IT Security Consulting for Companies
Cyber Security Consulting: A Level of Protection That Holds Up When It Counts
Cyber security consulting sorts the security of an IT landscape along three questions: what is reachable from the outside, how much of that can actually be exploited, and how much of that would anyone even notice. It rarely becomes important gradually — it becomes important on a date, when a major customer makes a certificate a condition of the contract, a supervisory authority expects a registration, an incident has exposed a gap, or a cloud and production environment grows faster than the control over it. What that calls for is a dependable inventory of your own systems, a sequence that starts at the largest risk rather than at the loudest alert, and evidence that stands up to an audit. That is the working ground of it security consulting.
Leading companies trust our network
What Cyber Security Consulting Delivers — and What It Does Not

IT security consulting — traded in the market under labels such as cyber security consulting, cybersecurity consulting, security consulting and information security consulting — works on one question: how resilient the protection of an organisation actually is. Its subject matter is security strategy, risk and vulnerability management, attack detection and the response to incidents. The starting point is an observation nearly every grown IT landscape shares: what a company operates grows faster than what it can evidence about it. That distance is where the work sits.
It separates attack surface from attack path. A great deal is reachable: a forgotten test server, a SaaS account without a second factor, a controller on the plant network, a service provider with remote access. Only part of that is exploitable, and what turns dangerous is the chain — the access that leads to privileges that lead to data. A list of a thousand findings is not a result; the result is the short enumeration of the paths that run from the outside all the way to something that matters.
It counts in evidence, not in tools. A firewall nobody maintains and an alert nobody reads do not raise the level of protection — they raise the number of systems. Every measure therefore comes with a named owner, an interval and a trail showing that it works. That trail is exactly what a customer, an insurer or a regulator wants to see; the tool alone interests none of them.
It plans for the day after the incident. Prevention has a ceiling, because every new application creates new reachability. What determines the damage is the time to detection and the question of whether anyone knows who decides and where a clean restore comes from. Whoever settles that during an attack loses days they do not have.
What it does not deliver. It cannot guarantee security and cannot bring residual risk to zero — anyone promising that is selling a feeling. It also does not replace legal advice: whether a rule applies in a given case, and how far the responsibility of the management board reaches, belongs in front of a lawyer. And it does not take operations off the line organisation: without IT operations, procurement and the business units, every measure stays a document.
Data protection in the narrower sense, contract drafting and regulatory interpretation belong to a different discipline — the profiles for that sit under Compliance & Legal. Platform architecture and identity services overlap with Cloud, Infrastructure & DevOps; here the security view takes the lead.
When Outside Support Makes the Difference in IT Security
Not every security question needs help from outside. Where the situation is known, capacity is free in-house and a comparable case has been handled before, the internal route is the faster one. In the situations below the arithmetic comes out differently — usually for reasons of time rather than of expertise: whoever keeps operations running cannot work through their weaknesses at the same time.
1. A Customer or Tender Demands Proof of Security
- Without a certificate or a completed security questionnaire, the bid drops out of the evaluation.
- The proof touches areas in which nobody has documented ownership so far.
2. A Supervisory Duty Reaches the Company for the First Time
- Whether the company is in scope is unclear, because it depends on sector, headcount and revenue at once.
- Registration, reporting channels and risk management have to be evidenced, not merely intended.
3. An Incident Has Happened — or Was Only Just Avoided
- Encrypted systems or a suspicious account tie up the entire IT leadership.
- The cause has to be established in parallel with the restore — both at once overwhelms small teams.
4. The Attack Surface Has Grown Overnight
- Cloud migration, an acquisition or plant networking put systems online that nobody has inventoried.
- Service provider access has grown without anyone withdrawing it again.
5. Alerts Pile Up Without Anyone Working Through Them
- The tools are in place, but their messages are not prioritised — the alarm turns into background noise.
- There is no rule on who reacts and when; at night and at weekends least of all.
6. A Key Role in the Security Organisation Is Vacant
- The lead for information security is unfilled while an audit is running.
- The market for these profiles is tight and a replacement takes time — the duties run on regardless.
Do you recognise your own situation in one of these warning signs? Twenty minutes are enough for a first delineation: which proof is needed first — and whether you need somebody from outside for it at all.
The Protection Layers IT Security Consulting Works On
The layers below cover most of what gets asked for in practice — a selection, not a closed list. Rarely is everything worked on at once: usually one trigger pulls a single layer forward, and the rest follow in the order that the risk dictates.
