Services

We help banks, manufacturers, utilities, hospitals and public bodies meet NIS2, DORA and Swiss requirements, secure their plants and clouds, test their defences and prepare their teams for the day an incident happens.

Security strategy and governance

Information security management systems, regulatory readiness and board reporting for NIS2, DORA, FINMA and ISO/IEC 27001.

Many organisations now fall under more than one regime at once. A German manufacturer may be an important entity under the NIS2 implementation act and also certify to ISO/IEC 27001:2022. A Swiss bank with an EU subsidiary answers to FINMA Circular 2023/1 at home and to DORA in the EU. We map those obligations against each other, find where one control can serve several requirements, and build a management system that people actually run.

Governance work also covers the people who sign off on risk. NIS2 makes management bodies responsible for approving and overseeing cybersecurity measures. We prepare risk reports, decision papers and training that give boards and executive committees a clear basis for those decisions.

Typical deliverables

  • Applicability assessment for NIS2, DORA, FINMA Circular 2023/1 and the Swiss FADP
  • Gap analysis and remediation roadmap against ISO/IEC 27001:2022
  • Information security policy framework, roles and risk methodology
  • Management reporting format and board briefing on cyber risk

OT and ICS security

Security for production lines, substations, water works and building systems, based on the IEC 62443 series.

Industrial control systems were built to run for decades and to stay available above all else. Connecting them to enterprise networks, remote maintenance and cloud analytics has opened paths that their designers never planned for. We start with an asset inventory and a zone and conduit model, because nobody can protect a plant whose network they cannot describe.

From there we work with plant engineers and operations teams on segmentation, secure remote access, patch and change processes, and monitoring that understands industrial protocols. We use IEC 62443 as the common language between asset owners, integrators and product suppliers, and we schedule changes around production rather than against it.

Typical deliverables

  • OT asset inventory and network architecture documentation
  • Zone and conduit model with target security levels per IEC 62443-3-2
  • Secure remote access and segmentation design for plants and substations
  • OT security requirements for integrators and suppliers in tenders

Security architecture and cloud security

Architecture reviews, identity design and cloud security for public, private and sovereign cloud platforms.

Most security incidents trace back to architecture decisions: flat networks, standing administrator rights, identities that outlive the people who held them. We review existing estates and design target architectures for identity, network, data protection and logging, with a migration path that operations can follow.

In the cloud we work on landing zones, configuration baselines and key management across the major providers and sovereign cloud offerings. Where customers or regulators ask for evidence, we work with the BSI C5 criteria catalogue. In German healthcare, § 393 SGB V has required a C5 Type 2 attestation for cloud processing of health data since 1 July 2025, and we help both providers and users of such services prepare for it.

Typical deliverables

  • Security architecture review with prioritised findings
  • Target architecture for identity, privileged access and segmentation
  • Cloud landing zone security baseline and key management concept
  • BSI C5 readiness assessment and control mapping

Offensive security

Penetration testing, red teaming and threat-led testing that show how an attacker would reach what matters.

We test web applications, internal networks, cloud tenants, mobile apps and industrial environments. Each test is scoped around a question the client needs answered, such as whether a supplier connection can reach the production network, rather than a fixed number of days. Reports describe the attack path, the evidence and the fix, written for both engineers and management.

For financial entities we support threat-led penetration testing under DORA and red team exercises aligned with TIBER-EU and its national implementations such as TIBER-DE. In Switzerland we run comparable scenario-based red team exercises for banks and insurers, using the same principles of threat intelligence, controlled execution and joint learning with the defending team.

Typical deliverables

  • Penetration test report with attack paths, evidence and remediation guidance
  • Red team scenarios based on threat intelligence for the client's sector
  • Purple team workshops to turn findings into detection rules
  • Retest and closure confirmation for remediated findings

Detection and incident response readiness

SOC design, incident response retainers and exercises, so that the first hours of an incident follow a plan.

Regulators now set clocks for incident reporting. Under NIS2 an early warning is due within 24 hours of becoming aware of a significant incident. Swiss critical infrastructure operators have 24 hours to report a cyberattack to BACS, with fines possible since 1 October 2025. Meeting those deadlines depends on detection, escalation and decision rights that are settled before anything goes wrong.

We design security operations, whether in-house, outsourced or mixed, and define use cases, playbooks and service levels. Our incident response retainers give clients agreed access to responders. Tabletop exercises put executives, IT, legal and communications in the same room with a realistic scenario, and the follow-up lists what to change.

Typical deliverables

  • SOC target operating model and detection use case catalogue
  • Incident response plan with reporting workflows for BSI, BACS and FINMA
  • Incident response retainer with agreed response times and contacts
  • Tabletop exercise for executive and technical teams, with written lessons learned

Third-party and supply-chain security

Security requirements for suppliers, ICT third-party risk under DORA, and product security under the Cyber Resilience Act.

Supply-chain security runs in two directions. As a buyer, an organisation must know which suppliers can reach its systems and data, and NIS2 and DORA both require that this risk is managed. We build supplier classification, contract clauses, assessment processes and the register of information that DORA requires for ICT third-party arrangements.

As a manufacturer, an organisation may itself be the supplier. The EU Cyber Resilience Act sets security requirements for products with digital elements. Its reporting obligations for actively exploited vulnerabilities have applied since 11 September 2026, and its main requirements apply from 11 December 2027. We help product teams set up vulnerability handling, software bills of materials and the technical documentation needed for conformity.

Typical deliverables

  • Supplier risk classification and assessment process
  • Security clauses for ICT contracts and the DORA register of information
  • Cyber Resilience Act applicability and gap assessment for product lines
  • Vulnerability handling and SBOM process for product security teams

Talk to us about your security priorities

Tell us about your organisation, the regulations that apply to you and what you need to achieve, and we will come back to you to arrange a confidential first call. Email contact@alpwacht.com. If you are dealing with an active incident, say so in the subject line.

contact@alpwacht.com