Standardised per DIN SPEC 27076
DIN SPEC 27076 defines the exact process, the 27 questions, and the assessment methodology. As an authorised consultant we conduct the check to this uniform standard - comparable, transparent, and recognised.
DIN SPEC 27076 · BSI Standard
The state-supported IT security check for SMEs. In a structured interview with 27 questions we assess your current security level - and show where your organisation needs to act immediately.
BSI CyberRisikoCheck authorised · AZAV-certified consultant · Results within 1 week · SMEs < 50 employees
CyberRisikoCheck
per DIN SPEC 27076
Certification
AZAV-certified consultant
Subsidisable consulting services
Trusted by our clients
The Standard
The CyberRisikoCheck is a procedure developed by Germany's Federal Office for Information Security (BSI) and standardised through DIN SPEC 27076. It was designed specifically for small and medium-sized organisations that do not have their own IT security department.
DIN SPEC 27076 defines the exact process, the 27 questions, and the assessment methodology. As an authorised consultant we conduct the check to this uniform standard - comparable, transparent, and recognised.
As an AZAV-certified consultant we review your individual funding options. Regional digitalisation grants and state programmes can significantly reduce costs. We advise you on eligibility free of charge.
You receive not generic security advice, but a prioritised action plan for your organisation. We distinguish quick wins that can be implemented immediately from strategic measures with a medium-term horizon.
At its core, the check consists of a structured interview with 27 questions, conducted with you and your IT responsible. Deep technical prior knowledge is not required - the questions are formulated in a practical and understandable way.
The result is an individual risk report showing your current security level across six topic areas with concrete, prioritised recommendations. Not abstract concepts - but a clear plan of what to do next.
The Structure
The 27 questions of DIN SPEC 27076 are structured across six topic areas covering the most important IT security domains for SMEs.
How is information security organised in your company? Are responsibilities, policies, and emergency plans in place? This area covers the foundation of every IT security strategy.
Who has access to which systems and data? Are password policies and multi-factor authentication in use? Unauthorised access is one of the most common entry points for cyber attacks.
Are your data backed up regularly? Is restoration guaranteed in an emergency? Without a functioning backup concept, a ransomware attack can permanently cripple operations.
Are operating systems and software updated promptly? Structured patch management closes known vulnerabilities promptly - prioritised by criticality and patch availability.
Are endpoints and servers protected by up-to-date antivirus and endpoint detection? Are systems monitored for unusual behaviour? Malware is involved in 6 out of 10 attacks.
Are your networks segmented and protected by firewalls? Is there an up-to-date inventory of all IT systems? A complete overview of your IT landscape is a prerequisite for any security strategy.
Our approach
The CyberRisikoCheck is deliberately lean and efficient. No weeks-long process - quickly and easily you receive clear insights about your security posture.
In a brief initial call (approx. 30 minutes, by phone or video conference) we clarify the framework conditions, answer your questions, and schedule the interview appointment. No engagement without complete information.
A certified AWARE7 consultant conducts the standardised interview with 27 questions - in your infrastructure or via video call. Participants should include management and IT responsible persons. The interview takes approx. 2-4 hours.
We analyse the responses systematically per DIN SPEC 27076 and create your individual risk report. This shows the fulfilment level per topic area, identified risks by criticality, and a consolidated overall assessment.
In a joint results presentation we explain your risk profiles and provide prioritised, actionable recommendations. You receive a clear roadmap - what to do immediately, and what to address in the medium term.
References
These case studies are available in German.
Why AWARE7 for the CyberRisikoCheck
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
FAQ
Questions about the process, subsidies, or results? Find answers to the most common questions here.
Aus dem Blog
BSI IT-Grundschutz für KMU: pragmatischer Einstieg mit dem KMU-Profil, wichtigste Bausteine, kostenlose BSI-Werkzeuge und Unterschied zu ISO 27001.
Der Informationssicherheitsbeauftragte ist der Ansprechpartner für Informationssicherheit im Unternehmen. Diese Aufgaben hat er!
Scope definieren, Angebote vergleichen, Qualifikationen prüfen: So wählen KMU den passenden Pentest-Anbieter - ohne Fallstricke.
Discover in half a day where your organisation really stands in IT security - structured, standardised per DIN SPEC 27076, and with up to 50% state subsidy.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days