Security Strategy, ISMS and ISO 27001
Establish protection requirements, assess risks, set policies and responsibilities, and carry all of it into a management system that survives an audit. That includes the scope, the risk methodology, the justification for the chosen measures and the preparation for an external audit.
Risk Analysis, Vulnerabilities and Penetration Testing
Take stock, make externally reachable systems visible, rate the weaknesses and put them in order. That includes recurring scans, targeted penetration tests and a procedure that turns findings into tasks with a date and an owner.
Security Operations: SOC Setup, SIEM and Attack Detection
Bring together events from the network, endpoints and cloud, write detection rules and pace operations so that an alert actually gets handled. That includes connecting the data sources, the detection use cases and the question of what runs in-house and what a service provider takes on.
Incident Response and Digital Forensics
From the first suspicion to the report: containment, evidence preservation, root cause analysis and a restore that does not copy a back door along with it. That includes a rehearsed emergency plan, clear decision paths and a review that turns the incident into a lasting change.
Cloud and Application Security
Secure permissions, network segments and configurations in AWS, Azure or Google Cloud — and your own software with them. That includes threat modelling, checks inside the development pipeline, the handling of third-party code and an access model without blanket trust.
OT and Production Security
Secure controllers, machine networks and remote maintenance access without stopping the plant. That includes an inventory of the automation technology, the separation of office and plant network, the handling of legacy systems that can no longer be patched, and the zone concepts of IEC 62443.
Which of these layers comes first in your organisation depends on where the shortest path from the outside to something important runs today. Sketch your starting position — what comes back is a judgement, not slideware.
The Engagement Formats Security Experience Comes In
What decides the effect is often less the depth of expertise than the frame: the mandate somebody arrives with, how much access is agreed, and who carries the residual risk in the end. Switching format mid-course is the normal case. Three things hold across all of them: a named internal counterpart with access to the management board, objectives written down before day one, and an agreement on what gets handed over at the end.
Independent Assessment of the Level of Protection
An experienced individual records systems, responsibilities and measures and names the paths that run from the outside to something essential — on the basis of their own examination, not of the policies presented.
Short-Term Reinforcement During an Incident
For encryption, data exfiltration or a suspicious account: fast staffing, high availability, tight coordination with IT leadership and the management board — one incident, one objective, one closing report.
Interim CISO With Decision-Making Authority
Somebody from outside takes over the lead for information security — during a vacancy, in a build-up phase, or where an authority is needed that does not sit inside the grown web of interests. With budget and reporting responsibility and a structured handover.
Building an ISMS and Security Operations
A small team builds the management system, the detection rules and the reporting channels so that they keep running unattended — and makes sure deviations surface early rather than in an audit.
Cyber Security by Industry: Which Rulebook Sets the Bar
The craft of IT security looks similar across industries; what differs is the rulebook it is measured against and the question of which outage hurts first. In manufacturing every minute of plant downtime counts, in a hospital it is patient care, at a grid operator it is security of supply — and in financial supervision it is the completeness of the evidence. Somebody who comes from the industry knows that ranking and does not have to learn it first: they know what each auditor asks for, which legacy systems typically stand in this environment and which measure will founder on the resistance of operations. That is why we staff security engagements by industry experience and not by tool knowledge alone — from a network covering more than 25 disciplines and over 300 role profiles. The six fields below are the ones we are asked for most often; they stand as examples and do not exclude others.
Financial Services and Insurance
Hardly any sector is supervised this densely: regulatory requirements for IT, rules on digital operational resilience and card payment standards apply side by side and each demands its own evidence. The effort therefore sits less in the technology than in the completeness of the documentation and in outsourcing management — the service provider of a service provider belongs in the picture. What is wanted are profiles fluent in audit language and in technology at the same time.
Energy, Water and Critical Infrastructure
Operators of critical plants live with the hardest combination: control technology with a long service life, telecontrol links across the territory, legally required attack detection and a duty to supply that makes maintenance windows expensive. Progress here lies in segmentation, controlled access and a detection that also works where no security agent may be installed. The precise scope depends on thresholds and belongs to be checked, not estimated.
