Security as provable control, not box-ticking — OSSTMM-measurable testing, a lean ISO 27001 ISMS, BSI Grundschutz baselines, and defense in depth, implemented pragmatically.
Good security is not a certificate on the wall — it is control you can prove. We ground our work in three standards that have stood the test of time — OSSTMM (measurable, repeatable testing), ISO 2700x (a risk-based management system), and BSI IT-Grundschutz (a pragmatic baseline-controls catalogue) — and we live defense in depth: layered controls so no single failure is fatal. The point is the substance, not the paperwork: default-deny, auditable, threat-modelled, verifiable.
We are OSSTMM/OPSA-certified (OSSTMM Professional Security Analyst); for ISO 27001 and BSI Grundschutz we are practitioners who have built ISMS repeatedly and taken organizations through (re-)certification — so we can make you audit-ready, whether or not you ever need the plaque.
The standards we use — and what each gives you, pragmatically
| Standard / approach | What it gives you — pragmatically | Where it shows up |
|---|
| OSSTMM (ISECOM) | Measurable, repeatable security testing — facts over opinion, an actual operational-security metric (the rav). Analysis that proves control, not checklists. We are OSSTMM/OPSA-certified (Professional Security Analyst). | Security assessments & audits · audit evidence in the
Security & Observability Platform |
| ISO 2700x | A lean, risk-based ISMS and controls catalogue — governance, risk treatment and named accountability without the bureaucracy. We have built ISMS and led (re-)certifications. | Rent-a-Security-Officer ·
Rent-a-Data-Protection-Officer |
| BSI IT-Grundschutz | A pragmatic baseline of building blocks (Bausteine) and the BSI 200-x method — ISO-27001-compatible, hardening you can apply layer by layer. | Host / network hardening ·
Sovereign Edge Firewall |
| Defense in depth (lived) | The principle that ties them together — layered, default-deny controls so no single failure is fatal, each layer independently auditable. | Sovereign Edge Firewall ·
Abusive HTTP Watch ·
Sovereign Certificate Authority ·
Security & Observability Platform |
The questions below are grouped for the CEO (what to do), the CIO (how), the standards and methodology, and working together.
For the CEO — what to do, and why it is a board topic
Is security really a board topic — or can I delegate it to IT?
Board topic. Under NIS2 (and GDPR) security oversight is an explicit management responsibility — directors can be held personally liable for insufficient governance. A breach hits revenue, reputation and continuity, not just the server room. You can delegate the work, not the accountability. →
Rent-a-Security-Officer ·
AboutWhat does good security actually buy me?
Provable control: fewer and smaller incidents, faster recovery, and evidence you can hand to auditors, insurers, regulators and customers. It turns security from a cost centre and a liability into something that wins tenders and shortens sales cycles. →
Security & Observability PlatformIsn't a certificate (ISO 27001) the goal?
The certificate is the receipt, not the security. We have built ISMS and led organizations through (re-)certification — and we deliver the substance whether or not you pursue the plaque. If a tender or customer requires ISO 27001, we make you certification-ready; if they don’t, you still get real, provable control. Substance first, paperwork only where it pays. →
ConsultingWhat is the risk of doing nothing — we have been fine so far?
Risk compounds silently: unpatched exposure, no detection, no incident plan — until the one event you can’t recover from cheaply and can’t prove you took reasonable care against. Under NIS2, ‘we hadn’t gotten to it’ is itself a finding. →
Rent-a-Security-OfficerWhere do I start — what is the first step?
A short, measurable assessment (OSSTMM-style) of where you actually stand, then a prioritized, reversible plan — not a year-long programme before anything improves. Often a fractional CISO or a scoped review delivers the first risk reduction in weeks. →
Consulting ·
ContactHow much should we spend on security?
Enough to cover your real risk, no more — which is why we measure first (OSSTMM) and treat risk by priority (ISO 27005 / BSI). Defense in depth lets you invest layer by layer instead of one big bet. We model it against your real exposure, not a vendor’s catalogue.
For the CIO — how to implement it
How do you assess security without it being a checklist?
OSSTMM: measurable, repeatable testing of actual operational security — what is exposed, what is controlled, what is a real limitation — producing a metric (the rav) you can track over time, not a pass/fail checklist. Facts over opinion. →
Security & Observability PlatformCan we get an ISMS without drowning in bureaucracy?
