
Our Classics

Pentesting
Controlled simulation of real-world cyberattacks—for companies that want to know whether and how vulnerabilities can actually be exploited. We carry out targeted attacks on specific applications, systems, or infrastructure to demonstrate concrete attack vectors and their effects.

Managed pentesting
Continuous penetration testing for complex IT environments. Instead of one-off snapshots, we provide ongoing, reliable transparency into real attack risks and ensure the long-term security of critical systems.

Red Teaming
Targeted simulation of real-world attacks on your company—across technology, processes, and employees. The focus is not only on the attack itself, but also on how well your internal Blue Team detects, assesses, and defends against it.

Consulting
We provide consulting services based on established standards and regulatory requirements such as ISO/IEC 27001, BSI IT-Grundschutz, NIS2, DORA, and Critical Infrastructures, and translate these into solutions that are practical and economically viable.

IT security sparring partner
As your IT security partner, we provide strategic and operational support for all matters related to IT security. We serve as a reliable long-term partner and are available on short notice whenever you need our expertise.

Presentations & Workshops
From security awareness to professional development: We provide practical knowledge, raise awareness, and make complex security topics easy to understand.
All services at a glance
Safety Inspections
The ultimate test of IT security: We identify real vulnerabilities in your systems before real attackers can exploit them. We do this by acting like potential attackers.
We conduct controlled, manual attacks on, for example, web applications, web services, APIs, mobile applications, desktop and client systems, networks, perimeter infrastructures, Windows enterprise networks, embedded and IoT systems, as well as automotive systems and vehicle components. In doing so, we test the actual exploitability of vulnerabilities and assess potential attack vectors and their impacts. The results clearly identify the existing risks and the technical measures that can be taken to mitigate them.
Continuous vulnerability analyses and penetration tests in a subscription model – for sustainable security instead of one-off tests.
We simulate realistic, targeted cyberattacks, replicating the entire attack chain—from initial access through privilege escalation and lateral movement to access to critical systems or data. Depending on the scenario, we also employ social engineering, phishing, or physical access attempts. The focus is on testing existing protection, detection, and response capabilities under real-world attack conditions. This method is particularly well-suited for organizations with a high level of security maturity that wish to test their existing controls and SOC capabilities against realistic attack scenarios.
We combine controlled attack simulations with direct collaboration between Offensive Security and the SOC. Attack techniques are simulated, detected, and analyzed jointly. This allows for immediate improvements in detection and response, which can then be validated again.
We identify and assess technical vulnerabilities in systems, applications, and infrastructure in accordance with best practices and established standards such as BSI IT-Grundschutz, CVSS, NIST, and OWASP. In doing so, we document and prioritize risks based on severity, exploitability, and criticality. Unlike penetration testing, the focus is on systematically identifying all vulnerabilities and deriving concrete remediation measures, rather than on the targeted exploitation of individual vulnerabilities.
We assess the technical effectiveness of existing security controls—such as firewalls, EDR/XDR, MFA, and network segmentation—based on specific attack scenarios. This evaluation focuses not only on the current configuration but also on the actual level of protection provided. This allows us to identify targeted improvements to the configuration, architecture, and interaction of the controls.
We analyze embedded systems, firmware, and hardware for technical vulnerabilities in vehicles, machinery, industrial equipment, and electronic products. Depending on the test objective, we examine boot processes, update mechanisms, debug interfaces, communication channels, control units, and chip-level components. Our services range from prototypes and mass-produced products to the analysis of individual chips and components. In addition, we are qualified to work on high-voltage systems.
We simulate targeted phishing attacks to test and strengthen your employees’ security awareness.
We analyze publicly accessible sources and darknet platforms for exposed company data and risks.
With this range of services, we meet the essential requirements through our own full-time experts. For specialized issues, we rely on selected partners with in-depth expertise in the relevant field and a proven track record of collaboration.
Simulation of realistic attacker profiles and their tactics, techniques, and procedures (TTPs) to validate the effectiveness of protective measures, attack detection, and incident response under realistic conditions.
A compact IT security check especially for small and medium-sized companies – pragmatic, understandable, effective.
Consulting
