Client Success Stories

ITSCM FOR THE PREVENTION OF CYBER-ATTACKS & IN PREPARATION FOR NIS-2

Cyberattacks are the new normal. IT Service Continuity Management (ITSCM) has therefore become a core consulting capability for organisations seeking resilience and NIS‑2 readiness. We enable our clients to design and operationalise ITSCM by building robust response organisations and validating them through realistic scenarios such as controlled site isolation. Clear processes, defined roles and seamless integration with Risk Management and Business Continuity Management (BCM) transform resilience from a theoretical concept into a managed, long‑term capability.

 

The Customer

Kreis 1

SECTOR

Engineering & Manufacturing

Kreis 1

Turnover

> 5 BILLION EUR

Kreis 1

Employees

10.000 - 50.000

Initial Situation

Our client, a globally operating mechanical engineering company, is facing a rapidly intensifying threat landscape while simultaneously meeting rising regulatory demands such as NIS‑2, TISAX and ISO 27001.While a globally organised IT setup and initial security measures were already in place, cyber attacks, ransomware and targeted industrial espionage have significantly increased the pressure on operational resilience. The objective was clear: extend the existing IT service portfolio with a structured, enterprise‑wide IT Service Continuity Management (ITSCM) framework. Critical services needed to be transparently identified, responsibilities clearly defined and robust processes established – fully aligned with Business Continuity Management and Risk Management, including realistic stress tests such as controlled site shutdowns.

IT Service Continuity Management is a core capability for operating securely in a continuously evolving threat landscape.

Objectives

  • End‑to‑end analysis of critical IT services and their technical and organisational dependencies
  • Design and implementation of an ITSCM process with clearly defined roles, responsibilities and interfaces

  • Development and execution of realistic emergency scenarios, including site isolation and controlled shutdowns

  • Establishment of an IT emergency organisation and tight integration with existing processes such as Incident Management

Our Assignment

Cyber incidents are no longer exceptional events – they are a permanent reality. By introducing IT Service Continuity Management, establishing a dedicated IT emergency response organisation and validating capabilities through realistic test scenarios such as site isolation, the organisation achieves measurable resilience and NIS‑2 readiness. Clearly defined processes, roles and interfaces with Risk Management and Business Continuity Management ensure long‑term operational stability – even under extreme conditions.

Challenges

  • Limited transparency regarding business‑critical IT services and their dependencies

  • Unclear roles, responsibilities and decision paths in crisis situations

  • •Existing contingency plans that exist on paper but fall short in operational reality

Measures

  • Systematic analysis of critical IT services, conducted jointly with service owners to create transparency and decision‑ready insights

  • Design and establishment of a scalable IT emergency response organisation with clearly defined roles, responsibilities, processes and escalation paths

  • Planning and execution of realistic test scenarios, involving all relevant stakeholders to validate preparedness under real‑world conditions

KC Process Model

As part of the engagement, a structured end‑to‑end process model was established to introduce IT Service Continuity Management at enterprise level.

First, business‑critical IT services were identified and prioritised based on their impact on core business processes. Together with the responsible service owners, technical architectures were analysed to uncover vulnerabilities and systemic dependencies. Building on this foundation, short‑term resilience measures were defined while key stakeholders from infrastructure, production, risk management and Business Continuity Management (BCM) were aligned across services. To translate strategy into operational readiness, scenario‑based workshops were conducted, simulating realistic cyber incidents such as site isolation and controlled shutdowns. For execution, a dedicated IT emergency organisation was designed and implemented, including a separate tenant, dedicated hardware, defined access points and physical security controls.

This setup was fully integrated into existing alerting and communication mechanisms to enable fast, coordinated response capability. Integration into the Group‑wide BCM framework ensured that ITSCM became a permanent element of the overall resilience strategy. A real‑world site test with on‑site participants validated processes, communication and technology under live conditions. The resulting ITSCM framework was documented with clear governance, roles and interfaces to ITSM and BCM, creating a scalable and continuously evolving resilience capability.

Kreis 2

“In an increasingly interconnected, digitalised world, IT services are the backbone of every business model; resilience is not just a bonus – it is vital for survival!”

Alexander Lambrecht-Kuhn
Principal Consultant

Customer Benefits

Costs

A structured ITSCM approach reduces unplanned downtime, limits financial impact and protects operational continuity.

Compliance

ITSCM enables demonstrable compliance with regulatory requirements such as NIS‑2 through structured, auditable continuity planning.

Management

ITSCM creates transparency, strengthens trust in IT and enables informed, risk‑aware decision‑making at management level.

The question is no longer if a cyber incident will occur, but how resilient an organisation is when it does.