IT Security: Find the Gaps Before Someone Else Exploits Them
IT security and data protection for companies that want to know where their systems are exposed.
Most security gaps are mundane: a server without updates, an account with too many permissions, an interface without authentication. Add to that GDPR requirements nobody feels responsible for. We review your systems, name the gaps plainly and close them in order of risk.
Most gaps only show up after the incident
Many companies discover gaps in their IT security only after a data loss, a ransomware infection or a GDPR audit. By then the damage is done, and the search for the cause starts under time pressure. We reverse the order. First, we review your systems, access rights and processes. Then you get a list of vulnerabilities, ranked by risk, with the next steps for each one. We only choose IT security solutions once it is clear which problem they solve.
- Reviewsystems, access rights, processes
- List of vulnerabilitiesranked by risk
- Next stepsfor each one
- IT security solutiononly once the problem is clear
Security services
Security audits
We review servers, applications and access rights and scan your IT infrastructure for known vulnerabilities. The result is a report with priorities.
Penetration testing
We attack your application the way an attacker would, and we document every path that gets in.
Incident response
On-call coverage and response times written into the contract. In an emergency, you know whom to call and what happens first.
Compliance and standards
Data protection
- GDPR compliance
- Privacy by design
- Data protection impact assessment (DPIA)
- Documentation and training
Certifications for your company
Your company earns the certification, not Onveda. We help you implement the technical requirements in your applications and document them for the audit.
- ISO 27001 requirements
- BSI IT-Grundschutz (the German federal IT security baseline)
- PCI DSS for payment data
- Criteria for a C5 attestation (the German cloud security standard)
Security technologies
Network security
- Next-gen firewalls
- IDS/IPS systems
- VPN solutions
Identity and access
- Multi-factor authentication
- SSO solutions
- PAM systems
Monitoring and SIEM
- Log management
- Security analytics
- Threat intelligence
The first call is about your biggest risks
The intro call takes 30 minutes and is free. You describe your systems, and we tell you where we would look first and whether we are the right team for it. We work in English and German.

Jens Bohl Founder and Managing Director