Aetherize pillar

Security

Detection stops attacks while they run and holds the reporting deadlines when it matters.

Back to the overall concept

01

Overview

What this pillar delivers

01

Overview

What this pillar delivers

The grace period the BSI had granted for registration ran out on 31 July 2026. Fines range up to ten million euros, and executives are personally liable if they fail to approve and oversee the measures. We have deep hands-on experience with NIS2 and DORA, and that experience flows into every process we look after.

The evidence needs to be produced while the software is built, so it is reviewed continuously and stands ready for certification.

We build security into all processes so the evidence emerges in live operation, mapped to ISO 27001, BSI IT-Grundschutz or DORA, ready for any analysis or audit.

What changes for you

The platform reports attacks and stops them while they run

Weeks of audit preparation shrink to pulling a report from the live system

Executives prove their oversight duty with reports from the system

The NIS2 and DORA reporting deadlines are prepared before an incident needs them

Standard duration

2 to 10 weeks

Deployment scenarios

New cluster on premises, no additional applications, harden the operating systems, roll out IDS/IPS and SIEM and switch the rules to enforcing

2 weeks

Cluster is running with some workloads, review and adapt them against the rules, including the conversations with your teams

3 weeks

Build in password and certificate rotation

2 weeks

02

Evidence

How the incident report comes about

One incident from process start to initial notification, with the regulator’s deadline alongside.

02

Evidence

How the incident report comes about

One incident from process start to initial notification, with the regulator’s deadline alongside.

Two seconds, then four hoursExample
  1. 03:14:02process started from a temporary directorybehaviour rule triggers
  2. 03:14:02process terminatedblocked, not merely logged
  3. 03:14:03outbound connectiondropped, destination not approved
  4. 03:14:09event handed to your situation picturecase opened, on-call alerted
  5. 03:41classification by the on-call engineerreportable under DORA Article 19
  6. 06:58initial notification to the regulator3 h 17 after classification

Deadline

3 h 17 of 4 h

Less than two seconds pass between detection and stop. The time after that belongs to the reporting chain. Without a prepared template and a named owner, the search starts here, the four hours run regardless.

Example values from an incident record. The attack did happen, and that is the point: it ends in the second line, and the deadline holds. The result is the incident report with the full deadline chain.

How long would your organisation need today to file the initial notification?

Book an intro call

03

Modules

Three modules

03

Modules

Three modules

M1: Hardening

Recommended start

Configuration is checked against recognized hardening baselines, deviations are documented with reasons

Workloads run without elevated privileges, exceptions are approved individually and expire

Policy as code with reporting, violations land on the dashboard and in the alert path

Every network connection is denied until approved, outbound traffic limited to a target list

Encryption end to end, mutual authentication in the service network where needed

Certificates and keys managed centrally, expiry monitored

Node operating systems reduced to what is needed

M2: Detection and response

Module

IDS: behavioural monitoring at kernel level, reports anomalies while they happen

IPS: the same layer enforces: process starts, file access and network connections are blocked, not merely logged

WAF in front of the ingress layer, protection against common attack patterns, rate limiting against overload

Artifacts are scanned for vulnerabilities before admission, blocked above a defined severity

Continuous configuration checks of the platform and cloud accounts

Complete access log forwarded to your existing SIEM

Detection rules against isolation escape, abuse of technical accounts, privilege escalation

M3: Evidence

Module

Every control mapped to ISO 27001 Annex A, BSI IT-Grundschutz and DORA Articles 5 to 15

Evidence as a versioned report from the live system

A vulnerability process with severity, deadline and escalation

Reporting templates for NIS2 and DORA including the deadline chain

Scope: We deliver technical controls and their evidence. The management system and the certification stay with you and your auditor. You provide: access to existing security tooling and the SIEM. Tool selection happens in the audit, matched to what you already license.

04

Comparison

Which duties this pillar covers

04

Comparison

Which duties this pillar covers

Three of the seven rows in the comparison point here.

Detect and stop attacks

§ 30 BSIG requires risk measures, DORA Article 10 requires detection.

IDS and IPS at kernel level report and block while the attack is running.

Prove effectiveness

The board is liable for the measures actually working.

Every control is mapped to ISO 27001, BSI IT-Grundschutz and DORA, and the report comes versioned out of the running system.

Report within deadlines

NIS2: early warning 24 hours, report 72 hours. DORA: initial report 4 hours after classification.

Report templates and the deadline chain are prepared, alert paths and escalation are wired up.

The full comparison

Next step

30 minutes that belong before your next audit

An intro call with the founders. We listen to where you stand and recommend the best next step.

30 minutes

Free of charge

With the founders

Request an intro call

One email is enough. We reply with a proposed time.

Write an email

Next step

30 minutes that belong before your next audit

An intro call with the founders. We listen to where you stand and recommend the best next step.

30 minutes

Free of charge

With the founders

Request an intro call

One email is enough. We reply with a proposed time.

Write an email