

Information Security from the Attacker's Perspective
We combine information security with many years of experience in offensive cybersecurity. As penetration testers, we consistently examine systems from an attacker’s perspective: How are attacks carried out, which vulnerabilities can actually be exploited, and which measures are effective in practice?
This perspective shapes our approach. We develop ISMS, security strategies, risk analyses, and organizational measures not theoretically, but based on real risks and the operational reality within the company. In doing so, we take into account existing processes, responsibilities, resources, and industry-specific conditions.
We work based on established standards and regulatory requirements such as ISO/IEC 27001, BSI IT-Grundschutz, DORA, NIS2, and Critical Infrastructures, and translate these into practical, implementable structures.

Making Compliance Sustainable and Cost-Effective
Achieving compliance is manageable. The real challenge lies in making it effective over the long term, sustainable, and cost-effective. After all, compliance always becomes an integral part of the organization—with established processes, controls, responsibilities, and ongoing effort. It is therefore crucial, right from the outset, to create a framework that is sustainable in the long term and can be integrated into the operational reality.
Our approach is geared toward creating appropriate, efficient, and sustainable structures. In doing so, we take into account not only the required level of maturity but also the company’s organizational, operational, and economic conditions.
We evaluate security measures not only in terms of their formal compliance, but also in terms of their actual effectiveness, feasibility, and their contribution to reducing relevant risks.
Our Values in Consulting:
Team Sports
We work with our clients as equals and see ourselves as part of the team. Together, we tackle challenges and deliver measurable results.
Cost-Effectiveness
We take into account effort, resources, and costs, and strike an appropriate balance between security levels, regulatory requirements, and economic viability.
Pragmatism
We focus on what matters most and develop safety structures that are not only documented but also understood, applied, and put into practice in our day-to-day operations.
Expertise
Our consultants hold relevant certifications and have project experience in ISO/IEC 27001, BSI IT-Grundschutz, B3S, DORA, and NIS2, and can assist with both specific issues and the full implementation of complex security and compliance projects.
Choose the plan that's right for you:
Your contact persons
Security is a matter of trust. With us, you don't talk to a ticket system - you talk directly to experienced experts.

S. Philipp Kalweit
Managing Partner

Dipl.-Wirtsch.-Ing. Günther Paprocki has been Managing Partner of KALWEIT ITS since 2024 and is responsible for Operations and Human Resources as well as the organizational development of the company. He previously held various positions at Sharp, Philips and Cisco, where he gained experience in central technology developments, including the development of early mobile networks and the first internet infrastructures.
Günther Paprocki
Managing Partner