IT and information security for companies with 10 to 500 employees

The customer, the investor or the auditor asks: is the proof ready that your IT and security are in order?

Your systems grew or were outsourced. The knowledge is scattered, and nobody can measure the state. That is arithmetic, not a failure. We measure the state, fix what carries the biggest risk first, and deliver the evidence before anyone asks.

The assessment Fixed price, by system landscape 7,500 to 12,000 euros

If a customer requires ISO 27001

In most cases you do not need the certificate right away. The risk team has to be able to document a risk.

Exception: with a knock-out criterion in a tender, with a public-sector buyer, or as a DORA-critical supplier, the scope often requires the passed certificate. The roadmap.

If a questionnaire is on your desk

If a customer or your cyber insurer has sent you a security questionnaire, we fill it in as part of the assessment. No separate product, no extra invoice.

Triggers

No matter who asks next

Seven triggers, one root. Every one of our mandates has started in the same place.

The first step

We start with an assessment.

A control point is a fixed, surveyed reference. From it you map unknown terrain. That is exactly what the assessment is: the fixed reference point in an IT estate that has grown.

  • A gap and maturity analysis. We rate every control from Annex A of ISO 27001:2022 on a capability scale from zero to five per ISO/IEC 33020. The result we map to the Functions and Categories of NIST CSF 2.0. If a customer requires SOC 2, we add its Trust Services Criteria. Technically we measure against named references: the CIS Benchmarks, the AWS or Azure Well-Architected Framework and Zero Trust architecture per NIST SP 800-207. The basis is interviews with the people responsible for your systems.
  • The inventory: tools, systems, contracts and where they overlap.
  • What actually has an effect and what is only paper.
  • An open security questionnaire from a customer or insurer, filled in with you.
  • A findings report you can put in front of your board. You own it.

7,500 to
12,000 euros

Duration
About two weeks
Price
Fixed, by system landscape
After that
You decide

No framework agreement, no automatic renewal. What comes next is your decision.

The price follows your system landscape, not your headcount: a grown on-prem estate with two to three interviews costs 7,500 euros, several large cloud environments cost around 12,000 euros. Buy the ISO roadmap and the assessment is included. You do not pay for it twice.

Consultantswrite controls down
controlpunktdoes both
Providersinstall the IT

The market is split, we are not. Good security is good IT. What to do gets decided only once someone knows what is actually there.

We lead the conversations with the risk team, from day one and for as long as it takes. The roadmap.

Honesty

What we do not do is just as visible as what we do.

If you have an incident in progress right now

We are not the right people. Call your cyber insurer. They have an incident response provider on file. Come back once the forensic report is in your hands. Bring it, the assessment builds on it. You can also reach out while the forensics are still running; we then plan what follows. After that the rebuild starts: put access in order, get detection running, make the state provable. That is exactly what we did after a phishing incident, the case is here.

No incident response, no forensics, not even brokered.

If there is an IT lead, we work for them, not in their place.

We do not talk to your board without you.

The plan carries your name. You present it, we sit in the back.

You can stop after the first phase.

The findings go to you first. You read the draft before anyone else sees it.

What comes next follows from what we find.

The assessmenttwo weeks 7,500 to 12,000 euros

Five engagements are documented as cases below, actually run and not invented. Every one began with an assessment. Which route it becomes is settled at the end of the assessment, not before it. The whole way to the ISO certificate: roadmap 15,000 to 25,000 euros plus ISMS 40,000 to 80,000 euros, which makes 55,000 to 105,000 euros. The assessment is included in the roadmap. You choose the certification body yourself and pay it directly. The cases.

Cases

Every engagement began the same way. None ended the same way.

The assessment

A trading company

ISO roadmap

No ISMS, and a major customer with a deadline.

After three weeks a strategy with a solid timeline was on the table, and the customer accepted it. The pressure was off.

Out of it: the ISMS in eight months, a GRC platform set up, then vCISO on a mandate.

A fund-owned company

Portfolio

The IT had grown, no governance, no documentation.

Out of it: the IT estate documented, consolidated, migrated from on-premise to the cloud, two acquisitions technically integrated, governance put in place (IAM, HR system).

A fintech

Detection: MDR and EDR

Regulated, but no view of attacks inside its own house, an ISMS only on paper.

Out of it: managed detection, EDR across the estate, ISMS consulting, and a penetration test at the end.

An insurer

Closing ISMS gaps

The ISMS was in place, but their own IT could not run the standards.

Out of it: a cryptography standard and a logging concept their own team understands and can run.

A software company

Detection: MDR and EDR

After an incident: accounts taken over through phishing, no detection in the house.

Out of it: access put in order, MDR and EDR rolled out, an ISMS set up. Today the operation sees an attack.

Before anyone from our side gets access to your systems

  • Professional indemnity insurance of 1 million euros, plus office, business and product liability of 5 million euros for personal injury and property damage. Both with a threefold annual aggregate and no deductible. We show the policy in the first call.
  • Confidentiality and data processing agreements are always signed before the first access.
  • Our specialists are contractually bound and vetted before they work on an engagement. Whoever is in your systems is named in your contract.

You get a phone call.

Thirty minutes with one of our clients, in confidence.

We do not name our customers publicly. Names and references are on the table in the first conversation.

Trust in detail

Tools and people

We work with a stack we know in depth: Microsoft Security, Cloudflare, Zscaler, Tailscale, Azure, Google Cloud and Workspace. If a different tool fits your landscape better, we recommend it, even when we do not supply it. We name our partnerships openly, so you can judge what we recommend.

For the SOC we select and set up. The operation goes to a provider who can do that around the clock. We do not claim to do it on the side.

We are a fixed circle of certified specialists for network, cloud, Microsoft Security, identity and GRC, plus partners for offensive security. The founder is Lead Implementer for ISO 27001 (PECB), with certifications across the circle for AWS, Azure and Google Cloud.

We introduce the people involved by name in the first conversation.

The founder

Tomislav Ljubas, founder of controlpunkt

Tomislav Ljubas

Founder and managing director, controlpunkt GmbH

LinkedIn profile

I built the systems before I governed them. That is what sets me apart from a consultant who only writes controls down.

Tomislav Ljubas

Twelve years in corporate IT at a listed group: started as a data engineer, then IT compliance, then IT architecture, up to leading corporate IT and security. Five of those years, 2018 to 2023, as CISO, alongside the line role.

Intro call

hello@controlpunkt.com Connect on LinkedIn

We reply within one business day.

What to put in the first email

  • Who you are and your company.
  • What it is about: the trigger, the real problem. A sentence or two is enough.
  • If a customer, an investor or a regulator has set a deadline: add the date.
  • After an incident: where the forensics stand.