Our services
Support for growth strategies, transformations or M&A processes.
Our freelance experts have in-depth specialist knowledge in their field.
We provide you with experienced interim managers who take on responsibility.
Customized expert teams for complex projects
We find the best experts for these companies
Private equity
Efficient support throughout the deal cycle
Management consultancies
Flexible resources for demanding projects
Medium sized business
Consulting expertise for SMEs
Corporates
Technical and management experts for operational excellence
Scale-ups
Strategic & operational support for growth
Situation Picture

What Cyber Security Consulting Delivers — and What It Does Not

Abstract depiction of the layered defences of an IT landscape

IT security consulting — traded in the market under labels such as cyber security consulting, cybersecurity consulting, security consulting and information security consulting — works on one question: how resilient the protection of an organisation actually is. Its subject matter is security strategy, risk and vulnerability management, attack detection and the response to incidents. The starting point is an observation nearly every grown IT landscape shares: what a company operates grows faster than what it can evidence about it. That distance is where the work sits.

It separates attack surface from attack path. A great deal is reachable: a forgotten test server, a SaaS account without a second factor, a controller on the plant network, a service provider with remote access. Only part of that is exploitable, and what turns dangerous is the chain — the access that leads to privileges that lead to data. A list of a thousand findings is not a result; the result is the short enumeration of the paths that run from the outside all the way to something that matters.

It counts in evidence, not in tools. A firewall nobody maintains and an alert nobody reads do not raise the level of protection — they raise the number of systems. Every measure therefore comes with a named owner, an interval and a trail showing that it works. That trail is exactly what a customer, an insurer or a regulator wants to see; the tool alone interests none of them.

It plans for the day after the incident. Prevention has a ceiling, because every new application creates new reachability. What determines the damage is the time to detection and the question of whether anyone knows who decides and where a clean restore comes from. Whoever settles that during an attack loses days they do not have.

What it does not deliver. It cannot guarantee security and cannot bring residual risk to zero — anyone promising that is selling a feeling. It also does not replace legal advice: whether a rule applies in a given case, and how far the responsibility of the management board reaches, belongs in front of a lawyer. And it does not take operations off the line organisation: without IT operations, procurement and the business units, every measure stays a document.

Data protection in the narrower sense, contract drafting and regulatory interpretation belong to a different discipline — the profiles for that sit under Compliance & Legal. Platform architecture and identity services overlap with Cloud, Infrastructure & DevOps; here the security view takes the lead.

Warning Signs

When Outside Support Makes the Difference in IT Security

Not every security question needs help from outside. Where the situation is known, capacity is free in-house and a comparable case has been handled before, the internal route is the faster one. In the situations below the arithmetic comes out differently — usually for reasons of time rather than of expertise: whoever keeps operations running cannot work through their weaknesses at the same time.

1. A Customer or Tender Demands Proof of Security

  • Without a certificate or a completed security questionnaire, the bid drops out of the evaluation.
  • The proof touches areas in which nobody has documented ownership so far.

2. A Supervisory Duty Reaches the Company for the First Time

  • Whether the company is in scope is unclear, because it depends on sector, headcount and revenue at once.
  • Registration, reporting channels and risk management have to be evidenced, not merely intended.

3. An Incident Has Happened — or Was Only Just Avoided

  • Encrypted systems or a suspicious account tie up the entire IT leadership.
  • The cause has to be established in parallel with the restore — both at once overwhelms small teams.

4. The Attack Surface Has Grown Overnight

  • Cloud migration, an acquisition or plant networking put systems online that nobody has inventoried.
  • Service provider access has grown without anyone withdrawing it again.

5. Alerts Pile Up Without Anyone Working Through Them

  • The tools are in place, but their messages are not prioritised — the alarm turns into background noise.
  • There is no rule on who reacts and when; at night and at weekends least of all.

6. A Key Role in the Security Organisation Is Vacant

  • The lead for information security is unfilled while an audit is running.
  • The market for these profiles is tight and a replacement takes time — the duties run on regardless.

Do you recognise your own situation in one of these warning signs? Twenty minutes are enough for a first delineation: which proof is needed first — and whether you need somebody from outside for it at all.

