Start
Schlaglicht. The entry point into working together
Working together does not start with a product catalogue. It starts with an outside-in view of your organisation, and with the question of what actually follows from it.
Seeing from outside what others can already see.

- 1attributable Services and systems can be attributed to the company.
- 2early There is still time for review and decision.
- 3visible An access point is recognisable from outside, observed without intervention.
How the collaboration begins
An early observation is not yet certainty. It can, however, preserve options for leadership before time pressure dictates the decision. In the free initial conversation, we clarify the situation, question and responsibilities, without conducting an assessment. Only once objective and scope are agreed does the Schlaglicht begin as a commissioned entry assessment.
What the Schlaglicht is
The Schlaglicht views your organisation from the outside and consolidates available technical, commercial and public information from independent sources into a first overall picture. It requires little from you; internal system access is generally not needed for it.
Result
What you receive as a result.
- 01
Relevant findings and connections
Not a hit list, but connected observations with origin and relevance to your organisation.
- 02
Reliability
What is observed, what is supported, what is derived and what remains unknown.
- 03
Meaning and consequences
What the findings mean for your organisation and where action is immediately required.
- 04
Prioritised next steps
What to verify, decide and implement first.
Scope
What is agreed before an assessment.
Question
Which decision needs to become reliable.
Scope
Which entities, domains and perspectives are examined.
Depth of testing
What is collected externally, and what requires explicit authorisation.
Release & confidentiality
Who receives findings and how they are handled.
Pentest Light
Technical testing and Pentest Light.
Pentest Light: targeted technical security testing from the outside. We examine external attack surfaces, relevant vulnerabilities and possible attack paths within the agreed scope. Where required and explicitly authorised, targeted active validation complements the external analysis. You receive interpreted findings and prioritised next steps.
Scope and depth of testing are agreed in advance. Further exploitability and in-depth testing is agreed separately. Whether Pentest Light forms part of an engagement depends on the agreed scope, it is not automatically part of the Schlaglicht. Active testing against production environments only takes place with separate authorisation; external OT collection remains passive.
Perspectives
Which perspectives can be examined in depth.
- Technology
- External technical reality, reachable services, vulnerabilities and their connections.
- Governance
- The actual leadership and decision architecture and the evidence behind it.
- Behaviour
- Team patterns and organisational strain, surveyed within the agreed scope, for instance through interviews.
- Supply chain
- Relevant customers and suppliers seen from the perspective of the organisation in question.
Collaboration
How implementation or ongoing support follows.
The overall picture determines how the work continues. It does not end with a report.
One-off analysis
A concluded assessment of a clearly defined question.
Project
A defined outcome with agreed objective and scope.
Ongoing support
Recurring observation, reassessment and operational support for implementation.
Call-off
Deeper work whenever a concrete need arises.
Implementation includes operational support, steering measure projects, involving external specialists and, where wanted, additional legal validation through partners. Scope and terms are agreed individually.
Next step
Arrange an initial conversation.
Free of charge, with no assessment. Getting in touch triggers neither an engagement nor any technical testing.
Book a meeting on your topic

