SMEs in the crosshairs
Small and medium-sized enterprises are specifically targeted - because attackers expect less resistance there. Many incidents go unnoticed for a long time, until the damage is already done.
SME Security Assessment
Our 360-degree security assessment shows you the true state of your IT security in 2-3 weeks - externally, internally and organisationally. Specifically designed for small and medium-sized enterprises.
Trusted by over 200 SMEs
Threat Landscape
SMEs are attractive targets - because attackers know that budget and personnel for IT security are often limited there.
Small and medium-sized enterprises are specifically targeted - because attackers expect less resistance there. Many incidents go unnoticed for a long time, until the damage is already done.
Business interruption, data recovery, legal costs and reputational damage can add up quickly. For an SME, a single incident can threaten the existence of the business.
The NIS-2 transposition law in Germany has been in force since 06.12.2025 and massively expands the circle of regulated organisations. Many SMEs are also affected - with personal liability for company directors.
Three Components
Our SME Security Assessment combines three components into a cost-effective package. Each valuable on its own, unbeatable together.
What does your organisation look like to an attacker? We check all externally reachable systems and services:
On-site or via VPN we review your internal infrastructure for the most common vulnerabilities:
Half-day interactive workshop in which we present results clearly, identify quick wins and jointly develop a roadmap for the next 6-12 months:
Funding eligible
DIN SPEC 27076 was developed by the BSI (German Federal Office for Information Security) and the German SME Association - specifically for organisations with fewer than 50 employees. 27 requirements across 6 topic areas, completable in approx. 3 hours. Eligible for funding in several German federal states.
Your Contact Persons
Our consultants know the typical vulnerabilities in SMEs - and which measures have the greatest impact.
How it works
Personal meeting to capture your IT landscape, business processes and security requirements. We understand your organisation before we assess it.
Review of your externally reachable systems: web presence, mail security (SPF, DKIM, DMARC), DNS configuration, SSL/TLS and cloud services. What does an attacker see from outside?
On-site or remote review of your internal IT: Active Directory, network segmentation, patch management, backup strategy, endpoint security and access controls.
Interactive workshop with management and IT leads. Understand results, identify quick wins, develop a roadmap. Optionally with a live hacking demonstration.
Management-ready report with traffic-light ratings, a prioritised action plan and a realistic roadmap for the next 6-12 months.
Comparison
Three approaches to IT security - each has its place. The SME Assessment combines the best of both worlds.
| CyberRiskCheck | Penetration Test | SME Assessment | |
|---|---|---|---|
| Focus | Organisational | Technical depth | Technical + Organisational |
| Duration | 3 hours | 5-15 days | 2-3 weeks |
| Workshop included | No | Optional | Yes, always |
| Roadmap | Recommendations | Vulnerability list | 6-12 month action plan |
| Ideal for | Entry point (<50 employees) | Specific systems | Full overview (20-500 employees) |
| Funding eligible | Yes (DIN SPEC) | No | Yes (as CyberRiskCheck) |
References
These case studies are available in German.
Next Steps
The security assessment shows where you stand. These services help close the identified gaps:
ISO/IEC 27001 certified · BSI qualified · DIN SPEC 27076 qualified · AZAV accredited training provider
Why organisations trust AWARE7
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
Frequently Asked Questions
Aus dem Blog
Ein IT-Security E-Learning kann in Unternehmen zum Schutz vor erfolgreichen Cyberattacken eingesetzt werden. Das sind die Gründe!
Entdecke 9 Hacking Gadgets und erfahre, wie du sie sicher, legal und verantwortungsvoll nutzt, um IT-Sicherheit wirklich zu verstehen.
WeTransfer speichert teils Daten auf Servern in den USA. Das birgt Risiken und ruft WeTransfer-Alternativen auf den Plan.
Briefly describe your IT landscape - we will provide you with an individual quote within 24 hours. Free and non-binding.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days