Analysis of IT and Information Security

Cyber Risk Assessment in accordance with DIN SPEC 27076

Would you like to know where your company currently stands in terms of IT and information security, and in which areas action is needed?

Through the CyberRiskCheck based on DIN SPEC 27076, the Enterprise Europe Network at Bayern Innovativ GmbH offers small and micro-enterprises a structured assessment of their existing IT security measures.

As part of a facilitated assessment, the current state of IT and information security is evaluated based on a standardized set of requirements. The subsequent evaluation reveals the determined risk status and highlights unmet requirements as well as potential areas for improvement.
This service is aimed at Bavarian small and micro-enterprises with up to 50 employees and is free of charge for them.

27 requirements across six subject areas

More Information on the CyberRiskCheck

The CyberRiskCheck examines 27 requirements across six areas of IT and information security:

  • Organization & Awareness
  • Identity & Access Management
  • Data Backup
  • Patch and Change Management
  • Protection Against Malware
  • IT Systems and Networks

The requirements are reviewed as part of a structured discussion. This is not a test with right or wrong answers, but rather an assessment of the current state of affairs.

Process

The CyberRisk assessment is divided into several steps:

1. Preliminary Discussion & Preparation

In an initial meeting, we get to know your company and your current situation. We explain the process and determine which individuals and information are needed for the assessment.

2. Assessment

Together, we review your existing IT security measures based on the requirements of DIN SPEC 27076.

3. Report & Analysis

The information gathered is evaluated, and your company’s risk status is determined. The report is generated using the CyberRisikoCheck software provided by the Federal Office for Information Security (BSI).

4. Results & Action Plan

In a separate meeting, we’ll present the results to you and explain the resulting recommendations for action. Together, we can also discuss possible next steps.

5. Optional Follow-up

Upon request, we can schedule another meeting in about three to four months to discuss the status of the measures that have been implemented.

Your Benefits

The CyberRiskCheck offers you:

  • a structured assessment of the current state of your IT and information security,
  • a risk assessment based on the requirements of DIN SPEC 27076,
  • an overview of unmet requirements and potential vulnerabilities,
  • concrete and clearly formulated recommendations for action as a basis for further decisions.

Conducted Using BSI Software

To conduct the CyberRiskCheck, we use the software provided by the Federal Office for Information Security (BSI). This software is also used to generate the results report. For more information on the CyberRiskCheck, please visit the BSI website.

Note on the CyberRiskCheck

The CyberRiskCheck represents only a basic approach to assessing an existing IT security level in a micro or small business. It therefore provides only an initial indication for determining a company’s IT security level and cannot replace a comprehensive audit.
Measures suggested following the CyberRisikoCheck are purely advisory in nature. Whether these measures are appropriate and sufficient in individual cases must be decided by the company being assessed, with the assistance of third parties if necessary.
The BSI assumes no liability for the accuracy of the results presented, the appropriateness and completeness of the recommended measures, or the correct use of the software by the consultant.

Interested in the CyberRiskCheck?

Would you like to take a structured look at the current state of your IT and information security?
Schedule an appointment for an initial consultation.
The Enterprise Europe Network team at Bayern Innovativ will be happy to inform you about the process and the requirements for participation.

Your Contact

Robin Hesch
+49 911 20671-236
Europa & Internationales, Enterprise Europe Network, Bayern Innovativ GmbH, Nürnberg
Dr. Markus Döbbelin
+49 911 20671-234
Head of Europe and International | Head of Enterprise Europe Network, Bayern Innovativ GmbH, Nuremberg
Dr. Karolina Bähr
+49 911 20671-176
Europe & International, Project Manager, Enterprise Europe Network, Bayern Innovativ GmbH, Nuremberg