Protection Layers

The Protection Layers IT Security Consulting Works On

The layers below cover most of what gets asked for in practice — a selection, not a closed list. Rarely is everything worked on at once: usually one trigger pulls a single layer forward, and the rest follow in the order that the risk dictates.

Security Strategy, ISMS and ISO 27001

Establish protection requirements, assess risks, set policies and responsibilities, and carry all of it into a management system that survives an audit. That includes the scope, the risk methodology, the justification for the chosen measures and the preparation for an external audit.

Risk Analysis, Vulnerabilities and Penetration Testing

Take stock, make externally reachable systems visible, rate the weaknesses and put them in order. That includes recurring scans, targeted penetration tests and a procedure that turns findings into tasks with a date and an owner.

Security Operations: SOC Setup, SIEM and Attack Detection

Bring together events from the network, endpoints and cloud, write detection rules and pace operations so that an alert actually gets handled. That includes connecting the data sources, the detection use cases and the question of what runs in-house and what a service provider takes on.

Incident Response and Digital Forensics

From the first suspicion to the report: containment, evidence preservation, root cause analysis and a restore that does not copy a back door along with it. That includes a rehearsed emergency plan, clear decision paths and a review that turns the incident into a lasting change.

Cloud and Application Security

Secure permissions, network segments and configurations in AWS, Azure or Google Cloud — and your own software with them. That includes threat modelling, checks inside the development pipeline, the handling of third-party code and an access model without blanket trust.

OT and Production Security

Secure controllers, machine networks and remote maintenance access without stopping the plant. That includes an inventory of the automation technology, the separation of office and plant network, the handling of legacy systems that can no longer be patched, and the zone concepts of IEC 62443.

Which of these layers comes first in your organisation depends on where the shortest path from the outside to something important runs today. Sketch your starting position — what comes back is a judgement, not slideware.

Engagement Formats

The Engagement Formats Security Experience Comes In

What decides the effect is often less the depth of expertise than the frame: the mandate somebody arrives with, how much access is agreed, and who carries the residual risk in the end. Switching format mid-course is the normal case. Three things hold across all of them: a named internal counterpart with access to the management board, objectives written down before day one, and an agreement on what gets handed over at the end.

Stocktaking
Independent Assessment of the Level of Protection

An experienced individual records systems, responsibilities and measures and names the paths that run from the outside to something essential — on the basis of their own examination, not of the policies presented.

Emergency
Short-Term Reinforcement During an Incident

For encryption, data exfiltration or a suspicious account: fast staffing, high availability, tight coordination with IT leadership and the management board — one incident, one objective, one closing report.

Interim Leadership
Interim CISO With Decision-Making Authority

Somebody from outside takes over the lead for information security — during a vacancy, in a build-up phase, or where an authority is needed that does not sit inside the grown web of interests. With budget and reporting responsibility and a structured handover.

Programme Work
Building an ISMS and Security Operations

A small team builds the management system, the detection rules and the reporting channels so that they keep running unattended — and makes sure deviations surface early rather than in an audit.

Sector Rules

Cyber Security by Industry: Which Rulebook Sets the Bar

The craft of IT security looks similar across industries; what differs is the rulebook it is measured against and the question of which outage hurts first. In manufacturing every minute of plant downtime counts, in a hospital it is patient care, at a grid operator it is security of supply — and in financial supervision it is the completeness of the evidence. Somebody who comes from the industry knows that ranking and does not have to learn it first: they know what each auditor asks for, which legacy systems typically stand in this environment and which measure will founder on the resistance of operations. That is why we staff security engagements by industry experience and not by tool knowledge alone — from a network covering more than 25 disciplines and over 300 role profiles. The six fields below are the ones we are asked for most often; they stand as examples and do not exclude others.

Compliance and IT security specialists of a financial services provider at work

Financial Services and Insurance

Power generation plant as an example of critical infrastructure

Energy, Water and Critical Infrastructure

Plant and IT specialists jointly reviewing a production network

Industry and Manufacturing

Digital vehicle model as a symbol for connected vehicle systems

Automotive and Supplier Industry

Administrative building as a symbol for the public sector

Public Administration and Authorities

IT specialists and clinical staff working at monitors in a hospital

Healthcare and Hospitals

Compliance and IT security specialists of a financial services provider at work

Financial Services and Insurance

Power generation plant as an example of critical infrastructure

Energy, Water and Critical Infrastructure

Plant and IT specialists jointly reviewing a production network

Industry and Manufacturing

Digital vehicle model as a symbol for connected vehicle systems

Automotive and Supplier Industry

Administrative building as a symbol for the public sector

Public Administration and Authorities

IT specialists and clinical staff working at monitors in a hospital

Healthcare and Hospitals

Engagement Patterns

Security Projects That Get Commissioned Regularly — and the Evidence They Produce

What actually gets commissioned can largely be traced back to a handful of engagement patterns. Each has a recurring starting position, a sequence that holds, and a piece of evidence agreed before the start and checked during the engagement — not estimated at the end. The list is a selection.

Establish Whether NIS2 Applies to Your Organisation

Starting position: it is unclear whether — and in which category — the company falls under the new rules; the answer depends on sector, size and group structure at once. The sequence that holds: first justify and document the classification, then set up registration and reporting channels, then the measures. The evidence is a documented classification together with an action plan; the legal assessment belongs in front of a lawyer case by case.

Introduce a Management System to ISO 27001

Starting position: a customer demands a certificate, and inside the company single policies exist without a common frame. The route runs through scope and risk methodology, then the selection of measures and the evidence trail, and finally internal audit and management review. The evidence is a documentation set that survives an audit and a passed external audit — the certification body is engaged separately.

Work Through and Close a Security Incident

Starting position: systems are encrypted, data has left the building, or an account stood open longer than assumed. First containment and evidence preservation, then the proven root cause, then the restore — in that order, because a fast restore otherwise destroys the trail. The evidence is a forensic report with a substantiated point of entry and a list of measures that is re-checked later.

Order Cloud Access Along Zero Trust Lines

Starting position: permissions have grown over years, administrator rights are widespread, and access from your own network counts as trustworthy by default. The route runs through an inventory of identities and rights, then segmentation and strong authentication, and finally recurring recertification. The evidence is the share of privileged accounts and the number of accounts without a second factor — measured before and after.

Role Profiles

Which Security Profiles Get Staffed in Practice

Which profile fits depends on the cut of the work: an assessment of the level of protection calls for a different profile than building an attack detection capability or investigating an incident. The profiles below are the ones asked for most often; the full overview sits on the category page.

The Stages of a Security Programme

Scope and duration depend on size, system landscape and data situation; the sequence does not: first know what is there, then assess it, then close the most dangerous paths, then evidence it. No stage is skipped; the only shortening happens where dependable groundwork already exists.

Step 1: recording the systems and their exposure from the outside

1. Record the Estate and Its Exposure

It starts with an honest list: which systems, accounts and service providers actually exist — not which ones appear in the architecture diagram.
Externally reachable addresses, cloud accounts and remote maintenance paths are searched for, not asked about.
The result is a picture of the attack surface that the IT team recognises.
Step 2: assessing the risks and prioritising the attack paths

2. Assess Risks and Prioritise the Paths

Findings are not sorted by the severity rating of the tool but by where they lead.
Out of a thousand individual alerts emerge the few attack chains that run from the outside to data worth protecting.
Where data is missing, it is measured for a limited period instead of carrying assumptions forward.
Step 3: setting the measures and assigning ownership

3. Set the Measures and Assign Ownership

Every measure comes with a named owner, a date and a verifiable piece of evidence.
What is deliberately not done is documented as an accepted risk rather than passed over in silence.
The order follows the risk, not the ease of implementation.
Step 4: implementing the measures while operations continue

4. Implement Without Stopping Operations

Changes to permissions, segments and configurations are trialled on a limited scope first.
In production and hospital networks it is operational compatibility that decides what may be deployed.
Resistance usually points at a constraint that was missing from the plan.
Step 5: rehearsing attack detection and the emergency procedures

