FallbeispieleCase examples
Drei typische Mandatsverläufe – Gemeinde, KMU und Schule: Ausgangslage, Vorgehen, Ergebnis. Anonymisiert und ohne Marketing-Filter.Three typical mandate walkthroughs – municipality, SME and school: starting point, approach, result. Anonymised and without a marketing filter.
Beispielhafte, anonymisierte Mandatsverläufe – so läuft die Zusammenarbeit typischerweise ab.
Gemeinde, rund 4’500 Einwohner: Vom Fragezeichen zum IKT-Minimalstandard
Ausgangslage: Der Gemeinderat erhält vom Kanton die Empfehlung, die Informationssicherheit am IKT-Minimalstandard auszurichten – intern fehlen Fachwissen und Kapazität, der IT-Dienstleister betreut die Technik, aber niemand die Sicherheit als Ganzes. Vorgehen: Standortbestimmung mit Inventar und Risikobeurteilung in drei Wochen, verständlich aufbereitet für das Gremium; anschliessend beschlussfähiger Massnahmenplan mit Kosten und Prioritäten für den Budgetprozess. Umsetzung der Top-Massnahmen (Backups mit getesteter Wiederherstellung, MFA, Meldewege nach ISG, Notfallkarte) im laufenden Mandat als externe Fachstelle. Ergebnis nach sechs Monaten: dokumentierter Reifegrad-Fortschritt, klare Zuständigkeiten zwischen Verwaltung und IT-Dienstleister, jährliche Berichterstattung an den Gemeinderat – prüfungsfest und budgetiert.
Produktions-KMU, rund 35 Mitarbeitende: Der Kunden-Fragebogen als Weckruf
Ausgangslage: Ein Grosskunde verlangt einen ausgefüllten Sicherheits-Fragebogen als Bedingung für die Vertragsverlängerung; gleichzeitig kündigt der Versicherer eine Prämienerhöhung ohne Nachweise an. Vorgehen: Der Fragebogen wird als kostenlose Standortbestimmung genutzt: Jede Lücke wird zur Massnahme. Security-Check nach ISO 27001 und IKT-Minimalstandard, danach fokussierte Umsetzung – MFA auf allen externen Zugängen, getrennte und getestete Backups, Patch-Prozess, kurze Mitarbeitenden-Schulung, Notfallplan auf einer Seite. Ergebnis: Fragebogen wahrheitsgemäss und bestanden eingereicht, Vertragsverlängerung gesichert, Versicherungsprämie stabil – und ein Sicherheitsdispositiv, das die Firma auch ohne Fragebogen gebraucht hätte.
Schule mit mehreren Standorten: ICT, die im Unterricht funktioniert
Ausgangslage: Gewachsene Geräteflotte ohne zentrales Management, WLAN-Probleme im Unterricht, unklare Zuständigkeiten zwischen Lehrpersonen, Sekretariat und externem Support – und besonders schützenswerte Schülerdaten auf zu vielen Wegen. Vorgehen: ICT-Standortbestimmung mit Massnahmenplan für Schulleitung und Behörde; Einführung eines zentralen Gerätemanagements (MDM), Netzwerksegmentierung (Verwaltung, Unterricht, Gäste) und klarer Zugriffsregeln für Schülerdaten. Grössere Eingriffe konsequent in den Schulferien. Ergebnis: Geräte werden zentral eingerichtet und aktualisiert, das Sekretariat ist vom Unterrichtsnetz getrennt, Support-Wege sind definiert – und die Schule hat eine externe ICT-Fachstelle mit fester Ansprechperson statt Feuerwehrübungen.
So starten Sie
Jedes Mandat beginnt gleich: mit einem kostenlosen Erstgespräch (30 Minuten) zur Standortbestimmung. Termin vereinbaren – oder zuerst in unseren Whitepapern und Checklisten stöbern.
Exemplary, anonymised mandate walkthroughs – how the cooperation typically unfolds.
Municipality, around 4,500 residents: from question mark to the ICT minimum standard
Starting point: the municipal council receives the canton’s recommendation to align information security with the Swiss ICT minimum standard – internally, expertise and capacity are lacking; the IT service provider looks after the technology, but nobody owns security as a whole. Approach: an assessment with inventory and risk evaluation in three weeks, prepared understandably for the governing body; then a decision-ready action plan with costs and priorities for the budget process. Implementation of the top measures (backups with tested recovery, MFA, ISA reporting channels, emergency card) within an ongoing mandate as external specialist unit. Result after six months: documented maturity progress, clear responsibilities between administration and IT provider, annual reporting to the council – audit-ready and budgeted.
Manufacturing SME, around 35 employees: the customer questionnaire as a wake-up call
Starting point: a major customer demands a completed security questionnaire as a condition for contract renewal; at the same time the insurer announces a premium increase unless evidence is provided. Approach: the questionnaire is used as a free assessment: every gap becomes a measure. Security check based on ISO 27001 and the ICT minimum standard, followed by focused implementation – MFA on all external access, separated and tested backups, a patch process, short employee training, a one-page emergency plan. Result: questionnaire submitted truthfully and passed, contract renewal secured, insurance premium stable – and a security posture the company would have needed even without the questionnaire.
School with several locations: ICT that works in the classroom
Starting point: an organically grown device fleet without central management, Wi-Fi problems during lessons, unclear responsibilities between teachers, the school office and external support – and highly sensitive student data travelling too many routes. Approach: an ICT assessment with an action plan for school management and the authority; introduction of central device management (MDM), network segmentation (administration, teaching, guests) and clear access rules for student data. Larger interventions consistently scheduled for school holidays. Result: devices are set up and updated centrally, the school office is separated from the teaching network, support paths are defined – and the school has an external ICT specialist unit with a dedicated contact instead of fire drills.
How to start
Every mandate starts the same way: with a free initial consultation (30 minutes) for an assessment. Book an appointment – or browse our whitepapers and checklists first.