Security
Backup, endpoint, mail security, monitoring - and the compliance obligations
Security that works day to day, not just on slides. We implement what insurers require, what NIS2 prescribes, and what would actually have helped after a real incident.
Was wir in der Säule Security machen.
3 Topics, jedes einzeln buchbar oder als Gesamt-Setup. Klick auf eine Zeile öffnet die Detail-Page.
| No | Topic | Type |
|---|---|---|
| 01 | Backup· 3-2-1, versioned, tested - and genuinely restorable | Topic |
| 02 | Endpoint security· Patching, EDR, MDM - every device secured and managed | Topic |
| 03 | Monitoring· Uptime, logs, alerts - see problems before clients report them | Topic |
So bauen wir.
Vier Punkte, die in jedem Projekt der Säule Security unverhandelbar sind.
About this pillar.
What security means at CAVORT
Security is not a product you buy once and are then done with. It is an ongoing process that has to fit how you actually operate. We build security that does not get in the way day to day and that holds up when it matters.
Backup
A backup is worth nothing if you cannot restore from it. We follow the 3-2-1 rule:
- 3 copies of your data
- 2 different storage media
- 1 copy off site (ideally immutable)
A typical setup:
- Veeam for Windows, Linux and VM backup, often onto a Hetzner storage server
- Proxmox Backup Server for the Proxmox environment, deduplication-based
- Cold storage or S3-compatible storage with object lock for the immutable copy
- Microsoft 365 backup (Veeam or Dropsuite) - Microsoft does not back you up, you have to do that yourself
More important than the tools: restore tests. We test random files quarterly and run full scenarios annually in a test network.
Endpoint security
Patching is the least glamorous and most important single measure. We automate it through Intune, Tactical RMM or WSUS, depending on the ecosystem. On top of that EDR - usually Microsoft Defender for Endpoint for Microsoft clients, CrowdStrike or SentinelOne where it has to be.
The standard stack for a laptop:
- Full-disk encryption (BitLocker or FileVault)
- Automatic OS patches and application updates
- EDR with a central dashboard
- USB control (depending on the sector)
- Screen lock on inactivity
- MDM for remote wipe if a device is lost
Mail security
Eighty percent of attacks start with email. We harden mail with:
- DMARC enforcement (from none to reject, with aggregate reports)
- DKIM rotation every six months
- SPF, strict
- Proofpoint or Microsoft Defender for Office 365 against phishing and spear phishing
- Attachment sandboxing for risky file formats
- Anti-impersonation and brand spoofing protection
Monitoring
Without monitoring you find out about problems when a client calls. We use Uptime Kuma, Grafana, Sentry and hyperscaler-native tools to:
- check HTTP and HTTPS endpoints
- track server health (CPU, RAM, disk, network)
- spot log anomalies
- catch application errors in web apps
- warn about certificate expiry in good time
Alerts arrive by email, Matrix chat or phone - the last of those only for genuine emergencies such as a total outage.
NIS2 and compliance
Since it came into force, NIS2 is mandatory for “important” and “particularly important” entities. We support:
- applicability assessment (does this affect you?)
- risk management concept
- incident response plan
- technical and organisational measures
- monitoring and reporting paths
- annual review
We are not lawyers - we do the IT side. Legal review we bring in through partner law firms.
How we work together.
From the first hello to running operations in five steps.
Security - frequently asked.
FAQ.01Do we really need NIS2 preparation?
If you are an "important" or "particularly important" entity in Germany (see the BSI list of affected sectors and thresholds), it is mandatory. But even if you are not: your cyber insurer will probably require comparable baseline protection in 2026 or 2027 before paying out on a claim. Our advice - if the company has 50+ staff and meaningful digital value creation, you should have a NIS2-equivalent set of measures.
FAQ.02What does a backup strategy cost?
For a mid-market company with 50 staff we typically budget 300 to 700 EUR per month (storage, software licence, monitoring, tested restores). One-off setup comes on top, five to fifteen project days depending on the starting point. It can be done far cheaper, but that is usually "backup theatre" - copies that will not hold up when it counts.
FAQ.03How often do you test restores?
At least quarterly for critical systems. Once a year a full disaster recovery run in a test network. That is the point where a backup strategy is actually tested - the number of backups is irrelevant if the restore chain is broken.
FAQ.04Endpoint protection - is Windows Defender enough?
For most mid-market companies: yes, plus Microsoft Defender for Endpoint as an upgrade. We only deploy third-party tools (CrowdStrike, SentinelOne) where compliance requires it or the scale justifies it. The brand matters less than whether somebody actually looks at the alerts.
FAQ.05What matters more, backup or EDR?
Backup. Always. If you had to choose, build a genuinely working backup system first. EDR without backup protects against current attacks, but if one gets through you are lost. Backup without EDR is slower, but survivable.
FAQ.06Do you run phishing awareness training?
Yes, we work with partners such as KnowBe4 or build small campaigns ourselves. Technical protection without training the people is worthless - most incidents start with a clicked email.
FAQ.07Can you help after an incident?
Yes, we do incident response - but we are not a forensics specialist. On the IT side (recovery, remediation, temporary systems) we are well equipped. For the legal and forensic side we bring in partners.
Sprechen wir 30 Minuten über Security.
The intro call is free. No sales pressure. We listen, check whether we fit - and tell you straight.