01 — Cyber Security & GRC
Sicherheit, dieSecurity that zum Betrieb passt.fits how you work.
Ich baue Informationssicherheits-Managementsysteme auf, die im Audit bestehen und den Betrieb nicht ausbremsen – nach ISO/IEC 27001 und BSI IT-Grundschutz. Ohne Papiertiger, mit klaren Verantwortlichkeiten und in einer Sprache, die auch die Geschäftsführung versteht. I build information security management systems that pass the audit without slowing down operations – based on ISO/IEC 27001 and BSI IT-Grundschutz. No paper tigers, clear responsibilities, and in a language the board understands, too.
01Wer ich binAbout me
Ich bin ISMS- & GRC-Consultant und Informationssicherheitsbeauftragter aus Köln. I'm an ISMS & GRC consultant and information security officer based in Cologne.
Als ISB eines IT-Dienstleisters für öffentliche Auftraggeber und das Verteidigungsumfeld habe ich ein ISMS von Grund auf aufgebaut – Risikomethodik, Richtlinien, Schulungen, Incident-Prozess und Management-Review. Nach acht Monaten stand das erste ISO-27001-Zertifizierungsaudit: bestanden mit nur zwei geringfügigen Abweichungen. Dazu kamen Betrieb und Absicherung von SINA-Arbeitsplätzen für VS-NfD-Umgebungen. As information security officer at an IT service provider for public-sector and defence clients, I built an ISMS from scratch – risk methodology, policies, training, incident process and management review. Eight months in came the first ISO 27001 certification audit: passed with only two minor nonconformities. I also ran and secured SINA workstations for classified (VS-NfD) environments.
Davor war ich über fünf Jahre Prozess- und Projektmanager im Mittelstand: Ich habe Abläufe in Produktion, Lager und ERP/CRM optimiert, ein Erweiterungsprojekt mit rund 2 Mio. € Volumen samt Team geleitet und DSGVO- sowie GoBD-konforme Strukturen eingeführt. Before that I spent more than five years as a process and project manager at a mid-sized company: I optimised production, warehouse and ERP/CRM workflows, led a production expansion project worth around €2 million including its team, and introduced GDPR- and GoBD-compliant structures.
Neben der Governance trainiere ich die Angreiferseite: Pentesting-Labs auf Hack The Box, Lockpicking und physische Sicherheit, aktuell die eJPT-Zertifizierung. Wer weiß, wie angegriffen wird, schreibt Maßnahmen, die tatsächlich schützen. Beyond governance I train the attacker side: pentesting labs on Hack The Box, lockpicking and physical security, currently working towards the eJPT. Knowing how attacks work leads to controls that actually protect.
- StudiumDegree
- B.A. Integrated Design (Note 1,2), KISD / TH KölnB.A. Integrated Design (grade 1.2), KISD / TH Köln
- UmfeldSectors
- Öffentlicher Sektor, Verteidigung (VS-NfD), MittelstandPublic sector, defence (VS-NfD), SMEs
- ZertifikateCertificates
- ITIL® 4 Foundation · Lean Six Sigma Yellow Belt · Information Security Core Skills (Antisyphon) · Data Literacy
- In ArbeitIn progress
- eJPT (INE), Abschluss geplant Ende 2026eJPT (INE), expected end of 2026
- SprachenLanguages
- Deutsch, Englisch (C1)German, English (C1)
02Warum ichWhy me
Vom Start zum ZertifikatFrom kick-off to certificate
Vom leeren Blatt bis zur bestandenen ISO-27001-Zertifizierung – mit nur zwei geringfügigen Abweichungen.From a blank page to a passed ISO 27001 certification – with only two minor nonconformities.
ProzessdenkenProcess thinking
Als Prozessmanager habe ich Abläufe messbar wirtschaftlicher gemacht. Deshalb weiß ich: Sicherheit muss in bestehende Prozesse passen, nicht daneben stehen.As a process manager I made workflows measurably more profitable. That's why I know: security has to fit existing processes, not sit beside them.
Automatisiert statt abgeheftetAutomated, not filed away
Risikoregister, Meldeportal, Audit- und Review-Workflows in SharePoint, Power Automate und Power Apps – nachvollziehbar und auditfähig.Risk register, incident reporting portal, audit and review workflows in SharePoint, Power Automate and Power Apps – traceable and audit-ready.
SystemdenkenSystems thinking
Mein Designstudium mit Schwerpunkt Kybernetik hilft mir, Organisationen als Ganzes zu sehen – und Richtlinien zu schreiben, die tatsächlich gelesen werden.My design degree with a focus on cybernetics helps me see organisations as a whole – and write policies people actually read.
03Was ich anbieteWhat I offer
-
01
ISMS-Aufbau nach ISO/IEC 27001 & BSI IT-GrundschutzISMS implementation (ISO/IEC 27001 & BSI IT-Grundschutz)
Scope, Strukturanalyse und Schutzbedarf, Richtlinien, Risikobehandlung, Statement of Applicability und interne Audits – mit Begleitung bis zum Zertifikat und durch die Überwachungsaudits.Scope, asset and protection-needs analysis, policies, risk treatment, statement of applicability and internal audits – with support through to certification and the surveillance audits.
-
02
Risikomanagement, BCM & Incident ResponseRisk management, BCM & incident response
Ein Risiko-Framework, das von der Identifikation bis zur Nachverfolgung trägt – plus Incident-, Notfall- und Wiederanlaufprozesse, die im Ernstfall funktionieren und nicht nur auf dem Papier.A risk framework that carries through from identification to follow-up – plus incident, emergency and recovery processes that work when it matters, not just on paper.
-
03
Externer ISBExternal information security officer
Ich übernehme die Rolle des Informationssicherheitsbeauftragten – als Interimslösung, dauerhaft oder zur Verstärkung Ihres Teams. Sie bekommen einen festen Ansprechpartner und regelmäßiges Reporting an die Leitung.I take on the information security officer role – as an interim solution, long-term or to strengthen your team. You get a single point of contact and regular reporting to management.
-
04
NIS2-ReadinessNIS2 readiness
Betroffenheitsprüfung, Gap-Analyse, Registrierungs- und Meldepflichten und ein realistischer Umsetzungsplan. Die Kerndokumentation für die Risikomanagementmaßnahmen nach § 30 BSIG erstelle ich mit einem selbst entwickelten Generator – schnell und passgenau.Applicability check, gap analysis, registration and reporting obligations, and a realistic roadmap. I produce the core documentation for the risk management measures under Section 30 BSIG with a generator I developed myself – fast and tailored.
-
05
GRC-Automatisierung mit Microsoft 365GRC automation with Microsoft 365
Risikoregister, Maßnahmenverfolgung, Vorfallmeldungen und Freigaben mit SharePoint, Power Automate und Power Apps – statt Excel-Listen per Mail.Risk register, action tracking, incident reports and approvals with SharePoint, Power Automate and Power Apps – instead of spreadsheets by email.
-
06
Datenschutz- & Compliance-StrukturenData protection & compliance structures
Verzeichnis von Verarbeitungstätigkeiten, DSGVO-konforme Dokumentation und GoBD-konforme Prozesse.Records of processing activities, GDPR-compliant documentation and GoBD-compliant processes.
04AblaufProcess
-
ErstgesprächFirst call
30 Minuten, kostenlos und unverbindlich. Wir klären Ausgangslage, Ziele und ob die Zusammenarbeit passt.30 minutes, free and without obligation. We clarify the situation, goals and whether we're a good fit.
-
BestandsaufnahmeAssessment
Interviews und Dokumentensichtung. Ergebnis: ein ehrliches Bild vom Status quo.Interviews and document review. The result: an honest picture of where you stand.
-
Angebot & PlanProposal & plan
Klarer Umfang, Meilensteine und transparenter Aufwand – ohne offene Enden.Clear scope, milestones and transparent effort – no loose ends.
-
UmsetzungImplementation
Gemeinsam mit Ihrem Team, in kurzen Iterationen mit regelmäßigen Abstimmungen.Together with your team, in short iterations with regular check-ins.
-
ÜbergabeHandover
Dokumentation, Wissenstransfer und auf Wunsch weitere Begleitung im laufenden Betrieb.Documentation, knowledge transfer and, if you like, continued support in day-to-day operations.
05KontaktContact
Wo steht Ihre Informationssicherheit heute?Where does your information security stand today?
info [at] julianhabermann.deSchreiben Sie mir kurz, worum es geht – ich melde mich innerhalb von zwei Werktagen mit einem Terminvorschlag für das kostenlose Erstgespräch. Drop me a short note on what it's about – I'll get back to you within two business days with a slot for the free first call.
Bitte senden Sie keine vertraulichen Details unverschlüsselt per E-Mail. Auf Wunsch vereinbaren wir einen sicheren Austauschweg. Please don't send confidential details by unencrypted email. On request we can agree on a secure exchange channel.