IT security for SMEs: improve pragmatically instead of postponing
Cyberattacks no longer target only large corporations. Encrypted servers, stolen data, operations at a standstill — for mid-sized companies the risk is real, while time, budget and specialist knowledge for security are often missing.
On top of that comes growing external pressure: NIS2, security requirements from large customers along the supply chain, and cyber insurers demanding minimum standards.
I support companies in improving their IT security in a structured, proportionate way — not with fear and product sales, but with a clear view of processes, systems and the risks that actually matter.
What I help with
IT security does not start with tools, it starts with an overview. I help with:
- Taking stock: which systems, data and access rights actually exist?
- Identifying and prioritising risks — what would truly threaten the business, what is tolerable?
- Implementing the basics with the biggest leverage: access control, updates, backups, email security
- Assessing and answering external requirements: NIS2, customer audits, cyber insurance
- Building incident readiness: what happens on day X — and who does what?
- Considering security in digitalization and automation projects from the start (security by design)
For me, security is not an afterthought — it is part of every digitalization and architecture engagement.
Who this is for
This service is particularly useful for:
- mid-sized companies without a dedicated security team
- companies affected by NIS2 or asked by customers for security evidence
- management teams that want to know where they really stand on IT security
- companies that want to think digitalization and security together rather than one after the other
How we work together
Gain an overview
Together we map which systems, data, access rights and dependencies exist — often completely in one place for the first time.
Assess risks
Not every gap is equally critical. I prioritise by realistic damage to your business, not by the length of a checklist.
Prioritise measures
The basics with the biggest leverage come first: access control, updates, backups, email security, recovery capability.
Support implementation
Your IT team or service provider implements the measures — I structure, verify and translate between management and technology.
Keep it up
Security is not a project with an end date. We establish a simple rhythm of review, practice and adjustment.
If it becomes clear that systems need fundamental restructuring, this often also involves software architecture and technical project leadership.
What companies gain from this
The result is not a thick report for the drawer, but:
- a realistic picture of your own security posture
- prioritised measures instead of endless recommendation lists
- solid answers for customers, auditors and insurers
- a clear plan for the worst case
- security built into processes instead of blocking them
Why crozzIT
My background
Since 2024 I have been working as an enterprise architect at a statutory health insurer — a critical-infrastructure (KRITIS) organisation where IT security and regulation are part of everyday work. Before that, more than ten years of backend and cloud architecture at companies like Zalando, Klarna and IONOS.
My approach
I am not a pentest provider and I do not sell security products. My contribution is the architect’s perspective: understanding how business, processes and systems interconnect — and anchoring security where it actually works.
Frequently asked questions
- Are we even affected by NIS2?
- Roughly speaking: companies with 50+ employees or €10M+ revenue in certain sectors may be affected — directly or indirectly as a supplier. An initial assessment is usually possible in a short conversation.
- Do you also do penetration tests?
- No. For pentests I work with specialised providers — I help commission them sensibly and put the results into context.
- We have an IT service provider — is that not enough?
- IT service providers keep systems running, but rarely look at security from a business and risk perspective. Only both together create a solid picture.
- What is the best way to start?
- With a compact assessment: systems, access rights, risks, prioritised recommendations. This is available as a manageable fixed-price package and provides a basis for all further decisions.
- Does this replace an ISO 27001 certification?
- No — but it is often the pragmatic first step. If certification becomes necessary later, the groundwork is not lost but feeds directly into it.
This may also be relevant
IT security often interlocks with these services:
- Digitalization Consulting – when clarity about processes, bottlenecks and priorities is needed first
- Software Architecture & Technical Project Leadership – when systems and technical decisions need structure
- Case study: Warehouse opening hours instead of Excel – how a small app replaced an Excel sheet at Zalando
- All services at a glance
Would you like to know where your company really stands on IT security?
In a first conversation we clarify your current situation, urgent questions and sensible next steps.
Let's talk about it