Industry and Manufacturing
In networked plants two cultures meet: IT thinks in update cycles, automation engineering thinks in plant availability. A restart at the wrong moment costs output immediately, which is why classic tools often may not be deployed. What works is the separation of office and production network, a controlled remote maintenance path for machine suppliers and passive detection inside the plant network — the IEC 62443 series serves as the framework.
Automotive and Supplier Industry
Pressure here comes from two sides. Inward, clients require an audited handling of engineering information before any data is exchanged at all. Outward, the product itself is connected: control units, diagnostic interfaces and over-the-air updates need security management across the lifecycle as described by ISO/SAE 21434. For suppliers that means two parallel strands of evidence — one for the company, one per component.
Public Administration and Authorities
Public bodies work inside their own framework: the BSI IT-Grundschutz supplies modules and requirements that audits are based on. Long procurement routes and specialist applications nobody can replace at short notice make it harder. What works is less a large programme than a defensible prioritisation, clear ownership and evidence that stays comprehensible after a change of staff.
Healthcare and Hospitals
Hospitals combine highly sensitive data with medical technology that may not be altered freely after approval, and with operations that have no downtime. Sector-specific security standards set the frame; the hurdle sits in daily practice: shared workstations, devices from many manufacturers on one network, and staff who in an emergency treat first and log in second. Only what does not lengthen the clinical workflow holds — everything else gets bypassed.
Financial Services and Insurance
Hardly any sector is supervised this densely: regulatory requirements for IT, rules on digital operational resilience and card payment standards apply side by side and each demands its own evidence. The effort therefore sits less in the technology than in the completeness of the documentation and in outsourcing management — the service provider of a service provider belongs in the picture. What is wanted are profiles fluent in audit language and in technology at the same time.
Energy, Water and Critical Infrastructure
Operators of critical plants live with the hardest combination: control technology with a long service life, telecontrol links across the territory, legally required attack detection and a duty to supply that makes maintenance windows expensive. Progress here lies in segmentation, controlled access and a detection that also works where no security agent may be installed. The precise scope depends on thresholds and belongs to be checked, not estimated.
Industry and Manufacturing
In networked plants two cultures meet: IT thinks in update cycles, automation engineering thinks in plant availability. A restart at the wrong moment costs output immediately, which is why classic tools often may not be deployed. What works is the separation of office and production network, a controlled remote maintenance path for machine suppliers and passive detection inside the plant network — the IEC 62443 series serves as the framework.
Automotive and Supplier Industry
Pressure here comes from two sides. Inward, clients require an audited handling of engineering information before any data is exchanged at all. Outward, the product itself is connected: control units, diagnostic interfaces and over-the-air updates need security management across the lifecycle as described by ISO/SAE 21434. For suppliers that means two parallel strands of evidence — one for the company, one per component.
Public Administration and Authorities
Public bodies work inside their own framework: the BSI IT-Grundschutz supplies modules and requirements that audits are based on. Long procurement routes and specialist applications nobody can replace at short notice make it harder. What works is less a large programme than a defensible prioritisation, clear ownership and evidence that stays comprehensible after a change of staff.
Healthcare and Hospitals
Hospitals combine highly sensitive data with medical technology that may not be altered freely after approval, and with operations that have no downtime. Sector-specific security standards set the frame; the hurdle sits in daily practice: shared workstations, devices from many manufacturers on one network, and staff who in an emergency treat first and log in second. Only what does not lengthen the clinical workflow holds — everything else gets bypassed.
Security Projects That Get Commissioned Regularly — and the Evidence They Produce
What actually gets commissioned can largely be traced back to a handful of engagement patterns. Each has a recurring starting position, a sequence that holds, and a piece of evidence agreed before the start and checked during the engagement — not estimated at the end. The list is a selection.
Establish Whether NIS2 Applies to Your Organisation
Starting position: it is unclear whether — and in which category — the company falls under the new rules; the answer depends on sector, size and group structure at once. The sequence that holds: first justify and document the classification, then set up registration and reporting channels, then the measures. The evidence is a documented classification together with an action plan; the legal assessment belongs in front of a lawyer case by case.
Introduce a Management System to ISO 27001
Starting position: a customer demands a certificate, and inside the company single policies exist without a common frame. The route runs through scope and risk methodology, then the selection of measures and the evidence trail, and finally internal audit and management review. The evidence is a documentation set that survives an audit and a passed external audit — the certification body is engaged separately.
