Zum Hauptinhalt springen

Information Security from the Attacker's Perspective

We combine information security with many years of experience in offensive cybersecurity. As penetration testers, we consistently examine systems from an attacker’s perspective: How are attacks carried out, which vulnerabilities can actually be exploited, and which measures are effective in practice?

This perspective shapes our approach. We develop ISMS, security strategies, risk analyses, and organizational measures not theoretically, but based on real risks and the operational reality within the company. In doing so, we take into account existing processes, responsibilities, resources, and industry-specific conditions.

We work based on established standards and regulatory requirements such as ISO/IEC 27001, BSI IT-Grundschutz, DORA, NIS2, and Critical Infrastructures, and translate these into practical, implementable structures.

Making Compliance Sustainable and Cost-Effective

Achieving compliance is manageable. The real challenge lies in making it effective over the long term, sustainable, and cost-effective. After all, compliance always becomes an integral part of the organization—with established processes, controls, responsibilities, and ongoing effort. It is therefore crucial, right from the outset, to create a framework that is sustainable in the long term and can be integrated into the operational reality.

Our approach is geared toward creating appropriate, efficient, and sustainable structures. In doing so, we take into account not only the required level of maturity but also the company’s organizational, operational, and economic conditions.

We evaluate security measures not only in terms of their formal compliance, but also in terms of their actual effectiveness, feasibility, and their contribution to reducing relevant risks.

Our Values in Consulting:

Team Sports

We work with our clients as equals and see ourselves as part of the team. Together, we tackle challenges and deliver measurable results.

Cost-Effectiveness

We take into account effort, resources, and costs, and strike an appropriate balance between security levels, regulatory requirements, and economic viability.

Pragmatism

We focus on what matters most and develop safety structures that are not only documented but also understood, applied, and put into practice in our day-to-day operations.

Expertise

Our consultants hold relevant certifications and have project experience in ISO/IEC 27001, BSI IT-Grundschutz, B3S, DORA, and NIS2, and can assist with both specific issues and the full implementation of complex security and compliance projects.

Choose the plan that's right for you:

01
Workshop
We analyze a specific issue, provide clarity, and work together to develop solid next steps.
02
Ad hoc consulting
We bring our expertise to bear wherever you need additional know-how, an independent assessment, or support with implementation on short notice.
03
Long-term support
We provide your organization with ongoing support in the areas of strategy, governance, and implementation, and are available to serve as a professional sounding board.
04
Outsource IT Security
Upon request, we can handle key or all aspects of information and IT security, ranging from regulatory requirements and risk management to day-to-day security operations.

Your contact persons

Security is a matter of trust. With us, you don't talk to a ticket system - you talk directly to experienced experts.

*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(–scroll-root-safe-area-inset-bottom,0px)+var(–thread-response-height))] scroll-mt-(–header-height)” dir=”auto” data-turn-id=”3e5ba6a8-5344-4055-a8d0-724ba2cc8b90″ data-turn-id-container=”3e5ba6a8-5344-4055-a8d0-724ba2cc8b90″ data-testid=”conversation-turn-17″ data-scroll-anchor=”false” data-turn=”user”>

*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(–scroll-root-safe-area-inset-bottom,0px)+var(–thread-response-height))] scroll-mt-[calc(var(–header-height)+min(200px,max(70px,20svh)))]” dir=”auto” data-turn-id=”request-WEB:1bdbe56b-8d92-4638-803a-8b3029e53040-8″ data-turn-id-container=”request-WEB:1bdbe56b-8d92-4638-803a-8b3029e53040-8″ data-testid=”conversation-turn-18″ data-scroll-anchor=”false” data-turn=”assistant”>

Philipp Kalweit is the managing partner of KALWEIT ITS. At the age of 16, he turned his hobby into a profession with a special permit from the local court and founded today’s company a year later. For his entrepreneurial activities, he was honored in 2019 as “Hamburger of the Month” by DIE ZEIT, featured on the cover of Focus magazine and included in the Forbes “30 Under 30” list.  

S. Philipp Kalweit

Managing Partner

Dipl.-Wirtsch.-Ing. Günther Paprocki has been Managing Partner of KALWEIT ITS since 2024 and is responsible for Operations and Human Resources as well as the organizational development of the company. He previously held various positions at Sharp, Philips and Cisco, where he gained experience in central technology developments, including the development of early mobile networks and the first internet infrastructures.

Günther Paprocki

Managing Partner

Newsletter

Once a month. For CISOs, IT managers and decision-makers who want to know where real risks lurk - and how to counter them.
Receive newsletter