5. Rehearse Detection and Emergency Procedures

Detection rules are tested against known attack patterns — a rule that never fired is not evidence.
Reporting and decision paths are rehearsed before they are needed for the first time in a real event.
Every exercise produces a short list of corrections, not a presentation.
Step 6: producing the evidence and handing over to routine operations

6. Produce the Evidence and Make It Repeatable

The state of play is documented so that it survives an audit and stays comprehensible after a change of staff.
Recurring checks are given an interval and an owner so that the level reached does not quietly decay.
At the end stands a handover to your own organisation, not a standing engagement.
Price Structure

Daily Rates in IT Security — and How a Security Programme Can Be Budgeted

Security profiles are paid by the day; there is no fixed price per project in this model. The rate hangs on four things: the depth of responsibility — whether somebody audits or answers for the information security of a company; the rarity of the specialisation — forensics, attack simulation and OT security are narrow markets; the urgency — staffing during a live incident costs more than a plannable programme; and the length of the engagement — longer mandates sit below the rate of a short emergency deployment.

The bands below are the daily rates published on our own role pages — not an offer, but what these profiles are called at:

How a programme can be budgeted. Count in days worked, not in calendar months. An independent assessment of the level of protection sits in the low double-digit range of days. Building a management system spreads over months but consumes only a few days per week — the main load stays internal. An emergency deployment is close to full time; there it is the number of days on site that drives the cost, not the rate. A leadership stand-in is measured most honestly against what an unfilled security lead leaves behind in duties nobody got to.

What deliberately does not appear here. Audit fees of a certification body, licence costs of a detection platform and the prices of a testing provider are called by third parties — we do not quantify them. What we can quantify is the effort of the people we place.

Why this prices differently from a consulting firm. There a team is engaged in which one experienced person carries the responsibility and several junior people do the work — the blended calculation lowers the daily average and raises the number of days. Here it is the other way round: a higher rate for fewer heads, and the person who shows up is the one who then does the work. For bounded security engagements that is usually the smaller bill. This is also where cyber security consulting differs from a managed service: what is bought is a defined result, not a permanent capacity. Rates are net; VAT and travel expenses come on top.

The job titles in this market are predominantly English and often mean the same profile. Anyone looking for a security consultant — listed in tenders also as cyber security consultant, cybersecurity consultant, computer security consultant or information security consultant — will find them among the profiles under Cybersecurity. For more narrowly cut work there are the Freelance Cloud Security Engineer, the Freelance SIEM Engineer and the Freelance Application Security Engineer; the leadership role is filled by the Interim CISO. For adjacent questions, Compliance & Legal and Cloud, Infrastructure & DevOps add to the picture.

Threat Landscape

The Number of Known Vulnerabilities Grows Faster Than the Capacity to Close Them

29,500

entities in Germany fall under the supervision of the BSI since the NIS2 Implementation Act — previously it was around 4,500. For most of them it is the first regulation of this kind.
BSI, December 2025

119

new vulnerabilities became known per day in the reporting period from July 2024 to June 2025 — 24 percent more than the year before. The volume grows faster than any patching capacity.
BSI Situation Report 2025

€289bn

in damage from data theft, espionage and sabotage hit the German economy within twelve months; 87 percent of the companies surveyed were affected.
Bitkom, Wirtschaftsschutz 2025
Questions From Practice

