- Financial services
- Banks, insurers, asset managers and payment firms under DORA in the EU and FINMA Circular 2023/1 in Switzerland. We work on ICT risk frameworks, third-party registers, threat-led testing and incident reporting.
- Industry and manufacturing
- Machine builders, automotive suppliers, chemicals and process industries with production networks that were never designed to be connected. Many now fall under NIS2, and those that sell connected products also face the Cyber Resilience Act.
- Energy and utilities
- Grid operators, generators, municipal utilities and water suppliers that count as critical infrastructure (KRITIS) in Germany or Switzerland. Our work spans control systems, substations, remote access and the reporting duties that come with operator status.
- Healthcare
- Hospitals, laboratories and providers of health IT, where availability affects patient care. We support network segmentation of medical devices, incident readiness and the C5 requirements for cloud processing of health data in Germany.
- Public sector
- Federal, state and cantonal administrations and public enterprises with long-lived systems and procurement rules to respect. We help with security concepts, cloud decisions and the evidence that oversight bodies ask for.