service providers keep systems running, but rarely look at security from a business and risk perspective. Only both together create a solid picture.
What is the best way to start?
With a compact assessment: systems, access rights, risks, prioritised recommendations. This is available as a manageable fixed-price package and provides a basis for all further decisions.
Does this replace an ISO 27001 certification?
No — but it is often the pragmatic first step. If certification becomes necessary later, the groundwork is not lost but feeds directly into it.

This may also be relevant

IT security often interlocks with these services:

Would you like to know where your company really stands on IT security?

In a first conversation we clarify your current situation, urgent questions and sensible next steps.

Let's talk about it