DQ Security AuditKnow your weak points
before someone else finds them.
The DQ Security Audit shows you where your business really stands today.
Many businesses spend money on IT security without knowing whether it's going where it's actually needed. The DQ Security Audit brings clarity: structured, based on a recognised security standard, and with concrete recommendations as the result.
Cybersecurity affects everyone
SMEs manage sensitive data and run critical systems. Anyone who does is a realistic target.
Cybercriminals invest effort where resistance is lowest. Large corporations have security teams, sophisticated monitoring systems and substantial budgets. SMEs often have none of this, yet face similar systems, data and risks.
The tricky part: most vulnerabilities are silent. No alarm, no warning. An employee clicks a phishing email. A system has gone two years without an update. The server room is accessible to anyone who knows where to look. Such gaps exist in many businesses, usually unnoticed.
If you don't know your own security status, you can neither prioritise risks nor reduce them in a targeted way. A security audit creates transparency and shows exactly where action is needed.
OUR APPROACH
Six layers of your
IT security under the microscope
The assessment is based on the 7-Layer Model of IT Security,
the most established framework in cybersecurity.
A firewall won't protect you from an employee giving away their password. And awareness training won't help if your network segmentation has gaps. IT security only works when all relevant areas work together.
That's why the DQ Security Audit is based on the 7-Layer Model of IT Security. It looks at your security architecture holistically: from your most business-critical systems right through to the human factor. We analyse six of the seven layers as part of the audit.
Application Security, meaning the targeted review of individual business applications at code level, is deliberately excluded. It requires a separate, dedicated analysis.
You get a complete picture of your infrastructure, exactly where attacks actually happen.
WHAT WE REVIEW
Your IT security, systematically analysed
Our analysis is based on an established layer model of IT security and shows you
where your IT is already well positioned and where action is needed.
Mission Critical Assets
Some systems are the core of your operation: ERP applications, Active Directory, CRM. If one of these fails, it's not just one department that stops, it's the whole business. We check whether these systems have clear ownership and whether a targeted response is even possible in an emergency.
Data Security
Data is created in many places at once: local servers, cloud services, mobile devices, collaboration platforms. We assess whether access controls are effective, whether backups actually exist, and whether sensitive information is classified. Distributed environments such as Microsoft M365 often reveal unexpected gaps here.
Endpoint Security
Every laptop and mobile device is a potential way in. Risks are especially high when working from home, where devices are used outside the company network. We check whether patch management is centrally controlled and whether modern malware protection is active across the board.
Network Security
Once an attacker has compromised a device, the network determines how far the threat can spread. Well segmented networks limit the damage. We analyse whether VLANs are sensibly separated, whether firewalls are correctly configured, and whether internal data flows are controlled.
Perimeter Security
The perimeter is the first line of defence, both digital and physical. We look at both: secure VPN access, multi-factor authentication, as well as the question of who has physical access to your server room. Both belong to the same security strategy.
Human Layer
People make mistakes. That's not a criticism, it's a fact that every security strategy needs to factor in. We check whether your employees are regularly trained to recognise current attack methods and whether phishing simulations are used. A well trained team is an active part of your defence.
OUR PROCESS
From initial consultation to report
Structured, transparent, with minimal effort on your part.
An audit doesn't have to be a major project. Our process is designed to place as little burden as possible on your operations while still delivering a complete, reliable result.
STEP 1
Initial Consultation & Goal Setting
We start by clarifying your situation together: where you stand today, what matters most to you, and what you want to achieve with the audit. You'll learn how our traffic-light model works and exactly what you'll have in hand at the end.
STEP 2
On-Site & Remote Analysis
We kick things off together at your premises. From there, our specialists continue the work either on site or remotely, depending on what's needed, with no extra effort required from you. We gather configurations, system setups and processes directly together with your responsible staff.
STEP 3
In-Depth Technical Analysis
Our IT security specialists then take over. Where needed, they log into relevant systems, firewall configurations, the M365 admin centre, and verify the collected data on a technical level.
STEP 4
Documentation & Evaluation
All findings are brought together in a structured report. Every checkpoint is assessed using the traffic-light model: green, amber, red. You can see at a glance what's solid, what needs attention, and what's urgent.
STEP 5
Final Discussion
We present the results together, explain the context, and highlight which measures will have the biggest impact. The report becomes the foundation for your next decisions around IT security.
Your next step
Got questions about the process, or ready to get started? Our experts are here for you personally.
YOUR RESULT
A report that drives decisions instead of postponing them
Not a list of problems without context, but clear priorities with the background that matters.
After the audit, you'll have a report in hand that shows where your business stands today, which areas are solid and where there's real need for action. Not as a vague recommendation, but with clear priorities.
Your cybersecurity status, assessed clearly and transparently.
No internal gut feeling, no guesswork. We analyse your IT security using a structured, proven methodology, free from internal blind spots. Whether it's missing offsite backups, gaps in endpoint protection, or missing MFA on external access points: the report shows you clearly where the real weaknesses lie and which measures make sense.
Prioritised next steps mean you know what needs tackling right away, what's relevant in the medium term, and what pays off in the long run. That protects your budget from untargeted spending.
If you need support implementing the recommendations after the audit, we're happy to help with that too. From planning individual measures through to ongoing operation of security solutions.
OUR OFFER
All inclusive, from the initial consultation right through to the final discussion.
Initial consultation and goal setting
On-site analysis
Technical evaluation
Audit report with traffic-light assessment
Results discussion
