We do not compete with your municipal IT service provider. The specialist applications, the citizen portal, the document management stay where they are. We work on the layers underneath and beside them – the ones that decide the outcome: perimeter security and network separation in your own buildings, controlled access with a second factor, a backup path that still holds when the service provider itself is hit – and a rehearsed emergency plan instead of a binder on a shelf. Those are exactly the layers the Südwestfalen attack came through: a guessed password, no second factor, a poorly maintained VPN appliance.
For federal bodies we bring two things that rarely come together: our engineers are VS-NfD-briefed and have project experience in classified environments of the defence sector – and we run our systems on our own infrastructure in Germany, with our own server park and our own IP address space, right down to self-hosted language models. Contracts on an EVB-IT basis are routine for us, not an exception; as a specialist partner we also work as a subcontractor within existing lots.
What matters for Municipalities & Authorities
- B-04Cyber Security & ProtectionThe Südwestfalen attack came in through a guessed password, a missing second factor, and a poorly maintained VPN appliance. That is exactly what we work on: a hardened perimeter, controlled access with a second factor, maintained remote administration, and a security operation that flags anomalies before they turn into encryption.
- B-03Network & ConnectivityThe administrative network, specialist systems, control technology, and guest access belong in separate zones with controlled transitions – across town hall, works yard, schools, and depots. We plan and operate segmented networks and secure site-to-site links so that an incident in one property does not reach the whole administration.
- B-06Business Continuity & ResilienceA second, independent backup path is the single most important measure for a municipality: Veeam-based, immutable backups to geo-redundant in-house targets, tested recovery, and a rehearsed emergency plan – explicitly in addition to what your service provider backs up, and not in the same environment.
- B-09Regulation & ComplianceWe first establish soberly which of your units are subject to NIS-2 and which are not – core administration, own operation, shareholding. Where an obligation exists we then work against the catalogue of measures; where none exists, against the IT-Grundschutz profile "Basis-Absicherung Kommunalverwaltung". On request also as an external information security officer.
- B-05Managed Services & SupportOperations with 24/7 monitoring, traceable changes, and reports that feed straight into your evidence and your provider management – complementing your internal IT and your municipal IT association rather than replacing them, at a predictable monthly flat rate.
NIS-2 in the municipality: core administration no, utilities yes
The German NIS-2 implementation act has been in force since 6 December 2025. For the municipal level, the IT Planning Council chose not to extend the scope nationwide; whether the obligations also reach districts and municipalities is for each state to decide – and in North Rhine-Westphalia there is no state law to that effect so far. Legally independent municipal enterprises are unaffected by this: they fall directly under the BSI Act once the thresholds are met. We first establish which of your units are affected and which are not, and then work against the catalogue of measures where an obligation exists – and against the IT-Grundschutz profile "Basis-Absicherung Kommunalverwaltung", written by the municipal umbrella associations for exactly this case, where none does. An obligation is not the benchmark for security; it is only the part of it that gets audited.