Yes — that is the whole point. A lean ISO 27001 ISMS scoped to your real risks: the controls and records you actually need, BSI-Grundschutz building blocks for the baseline, and no paperwork that doesn’t reduce risk. We have built several and run them. →
Rent-a-Security-OfficerWhat does defense in depth mean concretely in our stack?
Layered, default-deny controls — perimeter and segmentation, host and config hardening, application and code, identity and trust roots, encryption, and detection/response — each independently auditable, so one failure isn’t fatal. →
Sovereign Edge Firewall ·
Sovereign Certificate AuthorityHow do we learn of an incident before our customers do?
Centralised detection and audit trails: SIEM/XDR across endpoints, servers, network and cloud, with alerting and a tested incident-response path — plus the searchable evidence to reconstruct what happened. →
Security & Observability PlatformHow does this integrate with what we already run?
We meet your estate where it is — standards-based (syslog, standard identity, APIs), agents where they help, hardening applied to existing systems. Defense in depth is additive; you don’t need a green field. →
Custom Software DevelopmentWho runs security after the engagement?
Your team, ideally: we build it to be operable, document everything, and can design hiring profiles and onboard your in-house security/architecture team — or run it transitionally while you staff up. →
Consulting ·
Rent-an-Enterprise-ArchitectStandards & methodology
What is OSSTMM, in plain terms?
The Open Source Security Testing Methodology Manual (ISECOM): a rigorous, vendor-neutral way to test security so the result is measurable and repeatable. Instead of an auditor’s opinion you get facts about what is exposed and what is actually controlled — and a metric (the rav) you can track. Security you can prove, by construction.
What is ISO 2700x?
The international family for information-security management: ISO 27001 (the certifiable ISMS — governance, risk treatment, Annex A controls), 27002 (control guidance), 27005 (risk). It is the management system that makes security repeatable and accountable rather than heroic.
What is BSI IT-Grundschutz?
The German Federal Office for Information Security’s baseline-protection approach: a catalogue of practical building blocks (Bausteine) plus the BSI 200-x method (ISMS, methodology, risk). It is pragmatic and ISO-27001-compatible — a concrete ‘do these things’ baseline rather than abstract principles.
OSSTMM vs. ISO vs. BSI — why all three?
They do different jobs and reinforce each other: OSSTMM measures (testing and assurance), ISO 27001 governs (the management system), BSI Grundschutz baselines (the concrete controls). Defense in depth is the architecture that ties them together. We use each where it adds value, none as box-ticking. → see the map above
Are you certified — OSSTMM, ISO 27001, BSI Grundschutz?
We are
OSSTMM/OPSA-certified (OSSTMM Professional Security Analyst). For ISO 27001 and BSI Grundschutz we are practitioners — we have built ISMS and taken organizations through (re-)certification — but Pronix doesn’t hold the company certificate itself; we have never needed the plaque to deliver the substance, which is rather the point. Where
you need the certificate for a tender or customer, we make you certification-ready and support the audit. →
ConsultingCan you take us to ISO 27001 / BSI certification?
Yes — that is exactly what we have done repeatedly: scope the ISMS, close the gaps with Grundschutz baselines, produce the evidence, and prepare you for the audit and re-certification. You get a working security system first, and the certificate as the by-product. →
Rent-a-Security-OfficerDo these standards apply if we are small or not regulated?
Yes, proportionally. The methodology scales down: measure what matters (OSSTMM), a right-sized ISMS, a Grundschutz baseline, defense in depth at your scale. Regulation (NIS2, GDPR) raises the stakes, but provable control is insurance for everyone. →
Rent-a-Security-OfficerWorking with Pronix
How does an engagement start?
With a free 30–60-minute scoping conversation. A paragraph about your situation gets you a follow-up question, a call, or an honest ’not a fit — here is who is’. No forms, no nurture sequence. →
ContactWhat is a fractional CISO / Rent-a-Security-Officer?
A senior security role engaged fractionally (typically 1–4 days/month) instead of a full-time hire — the named, accountable function and the hands-on work, when you need it but can’t yet justify or fill a full-time post. →
Rent-a-Security-OfficerRemote or on-site — and where do you work?
Remote-first, worldwide; scoping and most delivery happen remotely, on-site where it genuinely helps. Working languages include German and English.
How do you price?
A fixed monthly retainer for the agreed cadence and coverage — not time-and-materials that drifts. You know the number; we manage the scope. Incident response is scoped separately.
What happens when the engagement ends?
You keep everything: a working security posture, documented controls and decisions, the ISMS and its evidence. Because we build open and document as we go, the end is a handover, not a hostage situation. →
About