Aetherize pillar
Security
Detection stops attacks while they run and holds the reporting deadlines when it matters.
Back to the overall concept
The grace period the BSI had granted for registration ran out on 31 July 2026. Fines range up to ten million euros, and executives are personally liable if they fail to approve and oversee the measures. We have deep hands-on experience with NIS2 and DORA, and that experience flows into every process we look after.
The evidence needs to be produced while the software is built, so it is reviewed continuously and stands ready for certification.
We build security into all processes so the evidence emerges in live operation, mapped to ISO 27001, BSI IT-Grundschutz or DORA, ready for any analysis or audit.
What changes for you
The platform reports attacks and stops them while they run
Weeks of audit preparation shrink to pulling a report from the live system
Executives prove their oversight duty with reports from the system
The NIS2 and DORA reporting deadlines are prepared before an incident needs them
Standard duration
2 to 10 weeks
Deployment scenarios
New cluster on premises, no additional applications, harden the operating systems, roll out IDS/IPS and SIEM and switch the rules to enforcing
2 weeks
Cluster is running with some workloads, review and adapt them against the rules, including the conversations with your teams
3 weeks
Build in password and certificate rotation
2 weeks
03:14:02process started from a temporary directorybehaviour rule triggers03:14:02process terminatedblocked, not merely logged03:14:03outbound connectiondropped, destination not approved03:14:09event handed to your situation picturecase opened, on-call alerted03:41classification by the on-call engineerreportable under DORA Article 1906:58initial notification to the regulator3 h 17 after classification
Deadline
3 h 17 of 4 h
Less than two seconds pass between detection and stop. The time after that belongs to the reporting chain. Without a prepared template and a named owner, the search starts here, the four hours run regardless.
Example values from an incident record. The attack did happen, and that is the point: it ends in the second line, and the deadline holds. The result is the incident report with the full deadline chain.
How long would your organisation need today to file the initial notification?
Book an intro call
M1: Hardening
Recommended start
Configuration is checked against recognized hardening baselines, deviations are documented with reasons
Workloads run without elevated privileges, exceptions are approved individually and expire
Policy as code with reporting, violations land on the dashboard and in the alert path
Every network connection is denied until approved, outbound traffic limited to a target list
Encryption end to end, mutual authentication in the service network where needed
Certificates and keys managed centrally, expiry monitored
Node operating systems reduced to what is needed
M2: Detection and response
Module
IDS: behavioural monitoring at kernel level, reports anomalies while they happen
IPS: the same layer enforces: process starts, file access and network connections are blocked, not merely logged
WAF in front of the ingress layer, protection against common attack patterns, rate limiting against overload
Artifacts are scanned for vulnerabilities before admission, blocked above a defined severity
Continuous configuration checks of the platform and cloud accounts
Complete access log forwarded to your existing SIEM
Detection rules against isolation escape, abuse of technical accounts, privilege escalation
M3: Evidence
Module
Every control mapped to ISO 27001 Annex A, BSI IT-Grundschutz and DORA Articles 5 to 15
Evidence as a versioned report from the live system
A vulnerability process with severity, deadline and escalation
Reporting templates for NIS2 and DORA including the deadline chain
Scope: We deliver technical controls and their evidence. The management system and the certification stay with you and your auditor. You provide: access to existing security tooling and the SIEM. Tool selection happens in the audit, matched to what you already license.
Detect and stop attacks
§ 30 BSIG requires risk measures, DORA Article 10 requires detection.
IDS and IPS at kernel level report and block while the attack is running.
Prove effectiveness
The board is liable for the measures actually working.
Every control is mapped to ISO 27001, BSI IT-Grundschutz and DORA, and the report comes versioned out of the running system.
Report within deadlines
NIS2: early warning 24 hours, report 72 hours. DORA: initial report 4 hours after classification.
Report templates and the deadline chain are prepared, alert paths and escalation are wired up.
The full comparison