IT security workshop · NIS2 & ISO 27001 · 1 day

IT-security workshop for SMEs (NIS2-ready)

NIS2 also affects Swiss SMEs that sell into EU supply chains. The SIDD IT security workshop assesses your IT infrastructure in one day, identifies risks and vulnerabilities and delivers an action plan, compatible with ISO 27001 and NIS2 requirements.

CHF 2'500 – 5'000 1 day NIS2 · ISO 27001
IT Security Workshop for SMEs - NIS2 and ISO 27001
Lead Auditor ISO 27001 (BSI)

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this workshop

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Leads IT security workshops for SMEs focusing on network segmentation, IAM, patch management, backup, awareness and NIS2 preparation.

LinkedIn profile

How the IT security workshop helps your SME

One day that makes risks visible and delivers an actionable plan.

  • Identification and assessment of the key IT risks and vulnerabilities
  • Definition of your IT security requirements, tailored to your industry and contractual landscape
  • Action plan with concrete protective measures and priorities
  • Determination of legal requirements (revised FADP, NIS2, DORA, FINMA outsourcing)
  • Strengthening customer trust through a documented security status
  • Optional preliminary step toward an ISO 27001 certification

Workshop agenda (hour by hour)

Format: 1 day (3 h workshop + 2 h preparation + 3 h follow-up). Workshop via Teams or on site.

– 2 weeks: preliminary briefing

Questionnaire on IT setup, network, cloud, endpoints and critical systems.

– 1 day: preparation

2 h SIDD preparation, analysis of your information, identification of critical focus areas.

0:00 – 0:30: IT profile & risk appetite

Business model, IT setup, risk situation, legal framework.

0:30 – 1:30: Identity, access & network

IAM, MFA, segmentation, remote access, external interfaces.

1:30 – 2:30: Endpoint, patch & backup

EDR, patch management, backup strategy, recovery after an incident.

2:30 – 3:00: Awareness, incidents & Q&A

Training needs, incident response, NIS2/DORA requirements, open questions.

+ 5 days: report

3 h of SIDD follow-up, list of gaps with prioritisation and recommended actions.

Package & price

Flat rate. Complexity surcharges depending on the industry (e.g. medical technology, FINMA-regulated).

What are the next steps after the workshop?

You decide afterwards, there is no obligation to engage us further.

Type of findingRecommended follow-up service
Vulnerabilities in public-facing systemsVulnerability scan from CHF 5'000
In-depth validation of critical applicationsPenetration test
Building a complete ISMSISO 27001 consulting
No designated ISO / executive management riskExternal CISO/ISO/Information Security Officer
Data protection gaps (in parallel with IT security)Data protection workshop

What happens after the engagement is awarded?

Engagement

By email. You receive a preparation checklist with all the information required in advance.

Workshop

3 h via Teams or on site. All key IT security topics are covered.

Report

Prioritized report with concrete recommendations for action, e.g. network segregation, patch management, backup, penetration test.

Optional: follow-up mandate

On request, we support you as external ISO or accompany a Penetration test.

Why SIDD?

Why SMEs commission the IT security workshop from SIDD instead of merely working through a checklist.

One day, one action plan

In a single day, the workshop delivers a well-founded assessment of your IT infrastructure without requiring you to commit to a long mandate. You receive a prioritized action plan that your team can work with right away.

NIS2 and the ICT minimum standard

Our in-house InfoSec team assesses your infrastructure technically, while lawyers holding doctorates contextualize the regulatory framework. This way you understand what NIS2 means for you as a supplier in EU supply chains and where the Swiss ICT minimum standard (NCSC) applies.

Recognised testing frameworks

The assessment follows established reference frameworks and is mapped to ISO/IEC 27001 Annex A as well as the NIS2 requirements. The workshop is led at a senior level, by an ISO/IEC 27001 Lead Auditor (BSI-trained).

Confidential, data in Switzerland

Findings on risks and vulnerabilities are sensitive and remain in Switzerland, protected by an NDA and a duty of confidentiality. Where Dr. Staiger provides a legal assessment, attorney professional secrecy under Art. 321 SCC additionally applies.

A report, not a slide deck

You leave the workshop with a robust report on risks, vulnerabilities and measures, not with a slide deck. The result holds up before customers, auditors and the board of directors.

Independent, with no sales pressure

We strictly separate consulting and assessment, so the findings remain neutral. We point out sensible next steps such as a penetration test, vulnerability scan, ISMS or a CISO mandate, without requiring you to commission them from us.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the workshop report, concretely: LexCommand maps your findings across ISO 27001 Annex A, NIS2 and the Swiss ICT minimum standard and backs every regulatory reference in the prioritised gap list with its exact primary source, so overlapping duties surface together.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

What does the workshop cost?

CHF 2'500 – 5'000 as a flat rate. Sectors with a high compliance density (medical technology, FINMA) are at the upper end.

Who should take part?

IT managers, executive management and, where applicable, the person responsible for data protection. Ideally 2–5 participants.

Is the workshop NIS2-ready?

Yes. We take into account the NIS2 requirements (risk management, incident reporting, supply chain security) and map them to your current status. Full NIS2 compliance generally requires a follow-up project.

On site or remote?

Both options are possible. By default via Microsoft Teams. On-site workshop based on effort and travel costs, gladly in the Zurich / Zug area.

What does the report contain?

A gap list with prioritisation (critical / high / medium), concrete recommended actions, estimated effort, references to templates and possible follow-up mandates.

Are the workshop contents subject to confidentiality?

Yes, Art. 321 SCC. All content and the report are shared exclusively with the people you designate.

Your IT security status in a single day, NIS2-ready.

First download our self-check, or request a workshop date directly.