
„Our expertise starts where large technology providers, system houses or international consulting groups often reach their limits.“

We create security for complex corporate structures
We assist corporations and companies with complex IT security challenges. In doing so, we combine technical expertise, specialized know-how, and many years of experience with a clear focus on practical implementation.
Our range of services extends from manual penetration tests and security assessments to technical consulting and support for complex security requirements. Among other things, we test web and mobile applications, IT infrastructures, APIs, Active Directory environments, SAP systems, and OT environments. In addition, we provide support for specific technical issues and security-critical projects. The areas mentioned represent only a portion of our range of services.
We also support companies with Critical Infrastructures, DORA, BSI IT-Grundschutz, and B3S, as well as with requirements from ISO/IEC 27001 and other security standards and regulatory guidelines—from technical assessment through to concrete implementation.
We do not follow a rigid formula. Instead, we align ourselves with our clients’ existing standards, methods, and processes, and, when necessary, contribute our own tried-and-true approaches, procedures, methods, and experience.
We take a committed and solution-oriented approach, taking into account our clients’ technical, organizational, and operational circumstances. This results in well-balanced solutions that are robust and work effectively in everyday use.

For decisions that must be supported in an emergency
We see ourselves as an extension of our clients and bring additional know-how, specialized expertise, and a fresh, outside perspective to their organizations. Our core expertise in penetration testing gives us a unique understanding of how vulnerabilities are exploited in practice and which security measures are actually effective.
We work side by side with our clients’ teams, integrate ourselves into existing structures, and take on responsibility. To this end, we rely exclusively on full-time specialists based in Germany. In addition to specialized technical expertise, our team holds certifications such as OSCP, OSEP, GPEN, Malware On Steroids, ISO/IEC 27001 Auditor and Implementer, BSI IT-Grundschutz Practitioner, and other recognized certifications.
We bring our experience to the table, ask the right questions, and help make things better.
Our experience speaks for us:
9+ years
Leading and certified experts in the field of penetration testing. KRITIS experience in the energy, healthcare, finance and insurance, transportation and public sectors. From 2026 to 2029, we will be the primary provider of IT security (Rank 1) for Germany’s second-largest statutory health insurance provider.
520+
Penetration tests in the areas of web, cloud, IoT, network infrastructure, social engineering, red teaming and SAP at leading corporations with 15,000 to 450,000 employees.
Specialized in your industry
Experts for highly regulated industries. Close cooperation at eye level – anonymized references prove our experience.
- Penetration testing of online and mobile banking systems
- Security assessments of backend infrastructures and networks
- Red Teaming to simulate targeted attacks on critical systems
- Security awareness programs for employees
-
Safety checks of production and control systems (ICS/SCADA)
-
Analysis of web-based management and reporting applications
-
Advice on securing cloud environments
-
Red Team Exercises for testing organizational security measures
-
Penetration testing of critical infrastructure and control systems
-
Security assessments of customer portals and smart meter systems
-
Network and endpoint security assessments
-
Red Teaming for the detection of complex attack patterns
-
Penetration tests of patient portals
-
Mobile security testing of medical applications
-
Protecting sensitive health data through infrastructure reviews
-
Social engineering tests and awareness training
Control Center Software for Emergency Services
Black-box testing of the web-based dispatch software, including connected mobile components
Objective: To analyze potential attack vectors targeting incident data processing, authentication, and communication between the control center and emergency vehicles
Internal penetration testing, as well as testing of web applications and network interfaces
Special features:
– Analysis of access options to operational systems (e.g., fire control, baggage handling)
– Testing for potential privilege escalation via central directory services (Active Directory)
– Vulnerability analysis of connected terminal systems (kiosk PCs, ground staff devices)
– Technical implementation during ongoing operations under strict operational requirements and with a prior approval matrix
-
Security testing of transportation and warehouse management systems
-
Analysis of IoT and cloud-based services
-
Employee training on cyber risks
-
Red teaming to check the ability to respond to attacks
-
Application security assessments for web and mobile apps
-
Testing of development and deployment processes
-
Training for developers on secure software development
-
Red Teaming for simulating attackers at application and infrastructure level
-
Tests of customer portals and claims management systems
-
Mobile App Security Assessments
-
Advice on securing IT infrastructures and data
-
Social engineering and red team exercises to strengthen the safety culture
A selection of our classics

Pentesting
Performing targeted penetration tests - manual and detailed, to uncover vulnerabilities in web applications, mobile apps, SAP systems, cloud infrastructures and more.

Managed pentesting
For larger projects, we offer customized managed pentesting services, including the creation of test plans, concept development and continuous vulnerability tracking via your ticket system.

Red Teaming
Holistic attack simulations that test not only technical vulnerabilities, but also the responsiveness of your employees and processes to assess the overall security resilience of your organization

Consulting
We provide consulting services based on established standards and regulatory requirements such as ISO/IEC 27001, BSI IT-Grundschutz, NIS2, DORA, and Critical Infrastructures, and translate these into solutions that are practical and economically viable.

IT security sparring partner
As your IT security partner, we provide strategic and operational support for all matters related to IT security. We serve as a reliable long-term partner and are available on short notice whenever you need our expertise.

All Services
We specialize in advanced IT security and can find the right solution even for complex or unique challenges.
Advantages at a glance
Effective cybersecurity is needs-based, understandable and practicable. However, this is a particular challenge in highly regulated environments with complex IT infrastructures. We know the regulatory requirements and operational realities of your industry and develop effective security solutions tailored to them. Our expertise is based on the essentials: the attacker’s perspective.
We adapt to your processes, methods, and standards rather than imposing our own structures on you. Where appropriate and desired, we supplement them with our proven approaches.
Personal contact instead of a hotline: You speak directly with the experts who are familiar with your project and your environment.
We work independently, reliably, and as equals. You define the task—we take on the technical responsibility for its implementation.
We don’t just go through the motions; we aim to deliver technically sound and independent results. We’re passionate about our work, take a close look at every detail, and sometimes even challenge existing approaches. Our goal is simple: in the end, we want to find the best solution for you.

Do you already know Managed Pentest?
Leave the entire vulnerability management to us: we create precise test plans for all relevant IT systems – from the network infrastructure to applications, cloud and IoT components through to tracking vulnerabilities in the ticket system. With regular scans and targeted penetration tests, we identify security gaps and support you in continuously improving your IT security situation. We offer you full reporting, dashboards and regular jour fixes so that you can maintain an overview at all times and respond quickly to new threats. Rely on a transparent and efficient security solution that covers all your requirements.

Absolute experts in the field. For over nine years.
Our consulting and auditing company offers you customized solutions and personal support – in a quality that large technology providers, system houses or the BigFour are often unable to provide.
Your contact persons
Security is a matter of trust. With us, you don't talk to a ticket system - you talk directly to experienced experts.

S. Philipp Kalweit
Managing Partner

Dipl.-Wirtsch.-Ing. Günther Paprocki has been Managing Partner of KALWEIT ITS since 2024 and is responsible for Operations and Human Resources as well as the organizational development of the company. He previously held various positions at Sharp, Philips and Cisco, where he gained experience in central technology developments, including the development of early mobile networks and the first internet infrastructures.
Günther Paprocki
Managing Partner