As part of our consulting services, we eliminate technical weaknesses, develop IT security strategies and concepts and support your IT department in specific areas where support is needed.
We analyze the current level of information security maturity and evaluate governance, processes, roles and responsibilities, technical controls, and existing security measures. In doing so, we follow established standards and frameworks such as ISO/IEC 27001, BSI IT-Grundschutz, and NIST CSF. Based on the gap and maturity analysis, we derive risk-based measures, target states, and prioritized implementation steps for the strategic and operational advancement of information security.
We pursue an efficiency and benefit-oriented consulting approach:
- Pragmatic implementation: Solutions are designed to be as lean as possible, but as robust as necessary.
- Resource orientation: Expenditure and measures are based on the actual risk and business value, not on theoretical full coverage.
- Focus on requirements: Complexity is only built up where it really adds value.
- Ability to act instead of paperwork: The aim is a functioning implementation in everyday life, not oversized concepts.
We provide support in establishing, developing, and evaluating an information security management system in accordance with ISO/IEC 27001. This includes, among other things, risk analysis, security measures, documentation, internal audits, and preparation for certification.
We provide support in implementing the requirements of the Digital Operational Resilience Act. Our focus includes, among other things, ICT risk management, governance, resilience, incident management, security controls, and third-party management. We translate these requirements into specific organizational and technical measures.
We assess the NIS2 requirements relevant to the company and its existing security measures. In doing so, we identify regulatory gaps and determine specific areas of action to address them.
With this range of services, we meet the essential requirements through our own full-time experts. For specialized issues, we rely on selected partners with in-depth expertise in the relevant field and a proven track record of collaboration.
We provide support in implementing the BSI IT-Grundschutz methodology, from structural analysis and assessment of protection requirements through modeling and the IT-Grundschutz check to risk analysis and security design. In doing so, we assess and evaluate the degree to which the relevant module requirements have been implemented, identify deviations and residual risks, and derive concrete security measures and necessary actions from these findings. This creates a robust foundation for the transparent implementation, documentation, and continuous improvement of the security level.
With this range of services, we meet the essential requirements through our own full-time experts. For specialized issues, we rely on selected partners with in-depth expertise in the relevant field and a proven track record of collaboration.
We assist operators of critical infrastructure in assessing and implementing the relevant security requirements, as well as in preparing for audits. Identified gaps are evaluated and translated into concrete actions.
With this range of services, we meet the essential requirements through our own full-time experts. For specialized issues, we rely on selected partners with in-depth expertise in the relevant field and a proven track record of collaboration.
We analyze threats, vulnerabilities, existing security measures, and potential impacts on business processes. Risks are assessed and prioritized in a transparent manner so that security measures can be targeted where they will have the greatest impact.
We develop security strategies and technical and organizational security concepts based on existing IT infrastructure, business processes, and specific risks. This results in concrete objectives and actionable measures for the further development of information security.
Cyber resilience
Strengthening your company's resilience to cyberattacks - through prevention, detection and response.
We provide support for the technical analysis, containment, and investigation of security incidents. In doing so, we examine attack vectors, affected systems, and relevant evidence, and assist with containment, remediation, and recovery. For specialized forensic analyses, we draw on experienced partners and specialized experts. We often take on overall management as project managers, coordinate the parties involved, and conduct minor forensic analyses as part of our own scope of services. The goal is to quickly and systematically contain the incident and ensure a secure and controlled resumption of operations.
We simulate a realistic cyberattack as a tabletop exercise without actually interfering with systems. A specific attack scenario is played out step by step—for example, from the initial anomaly through assessment and escalation to containment and resumption of operations. In doing so, we verify whether roles and responsibilities are clearly defined, decisions are made in a timely manner, escalation and communication channels function properly, and the departments involved collaborate effectively. This allows us to identify weaknesses in existing incident response and crisis management processes at an early stage and address them specifically.
