eine Person, die einen Laptop benutzt

IT compliance & cyber resilience

Navigate a complex regulatory and technological landscape – using quantifiable, efficient and future-proof approaches.

The IT security situation in Germany is tense – the pressure on financial services providers to ensure their compliance with current regulations is increasing. At the same time, opportunities are arising for them to strengthen their cyber resilience.

According to the 2024 IT security report by the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI), the threat situation in cyberspace is tense. The damage caused by cyberattacks in Germany is estimated at over EUR 200 billion a year, with a rising trend. In 2024 alone, the Federal Criminal Police Office recorded over 131,000 cases of cybercrime. To make matters worse, according to the German Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin), most of the weak spots are “predominantly self-inflicted”.

In response, legislators are tightening the requirements for ICT risk management and defining a minimum level of resilience measures. Regulatory requirements  such as DORA, the AI Act and the German Financial Market Digitalization Act (Finanzmarktdigitalisierungsgesetz, FinmadiG) – are constantly increasing, both in terms of the depth and breadth of the associated implementation obligations.

For financial services providers, this means that ICT risks must be managed just as consistently as any other type of risk. Strong IT compliance is just as essential as innovative, cost-efficient and holistic strategies to enhance cyber resilience.

With future-proof concepts, companies can not only meet regulatory requirements but also strengthen their IT security in a sustainable way. What initially feels like regulatory pressure can thus become an opportunity – to improve the stability of IT systems and protect them effectively against cyberattacks.

Eine Person, die einen Taschenrechner benutzt
Implementation of “new” IT regulatory requirementsㅤㅤㅤㅤㅤㅤㅤㅤ

Efficient implementation of regulatory requirements – using a holistic, practical and future-oriented approach. We support financial services providers in the structured implementation of regulatory IT requirements – from gap analysis to employee training. This makes regulation manageable, integrable and sustainably effective.

Ein Mann und eine Frau, die auf einen Laptop schauen
IT audit preparation and supportㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤ

Mastering regulatory audits with confidence – using a structured, forward-looking and resilient approach. Whether it’s a recurring audit or an ad hoc one – we provide end-to-end support throughout the entire process: from requirements analysis and preparation to auditor communication. For transparency, early warning and long-term compliance.

Eine Frau, die auf einen Bildschirm zeigt
Optimizing IT compliance and governanceㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤㅤ

Strengthening IT compliance and governance – using a quantifiable, automated and resilient approach. We optimize IT compliance, develop resilience metrics and implement GRC tools – for efficiency and regulatory security in times of mergers, change or restructuring.

Eine Gruppe von Menschen klatscht in die Hände
IT compliance for newly founded financial services providers

Taking IT compliance into account right from the start – using a lean, scalable and regulatory-compliant approach. We help newly founded financial services providers set up an audit-proof IT governance scheme – from strategic design to the implementation of technical solutions, tailored to the business model and level of supervision.

Our services to support you

As part of our service portfolio, we advise you on IT compliance and digital operational resilience using a holistic approach that allows you to act effectively, sustainably and securely from a regulatory perspective.

We support you throughout the entire implementation process – from assessing your status quo and analyzing your maturity level to the concrete implementation of regulatory requirements (e.g. DORA, AI Act, FinmadiG), to increasing the maturity level of your existing IT governance and risk management. We identify and leverage efficiency potential in a targeted manner, for example by strategically deploying GRC tools.

Whether it’s audit preparation, (special) audit support or the development of management-relevant resilience KPIs – we help you meet regulatory requirements in a sustainable manner and manage them at an operational level.

Feel free to contact us

Profilfoto_Buschmann_Roger.jpg

Roger Buschmann

Senior Manager

Ein Mann in Anzug und Krawatte

Stephan Sahm

Senior Manager