Trust

Before any of us gets access to your systems

  • Professional indemnity insurance of 1 million euros, plus office, business and product liability of 5 million euros for personal injury and property damage. Both with a threefold annual aggregate and no deductible. We show the policy in the first call.
  • Confidentiality and data processing agreements are signed before anyone gets access.
  • Your exports leave us again. Whatever we export for the assessment, we delete in full once the work is done. Where you need it, we work inside your environment, over VDI or Citrix. Then no file leaves your house.
  • Our specialists are contractually bound and vetted before they work on a mandate. Whoever is in your systems is named in your contract.

You do not get a logo wall.

You get a phone call: thirty minutes with one of our clients, in confidence.

We do not name our customers publicly. Names and references are on the table in the first conversation.

Honesty

What we do not do is just as visible as what we do.

No incident response, no forensics, not even brokered.

In an active incident

If you have an active incident right now, we are not the right people. Call your cyber insurer. They have an incident response provider on file. Come back once the forensic report is in your hands. You can also reach out while the forensics are still running; we then plan what follows. After that the rebuild starts, and a case for it is here.

Second opinion

Trust also means being able to check independently. The sharpest proof of that is the second opinion. We earn nothing on the operation we review.

The founder

The track record

Tomislav Ljubas, founder of controlpunkt

Tomislav Ljubas

Founder and managing director, controlpunkt GmbH

LinkedIn profile

Twelve years in corporate IT at a listed group: started as a data engineer, then IT compliance, then IT architecture, up to leading corporate IT and security. Five of those years, 2018 to 2023, as CISO, alongside the line role.

I built the systems before I governed them. That is the difference from a consultant who only writes controls down.

The team

A fixed circle of specialists

Network, cloud, Microsoft Security, identity and GRC are covered by certified specialists, plus partners for offensive security.

We introduce the team by name in the first conversation, with each person's certifications.

What a mandate costs is on the relevant offer page, for example the assessment or the ISO 27001 roadmap.

Request a first call