Cybersecurity · Information Security · Automation

Security & ISMS
automated with purpose.

Less manual follow-up. Current evidence. Clear accountability. We connect your security systems and processes, from technical findings to management decisions.

Matthias Totzauer · Advisory, development, integration and agreed operational support

Three choices for initial guidance

Where should you start?

The automation finder suggests a focused starting point. No registration. Your choices are processed only on this page and are not stored.

01 / Cybersecurity

Turn technology into working processes.

We integrate existing tools and build the missing connections. Every workflow has an owner, defined inputs and an explicit failure path.

01

Assets & security inventory

Combine system data from existing sources, assign ownership and expose gaps.

Workflow, outcome & approval

What we automate

Reconcile devices, software, protection status and owners; raise tickets for missing assignments.

What you receive

Asset register with data freshness, source and exception history.

How it stays controlled

OT queries and new data sources are agreed with operations first.

02

Vulnerabilities & patch coordination

Turn scanner findings into prioritised tasks with owners, deadlines and effectiveness checks.

Workflow, outcome & approval

What we automate

Link findings to assets and criticality, reduce duplicates, create tickets and schedule validation.

What you receive

Traceability from finding to confirmed remediation.

How it stays controlled

Patch approval, maintenance windows and rollback stay within change management.

03

SOC, SIEM & incident workflows

Enrich alerts and turn repeatable handling steps into documented playbooks.

Workflow, outcome & approval

What we automate

Retrieve context, correlate related reports, assign cases, track deadlines and prepare summaries.

What you receive

Playbooks with case history, escalation and measurable handling time.

How it stays controlled

Account suspension, isolation and blocklists have explicit approval and exception rules.

04

Identities & access

Coordinate joiners, movers, leavers and recurring access reviews end to end.

Workflow, outcome & approval

What we automate

Route requests, collect approvals, trigger defined tasks and escalate overdue reviews.

What you receive

Access evidence linking request, approval, execution and confirmation.

How it stays controlled

Business approvals, privileged access and emergency accounts are handled explicitly.

05

Cloud, endpoints & configuration

Compare agreed security baselines with the actual environment on a recurring basis.

Workflow, outcome & approval

What we automate

Report configuration drift, missing protection, expiring certificates and failed jobs.

What you receive

Visibility into deviations, exceptions and agreed fixes.

How it stays controlled

Automatic remediation follows testing, scope limits and agreed authorisation.

06

Phishing & email security

Structure reported-email handling and simplify feedback to reporters.

Workflow, outcome & approval

What we automate

Capture reports, query approved context sources, assign cases and prepare status updates.

What you receive

A consistent reporting and handling process with traceable decisions.

How it stays controlled

Quarantine, deletion and mail-rule changes follow defined authorisation.

02 / Information Security

Embed information security in everyday work.

Make recurring governance work predictable with sources, ownership, deadlines and professional approval. Integrate with existing ISMS and GRC tools.

07

ISMS, controls & evidence

Move recurring information-security work from spreadsheets and reminder emails into dependable workflows.

Workflow, outcome & approval

What we automate

Request evidence, collect it from approved sources, track due dates and initiate policy reviews.

What you receive

Control register with owners, sources, review dates and version history.

How it stays controlled

Evidence and control effectiveness require professional review; a green status is not certification.

08

Risks, actions & management reporting

Connect risks and actions to operational status and keep decision-makers informed.

Workflow, outcome & approval

What we automate

Consolidate action status, escalate overdue tasks and prepare source-linked metrics.

What you receive

Risk register, action overview and recurring executive reporting.

How it stays controlled

Risk assessment, risk acceptance and budget decisions stay with named owners.

09

Suppliers & third-party risk

Coordinate supplier and service-provider security reviews throughout the relationship.

Workflow, outcome & approval

What we automate

Route questionnaires, collect evidence, track expiry dates and trigger reassessment.

What you receive

Supplier register with review scope, open actions and next review date.

How it stays controlled

Exceptions, risk approvals and contractual decisions require professional judgement.

10

Awareness & training evidence

Coordinate training, acknowledgements and recurring awareness activities.

Workflow, outcome & approval

What we automate

Assign audiences, send invitations and reminders, and track completion and content versions.

What you receive

Overview of assigned training, deadlines and evidence.

How it stays controlled

Privacy, employee representation and permitted reporting are agreed before rollout.

11

Backup, BCM & recovery

Bring backup status, recovery tests and exercises into ongoing management.

Workflow, outcome & approval

What we automate

Report failed backups, schedule restore tests, track actions and request emergency-contact reviews.

What you receive

Evidence of backups, tests, deviations and open actions.

How it stays controlled

Successful backups do not replace restore tests; production recovery remains a controlled decision.

12

CRA, SBOM & secure development

Connect product security with engineering, vulnerability handling and support.

Workflow, outcome & approval

What we automate

Import component inventories and SBOMs, route advisories, record approvals and track support periods.

What you receive

Product-specific evidence from components to vulnerability handling.

How it stays controlled

CRA scope, conformity and external reports are reviewed and approved by responsible people.

An illustrative workflow

From finding to dependable evidence.

  1. 1Finding arrives
  2. 2Asset & owner identified
  3. 3Ticket & deadline assigned
  4. 4Remediation approved
  5. 5Result verified
  6. 6Status & evidence updated

An example adapted to your data quality, responsibilities and tools. Errors, missing responses and exceptions are explicitly escalated.

From selection to operation

A focused pilot. A maintainable workflow.

We start with one bounded process and measurable objectives. Further workflows build on a dependable foundation.

  1. 01

    Understand

    Document the process, data, owners, failure cases and intended value.

  2. 02

    Build

    Agree access and approvals. Configure integrations and develop missing components.

  3. 03

    Validate

    Test realistic cases, duplicates, failures, rollback and acceptance criteria.

  4. 04

    Hand over

    Provide documentation, monitoring, ownership and agreed support arrangements.

What delivery includes

Process model and responsibilities, agreed configuration or source code, interface documentation, access model, test and acceptance records, error monitoring and an operating guide. We agree metrics upfront, such as handling time, overdue tasks, evidence age or manual steps.

Possible environments include Microsoft Sentinel, Defender, Entra ID, Microsoft 365, Azure, Wazuh, GLPI, Topdesk, Jira and existing GRC tools. Actual connections depend on APIs, licences, data quality and approved access.

Before your first automation.

Do we need to replace our security tools?

Usually the starting point is the existing landscape. We assess what can be connected, where data is missing and where a focused application makes sense.

Does automation act without human approval?

The permitted actions are defined per workflow. Collecting and reporting can be automated, while consequential actions can require approval. Production changes need tested rules, scope limits and a recovery path.

Can AI support the process?

Where useful, AI can assist classification, summaries and drafts. Data destinations and confidentiality are agreed first. Outputs are checked; risk acceptance, conformity and critical changes stay with responsible people.

Does this include ISO 27001 certification or guaranteed compliance?

No. Automation supports the ISMS and evidence preparation. Assessing effectiveness, legal requirements and certification remains a separate professional task.

Who operates the workflows after launch?

We agree ownership, monitoring, update handling and support before handover. Ongoing operational support is available within an expressly agreed scope; a 24/7 SOC is not implicitly included.

Where do you work?

ITCST is based in Wunsiedel, Bavaria. We support organisations in Germany and across Europe, remotely and on site by agreement, in German and English.

Your next step

Which workflow should get easier?

Tell us the process, the systems involved and the current bottleneck. Together, we define a useful first engagement.

Enquire about automation ↗

Technical reference points: NIST · Continuous Monitoring · Microsoft · Security Orchestration & Automation