Website security
& ongoing care.
Security hardening, updates, backups and monitoring for your website or shop. Honest in scope: I secure your web presence and keep it running — for corporate networks, endpoints and SOC operations I refer specialised partners.
Outdated websites are the no. 1 entry point.
Cyber Resilience and NIS2 Compliance
Since 2025, the EU NIS2 directive obliges thousands of companies across the DACH region to implement active risk management. Non-compliance means severe fines and personal liability for management.
What NIS2 Means for Your Business
📋 NIS2 Scope & Obligations
Does the NIS2 directive apply to your company? From as few as 50 employees or €10M revenue, strict obligations kick in: risk management, 24-hour incident reporting, and supply chain security.
⚠️ Avoiding Severe Penalties
Violations can result in fines of up to €10M or 2% of global annual revenue. Additionally, personal liability of managing directors is at stake — a risk no SME should ignore.
🛡️ My Contribution: the Web Layer
I harden the part attackers scan first: website, shop and hosting environment — with documented security measures, secure forms, backups and monitoring. For network, endpoint and SOC topics I work with specialised security partners.
🔍 Free Website Check
The free website check identifies weaknesses at the web level and delivers a prioritised action plan. For full NIS2 certification I refer vetted compliance specialists on request.
Four building blocks for a secure website.
What I concretely implement and continuously operate.
Hardening & security headers
CSP, HSTS and modern TLS configuration, hardened logins with 2FA, bot and spam protection for forms, least-privilege CMS roles.
Update & patch management
Keeping CMS core, plugins and dependencies current — tested in staging instead of blindly in production, with documented rollback.
Backups & recovery
Automated, versioned backups stored off the web server — including regular restore tests so the backup actually works when needed.
Monitoring & response
Uptime, malware and blacklist monitoring with clear response paths. Technical GDPR implementation (consent, embeds, forms) included.
From check to secure operations.
Systematically harden instead of patching ad-hoc.
Website check
Free automated check plus manual review: headers, TLS, update status, backup situation, GDPR basics.
Hardening
Quick wins first: critical updates, security headers, login hardening, form protection — with before/after evidence.
Safeguarding
Set up backup strategy and monitoring, prepare a staging environment for future updates.
Ongoing care
Monthly maintenance with a short report: what was updated, what monitoring flagged, what comes next.
Frequently asked.
Answers on scope, limits and cost.
What does ongoing maintenance cover?
Do you also cover firewalls, endpoints and SOC?
Does this help with GDPR and NIS2?
What does website security & maintenance cost?
Expert articles.
Background on cyber resilience, NIS2 and passkeys.
How secure is your website today?
The free website check shows you the biggest weaknesses in minutes — with concrete, prioritised actions.