As an IT security sparring partner, we support companies in areas where internal security resources, specialized expertise, or operational capacity are lacking or where there is a need for targeted external support. We handle specific security tasks, support existing teams, or, if necessary, assume overall responsibility for defined security areas.
Our services range from expert consulting and decision support to security assessments, technical evaluations, and security concepts, all the way through to the management and implementation of specific measures. We can also provide support in the event of short-term resource shortages, complex security issues, or as a temporary external security function.
Collaboration is possible regardless of the framework used. At the same time, we support the implementation and further development of requirements from ISO/IEC 27001, BSI IT-Grundschutz, DORA, and other regulatory or industry-specific guidelines.
Depending on your needs, we can handle specific tasks, defined areas of responsibility, or the complete operational management of information security. This provides companies with flexible access to security expertise without having to maintain their own in-house specialists for every required skill set on a permanent basis.
As an external Information Security Officer (ISO), we provide expert oversight of information security and serve as a central point of contact between management, IT, business units, and external service providers. We assess security risks, coordinate and prioritize measures, manage security incidents and projects, and provide transparency regarding the current security status.
We can handle the ISB function either entirely or as a supplement to existing internal structures. This includes, among other things, further developing the ISMS, preparing management decisions, supporting audits, and monitoring pending security measures. If needed, we can also take on the overall coordination of information security.
The service can be provided independently of any specific framework or tailored to meet the requirements of ISO/IEC 27001, BSI IT-Grundschutz, DORA, and other regulatory standards. This provides companies with a permanent, professional security function without having to build up the necessary resources and expertise entirely in-house.
We send targeted, unannounced phishing emails to your employees and analyze the results—who clicks, who reports it, and how people react. The real-life examples gathered during this process are then incorporated directly into an awareness training program, making the threat tangible rather than abstract.
In addition, we simulate attempts to gain physical access to your company through social engineering—for example, through tailgating, impersonation, or targeted approaches at the reception desk. This reveals whether security awareness is effective not only in the digital realm but also in face-to-face interactions.
To ensure a lasting impact beyond the one-time test, you can optionally add online security awareness training. This ensures that your workforce remains continuously trained and aware over the long term—rather than seeing awareness levels drop off after the one-time simulation.
It can also be used as a program item at corporate events: The analysis can be presented as a concise keynote speech at company parties, corporate anniversaries, or customer events. Especially at events with customer participation, presenting real, company-specific results creates an immediate “aha” moment and tangibly conveys just how seriously the company takes IT security. Any vulnerabilities uncovered do not damage the company’s image—especially since the issues have long since been resolved by the time the results are presented. Customers are aware that absolute security does not exist; instead, an open and transparent approach to findings is perceived as a sign of professionalism and maturity.
Seminars & Lectures
Practical and interactive formats on current IT security topics - individually tailored to your company.
Inspiring keynotes on cybersecurity, digital education and the mindset of modern attackers – understandable and impressive.
Training courses for employees that really make an impact: understandable, practical and with a lasting effect.
Interactive sessions in which we work with your team on specific security issues—practical, discussion-based, and tailored to your actual situation. Instead of generic content, we develop solutions that are tailored to your IT environment, your processes, and your specific level of security maturity.
Interactive hacking challenge especially for developers – with practical vulnerabilities that promote security awareness and sensitize the development team.
Your contact persons
Security is a matter of trust. With us, you don't talk to a ticket system - you talk directly to experienced experts.

S. Philipp Kalweit
Managing Partner

Dipl.-Wirtsch.-Ing. Günther Paprocki has been Managing Partner of KALWEIT ITS since 2024 and is responsible for Operations and Human Resources as well as the organizational development of the company. He previously held various positions at Sharp, Philips and Cisco, where he gained experience in central technology developments, including the development of early mobile networks and the first internet infrastructures.
Günther Paprocki
Managing Partner