Andreas Rühl Consulting. Over 20 years of experience in high-security environments (Nuclear, Finance, Public Sector). BSI IT-Grundschutz, ISO 27001, and pragmatic crisis management.
Request ConsultationSelected mandates (2018–2025). Focus: Critical Infrastructure, regulated industries, and crisis management.
Supporting the implementation of an ISMS in a high-security environment.
Operational management of a cyber attack, forensics, and recovery.
Implementation of a municipal ISMS and closing security gaps after incidents.
Consulting and project management for building an internal SOC.
Incident management and alignment with BAFIN security standards.
Revision of internal guidelines in the context of Critical Infrastructures.
Extensive consulting (400 person-days) on integrating security standards.
Long-term support in building and operating the ISMS.
Preparation for TISAX assessments and optimization of IT security.
Those ensuring security in nuclear energy, banking, or the medical sector cannot afford mistakes. For over 20 years, I have stood for IT security that is resilient, not just compliant on paper.
"As a father of 10 children, I know what it means to keep an overview when things get chaotic. I bring this resilience and calm to every one of my client projects."
BSI IT-Grundschutz is often mandatory for German authorities and KRITIS operators. Companies aiming for a "Gold Standard" in security also benefit from the BSI 200-x standards.
Yes. I have extensive experience in Incident Response, Forensics, and Business Recovery – even under extreme pressure.
ISO 27001 is the international standard. VdS 3473 (which I co-authored) is specifically tailored for SMEs to achieve a solid protection level with reasonable effort.
Whether it's a BSI project, ISO preparation, or an interim mandate.