Frequently Asked Questions About Cyber Security Consulting

Cyber security consulting establishes the level of protection of an organisation, improves it and makes it evidenceable. That includes recording the systems and their exposure, assessing the risks, implementing the measures, building an attack detection capability and preparing for a real event. What stands at the end is not a tool but an owner, an interval and evidence that survives an audit. In the market the same work is also offered as it security consulting, cybersecurity consulting or information security consulting.
NIS2 is an EU directive on cyber security; in Germany the NIS2 Implementation Act has applied since December 2025. It widens the circle of regulated entities considerably — the BSI now supervises around 29,500 entities instead of some 4,500 before. Whether a company is in scope depends on the sector and on thresholds for headcount and revenue at the same time. The duties include registration, risk management measures and the reporting of significant incidents. This account is orientation and does not replace legal advice: scope and duties belong to be assessed case by case by a lawyer.
ISO/IEC 27001 is the international standard for information security management systems. It does not prescribe a particular technical setup but a traceable cycle: define the scope, assess the risks, select measures with reasons, operate them, review them. It pays off above all where customers or tenders require it. The certificate is issued by an independent body; consulting and auditing may not come from the same hand.
Information security is the widest term: it protects information regardless of the medium, so paper, conversations and processes as well. IT security means the protection of the technical systems on which that information is processed. Cyber security is the view onto threats from the networked space and includes attackers, their methods and the response to them. The difference becomes noticeable in the evidence demanded: a management system follows information security, an attack detection capability follows cyber security. That is also why information security consulting and it security consulting are not always the same engagement.
The titles are predominantly English and are used that way in German tenders too. A security consultant — depending on the tender also called cyber security consultant, cybersecurity consultant, computer security consultant or information security consultant — assesses security architecture, policies and measures and accompanies their implementation; with us that is the Freelance Cybersecurity Consultant. A cyber security specialist or it security expert works more closely on one field — cloud, SIEM or application security. An information security expert is usually sought for the management side: ISMS, policies, evidence. Anyone searching for professional security consultants in English-language tenders means the same group. The leadership role is called CISO and is filled with us as an Interim CISO. For the selection, the title matters less than the question of whether somebody is meant to audit, to build or to answer for it.
It is paid by the day. The bands published on our role pages run from €600 to €1,900 per day, depending on profile and responsibility. Method-driven roles sit at the lower end, leadership stand-ins at the upper. What a programme costs in total is decided by the number of days worked: an assessment of the level of protection sits in the low double-digit range of days, an emergency deployment close to full time. Third-party services such as audit fees or licences are not included.
For an Interim CISO we publish €1,100 to €1,900 per day, for a Freelance Red Team Operator €800 to €1,400, for a Freelance Incident Response Specialist €750 to €1,300. Where a staffing lands inside the band depends on company size, industry, regulation, the availability required and urgency. For a penetration test the scope sets the price — the number of applications tested, the depth of testing and whether the detection capability is tested along with it. It makes sense to fix the test scope first and then count it in days worked. VAT and travel expenses come on top.
OT security is the protection of operational technology: controllers, machine networks, process control systems and remote maintenance access in production, energy supply and building services. The difference sits in the ranking of the protection goals: in IT confidentiality usually comes first, in OT availability — a plant that halts for security reasons causes damage itself. On top of that come systems with twenty years of service life that cannot be patched. What is workable is segmentation, controlled access and passive detection; the framework is the IEC 62443 series.
You can rely on us

Excellent. We are not the only ones who think so.

consultingheads has received several awards from leading trade magazines and independent third parties.

Siegel_TOP-Berater
consultingheads-award-top-company-2025-kununu
consultingheads-brand-eins-beste-berater-2025-1
consultingheads-kununu-top-company-2024
consultingheads-brand-eins-beste-berater-2024-3
consultingheads-kununu-top-company-2023 (1)
consultingheads-kununu-top-company-2023 (1)
consultingheads-brand-eins-beste-berater-2019-1
consultingheads-brand-eins-beste-berater-2021
consultingheads-brand-eins-beste-berater-2020
BrandEins_Berater2026_Logo_DE_basic
Siegel_TOP-Berater
consultingheads-award-top-company-2025-kununu
consultingheads-brand-eins-beste-berater-2025-1
consultingheads-kununu-top-company-2024
consultingheads-brand-eins-beste-berater-2024-3
consultingheads-kununu-top-company-2023 (1)
consultingheads-kununu-top-company-2023 (1)
consultingheads-brand-eins-beste-berater-2019-1
consultingheads-brand-eins-beste-berater-2021
consultingheads-brand-eins-beste-berater-2020
BrandEins_Berater2026_Logo_DE_basic
bildmarke
brand eins Best Management Consultants 2026 — consultingheads
Next Step

Let's Talk About Your Level of Protection.

A first delineation of the most pressing security question in conversation
One named next step instead of a proposal
Free of charge and without sales pressure
Twenty minutes in which we place your starting position and name which piece of evidence you need first — and whether this is a job for outside help at all.