Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

DIN SPEC 27076 · BSI Standard

BSI CyberRisikoCheck per DIN SPEC 27076

The state-supported IT security check for SMEs. In a structured interview with 27 questions we assess your current security level - and show where your organisation needs to act immediately.

BSI CyberRisikoCheck authorised · AZAV-certified consultant · Results within 1 week · SMEs < 50 employees

CyberRisikoCheck

per DIN SPEC 27076

  • Standardised 27-question interview
  • 6 IT security topic areas
  • Individual risk report
  • Prioritised action recommendations
  • Up to 50% subsidy possible
  • Completed within half a day

Certification

AZAV-certified consultant

Subsidisable consulting services

Trusted by our clients

27
Assessment questions per DIN SPEC 27076
6
Topic areas
50%
Subsidy possible
½ day
Duration

The Standard

What is the BSI CyberRisikoCheck?

The CyberRisikoCheck is a procedure developed by Germany's Federal Office for Information Security (BSI) and standardised through DIN SPEC 27076. It was designed specifically for small and medium-sized organisations that do not have their own IT security department.

01

Standardised per DIN SPEC 27076

DIN SPEC 27076 defines the exact process, the 27 questions, and the assessment methodology. As an authorised consultant we conduct the check to this uniform standard - comparable, transparent, and recognised.

02

Subsidisable consulting

As an AZAV-certified consultant we review your individual funding options. Regional digitalisation grants and state programmes can significantly reduce costs. We advise you on eligibility free of charge.

03

Immediately actionable results

You receive not generic security advice, but a prioritised action plan for your organisation. We distinguish quick wins that can be implemented immediately from strategic measures with a medium-term horizon.

At its core, the check consists of a structured interview with 27 questions, conducted with you and your IT responsible. Deep technical prior knowledge is not required - the questions are formulated in a practical and understandable way.

The result is an individual risk report showing your current security level across six topic areas with concrete, prioritised recommendations. Not abstract concepts - but a clear plan of what to do next.

The Structure

The 6 Topic Areas of the CyberRisikoCheck

The 27 questions of DIN SPEC 27076 are structured across six topic areas covering the most important IT security domains for SMEs.

01

Organisation & Processes

How is information security organised in your company? Are responsibilities, policies, and emergency plans in place? This area covers the foundation of every IT security strategy.

02

Identity & Access Management

Who has access to which systems and data? Are password policies and multi-factor authentication in use? Unauthorised access is one of the most common entry points for cyber attacks.

03

Data Backup

Are your data backed up regularly? Is restoration guaranteed in an emergency? Without a functioning backup concept, a ransomware attack can permanently cripple operations.

04

Patch Management

Are operating systems and software updated promptly? Structured patch management closes known vulnerabilities promptly - prioritised by criticality and patch availability.

05

Malware Protection

Are endpoints and servers protected by up-to-date antivirus and endpoint detection? Are systems monitored for unusual behaviour? Malware is involved in 6 out of 10 attacks.

06

IT Systems & Networks

Are your networks segmented and protected by firewalls? Is there an up-to-date inventory of all IT systems? A complete overview of your IT landscape is a prerequisite for any security strategy.

Our approach

From enquiry to risk report in one week

The CyberRisikoCheck is deliberately lean and efficient. No weeks-long process - quickly and easily you receive clear insights about your security posture.

01

Initial consultation & scheduling

30 min.

In a brief initial call (approx. 30 minutes, by phone or video conference) we clarify the framework conditions, answer your questions, and schedule the interview appointment. No engagement without complete information.

02

Structured interview - on-site or remote

½ day

A certified AWARE7 consultant conducts the standardised interview with 27 questions - in your infrastructure or via video call. Participants should include management and IT responsible persons. The interview takes approx. 2-4 hours.

03

Analysis & risk report

3-5 days

We analyse the responses systematically per DIN SPEC 27076 and create your individual risk report. This shows the fulfilment level per topic area, identified risks by criticality, and a consolidated overall assessment.

04

Results presentation & recommendations

1-2 hrs.

In a joint results presentation we explain your risk profiles and provide prioritised, actionable recommendations. You receive a clear roadmap - what to do immediately, and what to address in the medium term.

Why AWARE7 for the CyberRisikoCheck

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

01

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

02

Digital sovereignty: no compromises

100 %

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty
03

Fixed price within 24h: predictable project timelines

24 h

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

04

Your dedicated contact

1:1

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

FAQ

Frequently asked questions about the CyberRisikoCheck

Questions about the process, subsidies, or results? Find answers to the most common questions here.

The BSI CyberRisikoCheck is a standardised procedure per DIN SPEC 27076, developed specifically for small and medium-sized enterprises (SMEs) with up to 50 employees. In a structured interview with 27 questions, the IT security level is assessed across 6 topic areas. The result is an individual risk report with prioritised recommendations. The check is deliberately low-threshold - without deep prior knowledge your company can find out where it stands in IT security.
As an AZAV-certified training provider, our consulting services can be subsidised through various funding channels. Depending on the federal state and company size, regional funding programmes, digitalisation grants, and the Qualification Opportunities Act (Qualifizierungschancengesetz) are available. We assess your individual eligibility for funding free of charge in the initial consultation.
Yes, fundamentally. A penetration test is a technical security assessment in which real attacks on your systems are simulated. The CyberRisikoCheck, by contrast, is an organisational interview procedure: no systems are attacked, no ports are scanned. It assesses whether the most important IT security measures are fundamentally in place and organisationally embedded. The check is ideal as a first step - the penetration test as a more in-depth measure afterwards.
You receive a structured risk report with your security level per topic area and concrete recommendations for action. Many organisations use this report as a basis for the next discussion with management or the supervisory board. On request, we accompany you in implementing the measures - from simple quick wins through to building a complete ISMS per ISO 27001.
The structured interview typically takes 2-4 hours. You should plan for half a day in total. Ideally, management and those responsible for IT should participate. Deep technical knowledge is not required - the questions are formulated in a practical and understandable way. After the interview we require 3-5 working days for analysis and preparation of the risk report.
The CyberRisikoCheck is designed specifically for SMEs, which are typically not directly affected by NIS-2. It is an excellent starting point for establishing basic IT security measures. For organisations that actually fall under the NIS-2 Directive, we additionally recommend our NIS-2 consulting and the construction of an ISO-27001-compliant ISMS. Contact us - together we will find the right approach for your starting position.

Ready to find out where you stand?

Discover in half a day where your organisation really stands in IT security - structured, standardised per DIN SPEC 27076, and with up to 50% state subsidy.

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen