01 — Cyber Security & GRC

Sicherheit, dieSecurity that zum Betrieb passt.fits how you work.

Ich baue Informationssicherheits-Managementsysteme auf, die im Audit bestehen und den Betrieb nicht ausbremsen – nach ISO/IEC 27001 und BSI IT-Grundschutz. Ohne Papiertiger, mit klaren Verantwortlichkeiten und in einer Sprache, die auch die Geschäftsführung versteht. I build information security management systems that pass the audit without slowing down operations – based on ISO/IEC 27001 and BSI IT-Grundschutz. No paper tigers, clear responsibilities, and in a language the board understands, too.

01Wer ich binAbout me

Ich bin ISMS- & GRC-Consultant und Informationssicherheitsbeauftragter aus Köln. I'm an ISMS & GRC consultant and information security officer based in Cologne.

Als ISB eines IT-Dienstleisters für öffentliche Auftraggeber und das Verteidigungsumfeld habe ich ein ISMS von Grund auf aufgebaut – Risikomethodik, Richtlinien, Schulungen, Incident-Prozess und Management-Review. Nach acht Monaten stand das erste ISO-27001-Zertifizierungsaudit: bestanden mit nur zwei geringfügigen Abweichungen. Dazu kamen Betrieb und Absicherung von SINA-Arbeitsplätzen für VS-NfD-Umgebungen. As information security officer at an IT service provider for public-sector and defence clients, I built an ISMS from scratch – risk methodology, policies, training, incident process and management review. Eight months in came the first ISO 27001 certification audit: passed with only two minor nonconformities. I also ran and secured SINA workstations for classified (VS-NfD) environments.

Davor war ich über fünf Jahre Prozess- und Projektmanager im Mittelstand: Ich habe Abläufe in Produktion, Lager und ERP/CRM optimiert, ein Erweiterungsprojekt mit rund 2 Mio. € Volumen samt Team geleitet und DSGVO- sowie GoBD-konforme Strukturen eingeführt. Before that I spent more than five years as a process and project manager at a mid-sized company: I optimised production, warehouse and ERP/CRM workflows, led a production expansion project worth around €2 million including its team, and introduced GDPR- and GoBD-compliant structures.

Neben der Governance trainiere ich die Angreiferseite: Pentesting-Labs auf Hack The Box, Lockpicking und physische Sicherheit, aktuell die eJPT-Zertifizierung. Wer weiß, wie angegriffen wird, schreibt Maßnahmen, die tatsächlich schützen. Beyond governance I train the attacker side: pentesting labs on Hack The Box, lockpicking and physical security, currently working towards the eJPT. Knowing how attacks work leads to controls that actually protect.

StudiumDegree
B.A. Integrated Design (Note 1,2), KISD / TH KölnB.A. Integrated Design (grade 1.2), KISD / TH Köln
UmfeldSectors
Öffentlicher Sektor, Verteidigung (VS-NfD), MittelstandPublic sector, defence (VS-NfD), SMEs
ZertifikateCertificates
ITIL® 4 Foundation · Lean Six Sigma Yellow Belt · Information Security Core Skills (Antisyphon) · Data Literacy
In ArbeitIn progress
eJPT (INE), Abschluss geplant Ende 2026eJPT (INE), expected end of 2026
SprachenLanguages
Deutsch, Englisch (C1)German, English (C1)

02Warum ichWhy me

8 Monatemonths

Vom Start zum ZertifikatFrom kick-off to certificate

Vom leeren Blatt bis zur bestandenen ISO-27001-Zertifizierung – mit nur zwei geringfügigen Abweichungen.From a blank page to a passed ISO 27001 certification – with only two minor nonconformities.

+7 % ROI

ProzessdenkenProcess thinking

Als Prozessmanager habe ich Abläufe messbar wirtschaftlicher gemacht. Deshalb weiß ich: Sicherheit muss in bestehende Prozesse passen, nicht daneben stehen.As a process manager I made workflows measurably more profitable. That's why I know: security has to fit existing processes, not sit beside them.

Power Platform

Automatisiert statt abgeheftetAutomated, not filed away

Risikoregister, Meldeportal, Audit- und Review-Workflows in SharePoint, Power Automate und Power Apps – nachvollziehbar und auditfähig.Risk register, incident reporting portal, audit and review workflows in SharePoint, Power Automate and Power Apps – traceable and audit-ready.

Design

SystemdenkenSystems thinking

Mein Designstudium mit Schwerpunkt Kybernetik hilft mir, Organisationen als Ganzes zu sehen – und Richtlinien zu schreiben, die tatsächlich gelesen werden.My design degree with a focus on cybernetics helps me see organisations as a whole – and write policies people actually read.

