Many IT-Grundschutz projects begin with a long list of requirements. That looks thorough, but it quickly produces scattered spreadsheets, inconsistent ownership, and evidence that has to be gathered just before an audit.
A better starting point is a clean scope. Which organizational units, processes, applications, IT systems, networks, and service providers genuinely belong in the security concept? This decision determines which modules are relevant and which evidence will later need to withstand an audit.
Modeling connects real target assets to suitable IT-Grundschutz modules. Its value does not come from the assignment alone, but from whether the information domain's structure is represented coherently.
If a critical process depends on an application, a network segment, and an external provider, that dependency must be visible in the security concept. Only then can protection needs, implementation status, and residual risks be explained convincingly.
For the first defensible pass, a clear and compact scope is often more useful than a broad but vague one. Start with a representative information domain whose processes, applications, and infrastructure are well understood.
The method can then be repeated: add target assets, extend module assignments, propagate protection needs, prioritize open safeguards, and group evidence by ownership.
Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.
With the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.
Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.
Fewer job postings, restructuring at large consultancies and more visible solo consultants: what the data reveals about the cybersecurity consulting market.