Trust
Before any of us gets access to your systems
- Professional indemnity insurance of 1 million euros, plus office, business and product liability of 5 million euros for personal injury and property damage. Both with a threefold annual aggregate and no deductible. We show the policy in the first call.
- Confidentiality and data processing agreements are signed before anyone gets access
- Your exports leave us again. Whatever we export for the assessment, we delete in full once the work is done. Where you need it, we work inside your environment, over VDI or Citrix. Then no file leaves your house.
- Our specialists are contractually bound and vetted before they work on a mandate. Whoever is in your systems is named in your contract.
You do not get a logo wall
You get a phone call: thirty minutes with one of our clients, in confidence.
We do not name our customers publicly, because a logo on our wall would advertise the security problem behind it. We are our clients’ quiet partner, and later that holds for you too. Names and references are on the table in the first conversation.
controlpunkt GmbH, Basler Straße 3, 61352 Bad Homburg, Germany. Managing director: Tomislav Ljubas. Commercial register: Amtsgericht Bad Homburg v.d.H., HRB 16595.
Honesty
What we do not do is just as visible as what we do
No incident response, no forensics, not even brokered.
In an active incident
If you have an active incident right now, we are not the right people. Call your cyber insurer. They have an incident response provider on file. Come back once the forensic report is in your hands. You can also reach out while the forensics are still running; we then plan what follows. After that the rebuild starts, and a case for it is here.
Second opinion
Trust also means being able to check independently. The sharpest proof of that is the second opinion. We earn nothing on the operation we review.
The founder
The track record
Twelve years in corporate IT at a listed group: started as a data engineer, then IT compliance, then IT architecture, up to leading corporate IT and security. Five of those years, 2018 to 2023, as CISO, alongside the line role.
I built the systems before I governed them. That is the difference from a consultant who only writes controls down.
Where the name comes from
In surveying, a control point is the point whose position is known exactly. Everything else is set out from it. That is the role we take on for our clients: first the surveyed state, then every further decision.
The team
A fixed circle of specialists
Network, cloud, Microsoft Security, identity and GRC are covered by certified specialists, plus partners for offensive security.
We introduce the team by name in the first conversation, with each person's certifications.
Why our prices are public
Every offer on this website carries its price or its range, along with what drives it. That is unusual in consulting, and it is deliberate: you should be able to budget before you talk to us. A price that only appears in a sales conversation is a negotiating instrument. The ranges are frames, not a catalogue: the tailoring happens in the first call, to your company and your needs. After that the price is fixed, before we start. The goal behind this is simple: transparency instead of negotiation, simplicity instead of fine print.
Intro call
We reply within one business day.
What to put in the first email
- Who you are and your company
- What it is about: the trigger, the real problem. A sentence or two is enough.
- If a customer, an investor or a regulator has set a deadline: add the date
- After an incident: where the forensics stand