Security work for regulated organisations in Germany and Switzerland

We help banks, manufacturers, utilities, hospitals and public bodies meet NIS2, DORA and Swiss requirements, secure their plants and clouds, test their defences and prepare their teams for the day an incident happens.

Munich · Zurich
A mountain hut with one lit window on an alpine ridge at blue hour

Two jurisdictions, one standard of work

Security obligations in the German-speaking market have tightened in quick succession. Germany's NIS2 implementation act has been in force since 6 December 2025, without a transition period. DORA has applied to EU financial entities since 17 January 2025. In Switzerland, operators of critical infrastructure have had to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours since 1 April 2025, and FINMA Circular 2023/1 sets out how banks must manage operational risk and resilience.

Alpwacht is a cyber security consultancy with offices in Munich and Zurich. We work for organisations that operate across the border or answer to regulators on both sides of it. Our consultants combine governance, architecture, operational technology and offensive testing, so that a policy written in the boardroom and a firewall rule in a substation describe the same risk.

Munich at dawn with the Alps on the horizon

Who we work with

Financial services
Banks, insurers, asset managers and payment firms under DORA in the EU and FINMA Circular 2023/1 in Switzerland. We work on ICT risk frameworks, third-party registers, threat-led testing and incident reporting.
Industry and manufacturing
Machine builders, automotive suppliers, chemicals and process industries with production networks that were never designed to be connected. Many now fall under NIS2, and those that sell connected products also face the Cyber Resilience Act.
Energy and utilities
Grid operators, generators, municipal utilities and water suppliers that count as critical infrastructure (KRITIS) in Germany or Switzerland. Our work spans control systems, substations, remote access and the reporting duties that come with operator status.
Healthcare
Hospitals, laboratories and providers of health IT, where availability affects patient care. We support network segmentation of medical devices, incident readiness and the C5 requirements for cloud processing of health data in Germany.
Public sector
Federal, state and cantonal administrations and public enterprises with long-lived systems and procurement rules to respect. We help with security concepts, cloud decisions and the evidence that oversight bodies ask for.

How an engagement runs

We keep the method plain. Every engagement has a defined question, a named owner on the client side and an end point at which the client can carry on without us.

  1. 1

    Establish the facts

    We read the documentation, interview the people who run the systems and look at configurations and network traffic where we are allowed to. Findings rest on evidence, not on questionnaires alone.

  2. 2

    Rank the risks

    We set out what could go wrong, how likely it is and what it would cost the organisation, in terms that management and engineers both accept. Regulatory obligations are shown next to the technical risks, not in a separate report.

  3. 3

    Change what matters first

    We agree a sequence of measures with owners and dates, then work alongside the client's teams on design and implementation. Quick fixes and longer programmes are planned together so that one does not undo the other.

  4. 4

    Test and hand over

    We verify that controls work through retests, exercises or audits. The engagement ends with documentation, trained staff and a clear record of what remains open.

The kind of work we take on

Illustrative engagements, described without client names.

NIS2 readiness for a mid-sized machine builder

Situation
A family-owned machine builder in southern Germany has found that it is an important entity under the NIS2 implementation act. It has a capable IT team but no formal security management, and its production halls run on an older network shared with office systems.
Our work
We confirm the company's classification, guide its registration with the BSI and run a gap analysis against the act's risk management measures. We then design network segmentation between office and production, set up an incident reporting process, and brief the managing directors on their oversight duties.
What the client keeps
A documented security management system sized for the company, a segmentation plan that production has agreed to, a reporting process that meets the statutory deadlines, and a management team that understands what it is signing off.

Incident readiness for a Swiss utility

Situation
A cantonal energy and water utility is subject to the Swiss reporting obligation for cyberattacks on critical infrastructure. Its incident response plan predates the obligation and has never been exercised with management.
Our work
We revise the incident response plan to include reporting to BACS within 24 hours, define who decides on shutting down remote access to plants, and run a tabletop exercise built around a ransomware attack spreading from the office network towards control systems.
What the client keeps
A revised plan with clear decision rights, a tested reporting workflow, and a written list of improvements agreed by management and the operations team.

Threat-led testing for a cross-border bank

Situation
A private bank headquartered in Zurich with a subsidiary in Munich must show both FINMA and its EU supervisor that its critical functions withstand realistic attacks.
Our work
We build threat scenarios from intelligence on groups known to target private banking, run a controlled red team exercise against agreed critical functions, and close with a purple team phase in which our testers and the bank's defenders replay the attack together.
What the client keeps
Evidence of how far an attacker could get and how quickly the bank noticed, a remediation plan ranked by risk, and new detection rules already deployed in the bank's monitoring.
Zurich lake and old town in morning fog

Security as part of how an organisation is run

Regulation in Europe and Switzerland now treats cyber security as a duty of management, with deadlines and personal accountability. We think that is right. Security decisions belong next to investment, production and compliance decisions, made by people who understand both the business and the technology.

Our aim is to be the firm that engineers and executives both trust to tell them the plain state of things. That means calm assessments, clear priorities and work that still holds up when the auditor, the supervisor or an attacker tests it.

Where we work

Munich

Germany

Engagements in Germany and the EU. Governance, OT security, architecture and offensive security teams.

Munich sits at the centre of Bavaria's industrial base, close to automotive, engineering, aerospace and insurance firms. From here we reach plants and operators across southern Germany and Austria in a few hours.

Zurich

Switzerland

Engagements in Switzerland. Financial services, critical infrastructure, data protection under the FADP, and red teaming.

Zurich is Switzerland's financial centre and home to many banks, insurers and technology firms. Our team there works within Swiss law and close to the institutions it serves.

Work on security that regulators and plant operators depend on

We are hiring security consultants, OT engineers, penetration testers and incident responders for roles in Munich and Zurich, some hybrid. Applications are welcome in English, Hindi, Persian, Turkish and Arabic, and relocation support is available for many positions.

20 open roles. Applications close between December 2026 and early 2027.

See open roles

A fortnightly brief on cyber regulation and threats in Germany and Switzerland

Every two weeks we summarise new guidance from the BSI, BACS, ENISA, FINMA and the European Commission, along with significant advisories, with links to the original sources and a short note on what each item means for security teams.

Read the brief
Frost on granite

Talk to us about your security priorities

Tell us about your organisation, the regulations that apply to you and what you need to achieve, and we will come back to you to arrange a confidential first call. Email contact@alpwacht.com. If you are dealing with an active incident, say so in the subject line.

contact@alpwacht.com