Inventory
An up-to-date overview of all devices, systems and software is the foundation for every further measure.
GDPR, NIS2, GoBD & more – I show you what actually applies to your business, which building blocks make the biggest difference, and where you stand in minutes with the free self-check.
The General Data Protection Regulation and the German BDSG require you to protect personal data through technical and organisational measures (TOMs), maintain a record of processing activities, and report data breaches to the supervisory authority within 72 hours. In my consulting work, I help you implement these obligations in a practical way – without overloading your daily operations.
Germany's NIS2 implementation act has been in force since 6 December 2025 – with no transition period. As a rule, you're covered as an "important entity" if you operate in a regulated sector and have at least 50 employees or more than €10M in annual turnover; from 250 employees or over €50M turnover and €43M balance sheet total, you count as an "essential entity". NIS2 requires active risk management and reporting obligations to the BSI. Fines run up to €10M or 2% of global annual turnover for essential entities, and up to €7M or 1.4% for important entities – and management is personally liable and cannot delegate this responsibility. I help you check whether and how you're affected.
The GoBD (Germany's bookkeeping and record-retention rules) require audit-proof, unalterable retention of business-relevant documents and emails throughout the statutory retention periods. I show you how to implement this cleanly and without adding extra day-to-day effort.
Whether GDPR, NIS2 or general duty of care – the undefined legal term "state of the art" comes up everywhere. It means: you must use the currently available, established protective measures – no more, but no less. I keep you up to date on what currently counts.
Independent of NIS2, managing directors are personally liable under § 43 of the German GmbH Act if they breach their duty of care – and this increasingly includes adequate IT security. Anyone who knowingly ignores risks risks personal liability if damage occurs.
The German TDDDG governs when you may only use cookies or tracking on your website with consent. I check with you whether your site is cleanly set up here – my own site deliberately does without cookies and tracking entirely.
These fundamentals decide your IT security in practice – regardless of which law applies.
An up-to-date overview of all devices, systems and software is the foundation for every further measure.
3 copies, 2 media, 1 offsite location – with regularly tested restores.
Roll out security updates centrally, promptly and with documentation.
Firewall and centrally managed antivirus protection on all devices.
Two-factor authentication and access rights limited to what's actually needed.
Spam/phishing protection and audit-proof archiving under the GoBD.
Regular training so employees recognise phishing and similar threats.
A documented plan that saves time when it matters.
Up-to-date documentation of infrastructure, responsibilities and processing records.
Most requirements overlap in practice: if you properly implement the nine building blocks from Section B, you'll already meet a large part of GDPR, NIS2 and GoBD at the same time. My advice: first establish basic IT protection (Section B), then specifically check whether and in which category you're affected by NIS2 or other obligations (Section A), and only then – if useful or required – consider moving toward a structured ISMS under ISO 27001. That way you avoid starting at the most complex stage while the basics are still missing.
11 short questions covering the nine building blocks from Section B – one click per question. At the end you get an instant traffic-light result with prioritised recommendations.
Note: This self-check is a non-binding initial estimate and does not replace an audit or legal advice. No names, email addresses or other personal data are collected, stored or transmitted – it runs entirely locally in your browser.