03Was ich anbieteWhat I offer

  • 01

    ISMS-Aufbau nach ISO/IEC 27001 & BSI IT-GrundschutzISMS implementation (ISO/IEC 27001 & BSI IT-Grundschutz)

    Scope, Strukturanalyse und Schutzbedarf, Richtlinien, Risikobehandlung, Statement of Applicability und interne Audits – mit Begleitung bis zum Zertifikat und durch die Überwachungsaudits.Scope, asset and protection-needs analysis, policies, risk treatment, statement of applicability and internal audits – with support through to certification and the surveillance audits.

    ProjektProject
  • 02

    Risikomanagement, BCM & Incident ResponseRisk management, BCM & incident response

    Ein Risiko-Framework, das von der Identifikation bis zur Nachverfolgung trägt – plus Incident-, Notfall- und Wiederanlaufprozesse, die im Ernstfall funktionieren und nicht nur auf dem Papier.A risk framework that carries through from identification to follow-up – plus incident, emergency and recovery processes that work when it matters, not just on paper.

    MethodikMethod
  • 03

    Externer ISBExternal information security officer

    Ich übernehme die Rolle des Informationssicherheitsbeauftragten – als Interimslösung, dauerhaft oder zur Verstärkung Ihres Teams. Sie bekommen einen festen Ansprechpartner und regelmäßiges Reporting an die Leitung.I take on the information security officer role – as an interim solution, long-term or to strengthen your team. You get a single point of contact and regular reporting to management.

    LaufendOngoing
  • 04

    NIS2-ReadinessNIS2 readiness

    Betroffenheitsprüfung, Gap-Analyse, Registrierungs- und Meldepflichten und ein realistischer Umsetzungsplan. Die Kerndokumentation für die Risikomanagementmaßnahmen nach § 30 BSIG erstelle ich mit einem selbst entwickelten Generator – schnell und passgenau.Applicability check, gap analysis, registration and reporting obligations, and a realistic roadmap. I produce the core documentation for the risk management measures under Section 30 BSIG with a generator I developed myself – fast and tailored.

    AnalyseAssessment
  • 05

    GRC-Automatisierung mit Microsoft 365GRC automation with Microsoft 365

    Risikoregister, Maßnahmenverfolgung, Vorfallmeldungen und Freigaben mit SharePoint, Power Automate und Power Apps – statt Excel-Listen per Mail.Risk register, action tracking, incident reports and approvals with SharePoint, Power Automate and Power Apps – instead of spreadsheets by email.

    Tooling
  • 06

    Datenschutz- & Compliance-StrukturenData protection & compliance structures

    Verzeichnis von Verarbeitungstätigkeiten, DSGVO-konforme Dokumentation und GoBD-konforme Prozesse.Records of processing activities, GDPR-compliant documentation and GoBD-compliant processes.

    Compliance

04AblaufProcess

  1. ErstgesprächFirst call

    30 Minuten, kostenlos und unverbindlich. Wir klären Ausgangslage, Ziele und ob die Zusammenarbeit passt.30 minutes, free and without obligation. We clarify the situation, goals and whether we're a good fit.

  2. BestandsaufnahmeAssessment

    Interviews und Dokumentensichtung. Ergebnis: ein ehrliches Bild vom Status quo.Interviews and document review. The result: an honest picture of where you stand.

  3. Angebot & PlanProposal & plan

    Klarer Umfang, Meilensteine und transparenter Aufwand – ohne offene Enden.Clear scope, milestones and transparent effort – no loose ends.

  4. UmsetzungImplementation

    Gemeinsam mit Ihrem Team, in kurzen Iterationen mit regelmäßigen Abstimmungen.Together with your team, in short iterations with regular check-ins.

  5. ÜbergabeHandover

    Dokumentation, Wissenstransfer und auf Wunsch weitere Begleitung im laufenden Betrieb.Documentation, knowledge transfer and, if you like, continued support in day-to-day operations.

05KontaktContact

Wo steht Ihre Informations­sicherheit heute?Where does your information security stand today?

info [at] julianhabermann.de

Schreiben Sie mir kurz, worum es geht – ich melde mich innerhalb von zwei Werktagen mit einem Terminvorschlag für das kostenlose Erstgespräch. Drop me a short note on what it's about – I'll get back to you within two business days with a slot for the free first call.

Bitte senden Sie keine vertraulichen Details unverschlüsselt per E-Mail. Auf Wunsch vereinbaren wir einen sicheren Austauschweg. Please don't send confidential details by unencrypted email. On request we can agree on a secure exchange channel.