Work Through and Close a Security Incident
Starting position: systems are encrypted, data has left the building, or an account stood open longer than assumed. First containment and evidence preservation, then the proven root cause, then the restore — in that order, because a fast restore otherwise destroys the trail. The evidence is a forensic report with a substantiated point of entry and a list of measures that is re-checked later.
Order Cloud Access Along Zero Trust Lines
Starting position: permissions have grown over years, administrator rights are widespread, and access from your own network counts as trustworthy by default. The route runs through an inventory of identities and rights, then segmentation and strong authentication, and finally recurring recertification. The evidence is the share of privileged accounts and the number of accounts without a second factor — measured before and after.
Which Security Profiles Get Staffed in Practice
Which profile fits depends on the cut of the work: an assessment of the level of protection calls for a different profile than building an attack detection capability or investigating an incident. The profiles below are the ones asked for most often; the full overview sits on the category page.
The Stages of a Security Programme
Scope and duration depend on size, system landscape and data situation; the sequence does not: first know what is there, then assess it, then close the most dangerous paths, then evidence it. No stage is skipped; the only shortening happens where dependable groundwork already exists.
1. Record the Estate and Its Exposure
2. Assess Risks and Prioritise the Paths
3. Set the Measures and Assign Ownership
4. Implement Without Stopping Operations
5. Rehearse Detection and Emergency Procedures
6. Produce the Evidence and Make It Repeatable
Daily Rates in IT Security — and How a Security Programme Can Be Budgeted
Security profiles are paid by the day; there is no fixed price per project in this model. The rate hangs on four things: the depth of responsibility — whether somebody audits or answers for the information security of a company; the rarity of the specialisation — forensics, attack simulation and OT security are narrow markets; the urgency — staffing during a live incident costs more than a plannable programme; and the length of the engagement — longer mandates sit below the rate of a short emergency deployment.
The bands below are the daily rates published on our own role pages — not an offer, but what these profiles are called at:
- Interim CISO (Chief Information Security Officer): €1,100 – €1,900
- Freelance Cloud Security Engineer: €800 – €1,400
- Freelance Red Team Operator: €800 – €1,400
- Freelance Incident Response Specialist: €750 – €1,300
- Freelance Digital Forensics Analyst: €750 – €1,300
- Freelance Application Security Engineer (AppSec): €750 – €1,300
- Freelance Threat Hunter: €750 – €1,250
- Freelance Cybersecurity Consultant: €650 – €1,250
- Freelance SIEM Engineer (Splunk/QRadar): €650 – €1,200
- Freelance Vulnerability Management Specialist: €600 – €1,000
How a programme can be budgeted. Count in days worked, not in calendar months. An independent assessment of the level of protection sits in the low double-digit range of days. Building a management system spreads over months but consumes only a few days per week — the main load stays internal. An emergency deployment is close to full time; there it is the number of days on site that drives the cost, not the rate. A leadership stand-in is measured most honestly against what an unfilled security lead leaves behind in duties nobody got to.
What deliberately does not appear here. Audit fees of a certification body, licence costs of a detection platform and the prices of a testing provider are called by third parties — we do not quantify them. What we can quantify is the effort of the people we place.
Why this prices differently from a consulting firm. There a team is engaged in which one experienced person carries the responsibility and several junior people do the work — the blended calculation lowers the daily average and raises the number of days. Here it is the other way round: a higher rate for fewer heads, and the person who shows up is the one who then does the work. For bounded security engagements that is usually the smaller bill. This is also where cyber security consulting differs from a managed service: what is bought is a defined result, not a permanent capacity. Rates are net; VAT and travel expenses come on top.
The job titles in this market are predominantly English and often mean the same profile. Anyone looking for a security consultant — listed in tenders also as cyber security consultant, cybersecurity consultant, computer security consultant or information security consultant — will find them among the profiles under Cybersecurity. For more narrowly cut work there are the Freelance Cloud Security Engineer, the Freelance SIEM Engineer and the Freelance Application Security Engineer; the leadership role is filled by the Interim CISO. For adjacent questions, Compliance & Legal and Cloud, Infrastructure & DevOps add to the picture.
The Number of Known Vulnerabilities Grows Faster Than the Capacity to Close Them
29,500
119
€289bn
Frequently Asked Questions About Cyber Security Consulting
Excellent. We are not the only ones who think so.
consultingheads has received several awards from leading trade magazines and independent third parties.