Skip to main content

Managed IT Services

We do not only advise on IT and information security, we implement: assess the security level, design the target architecture and processes, put measures in place and keep operations secure on an ongoing basis.

Assessed, not assumed

Scope and security level are established and documented

Ready for audit

Policies, controls and incidents are findable and evaluable on audit day

Legal included

Contracts, notification duties and liability handled by the lawyers in our firm

Lived day to day

We check whether measures work, rather than describing them once

What we take on

Security, structure and the ability to evidence it

IT security is not a product, it is a process. We own it together with your internal owners.

Typical triggers: Usually one event tips the balance: an audit, a customer requirement, a security incident, or a new directive with a fixed deadline.

NIS-2 or customer requirements call for evidence that stands up

Security measures are documented but not lived day to day

IT owners are tied up in day-to-day operations

There is no independent review of the actual security level

Services in detail

What we take on in information security

From the inventory through to ongoing operations. Commissioned individually, built on one another.

IT security management

Security does not come from individual tools, but from a managed information security system. We capture protection needs, build the ISMS to ISO 27001 and, if you wish, provide the information security officer who runs it on an ongoing basis.

What we handle

Inventory and determination of protection needs

External information security officer for set-up and ongoing operations

Build an ISMS to ISO 27001 and support through to certification

Audit against BSI IT-Grundschutz, from a basic check to a full audit

Security policies, risk and measures management

IT security, backup and erasure concepts

Get in touch without obligation

Ways of working together

A task, a process, or the whole function

You decide how much information-security responsibility goes outside. The three models sit side by side and often run in parallel. IT support and day-to-day system operations stay with you. You can start at any scale, and move between models at any time.

Targeted support

Steering stays with you

A NIS-2 scope analysis, a DORA gap analysis, an audit or a security assessment: a defined brief with a documented result.

Outsource processes

Process ownership sits with us

We build the ISMS, support you through to certification and keep it running: monitor controls, handle incidents, support audits and customer assessments.

Take on the function

Information security and team sit with us

We also take on your people: information security as a whole – policies, ISMS, the appointed information security officer and the evidence, including your security owners. We do not take on the helpdesk, endpoints or system operations.

How we work

From security level to operations you can stand behind

First the actual security level, then the target picture, then implementation, then the controls that carry the evidence on audit day.

  1. 01

    Process review

    We capture protection needs, risks, existing measures and evidence, and expose gaps between documentation and practice.

  2. 02

    Design

    We draft the target picture, policies, roles and controls, aligned to regulation, customer requirements and effort.

  3. 03

    Implementation & development

    We put measures in place, introduce the ISMS, involve service providers and document in an audit-proof way in CLAIR.

  4. 04

    Operation & optimisation

    We monitor controls, support audits and adjust measures as threats and requirements change.

Technology in the background

Evidence you can find on audit day

Policies, controls, incidents and measures are kept in CLAIR, with deadlines, owners and a status overview. Audit extracts are produced at the press of a button.

Modules in use: Compliance Management · Incident management · Service-provider steering · Reporting & Cockpits

More about CLAIR
CLAIR on a monitor: a board of reported incidents by status and risk assessment

Frequently asked questions

Questions about working with us

Do you replace our IT department?

We can take on information security in full, including the team if you wish. We do not take on IT support, the helpdesk or day-to-day system operations.

Does NIS-2 apply to us?

We clarify that in the scope analysis based on sector, size and supply relationships. The result is a documented classification, not an assumption.

How do law and technology work together?

Contracts, notification duties and liability questions are handled by lawyers in the same group, without a second provider.

How long does set-up take?

An inventory usually takes a few weeks. Building a management system you can stand behind is a programme over several months.

How robust is your security level?

We review your IT and information security processes and show which measures actually have an effect.

Get in touch without obligation

Rather get in touch directly

+49 40 257 660 900 anfrage@clarius-group.com

Rolandsbrücke 4, 20095 Hamburg

Contact form

Tell us briefly what you need. We pass your enquiry on to the colleagues who work on your topic.

Form loading …

Training portal

Demo access to the training portal

We will set up an account so you can review the modules and the evidence trail yourself.

Form loading …

Your personal contact

Josef Blank-Beck

Josef Blank-Beck

Chief Technology & Product Officer

Get in touch by email