A-R-CAndreas Rühl Consulting
DEEN
Security Governance · ISMS · Audit Readiness · Resilience

Make information security manageable, auditable and ready for management decisions.

A.R.C. connects technical reality, organizational accountability and regulatory requirements into reliable governance, operating models and decision structures.

Focusmanageable security governance instead of document collections
Rolesenior advisory, cross-functional leadership and CISO support
Contextregulated, critical and audit-driven organizations
Modelremote, direct, partner-ready or white-label
When support becomes valuable

Not more activity — but reliable control.

Support is most valuable where technical measures, regulatory requirements and management accountability do not reliably connect.

1

Regulatory requirements need an operating model

NIS2, KRITIS, ISO 27001, BSI and TISAX must not remain disconnected checklists.

  • Clarify scope and roles
  • Translate requirements into action
  • Connect evidence and decisions
2

Security functions need an operating model

SOC, SIEM, monitoring, architecture and GRC only work with ownership, processes and feedback.

  • Design the target operating model
  • Structure technology selection
  • Connect operations and governance
3

An incident or audit creates immediate pressure

Under pressure, organizations need clear decisions, coordinated workstreams and a controlled transition into remediation.

  • Structure the immediate response
  • Prioritize findings
  • Restore audit and decision readiness
Delivery model

From mandate to traceable change.

The approach connects clear accountability, technical reality and risk-based evidence — from the initial situation assessment to a sound management decision.

PDCA without ritual: one clear hypothesis, one coherent delivery increment, proportionate evidence and deliberate feedback.

Clarify the mandate and system boundaries

What decision or change is required? Who is accountable? Which technical, organizational and regulatory boundaries matter?

Assess reality and requirements together

Technology, processes, organization, risks, contracts, standards and available evidence are assessed as one system.

Design the control and target operating model

Roles, decision paths, controls, data objects, technical measures and evidence are connected into an operating model.

Lead implementation across workstreams

Findings become prioritized work packages with accountable owners, dependencies, decisions and expected evidence.

Feed effectiveness and residual risk back into decisions

Progress is measured through traceable change, audit readiness and management decisions — not document volume.

Capability areas

Five capability areas, one control system.

One capability area may lead an engagement, while the interfaces remain part of the solution.

01

Security Governance

Mandate, roles, decision paths, CISO office, management reporting and action tracking.

02

ISMS & GRC

Scope, structure, protection needs, risks, framework mapping, policies and evidence models.

03

Audit Readiness

Gap analysis, requirements closure, statement of applicability, evidence quality and audit support.

04

Security Architecture

SOC/SIEM, monitoring selection, segmentation, WAF and technical governance.

05

Incident & Resilience

Immediate response, remediation, business continuity, emergency management and disaster recovery governance.

Selected experience

Experience in demanding security environments.

These examples show how A.R.C. structures information security across different situations — from ISMS and GRC transformations to audit readiness, security architecture and critical incident response.

KRITIS / NIS2 / GRC

Enterprise-wide security and GRC transformation

ISMS enhancement, cross-framework mapping, structure and protection-needs model, policies, risk and evidence integration, and implementation planning.

Outcome: The engagement supported the enterprise-wide transformation and was recommended for comparable projects.

Incident Leadership

Cyberattack at a regulated insurer

Coordination of the immediate response and subsequent incident handling, technical workstreams, and support for regulatory communications.

Focus: Restore decision-making capacity, coordinate technical and regulatory work, and prepare decisions.

SOC / Operating Model

SOC as a security function rather than a tool project

End-to-end SOC design including project management, process and organizational design, and coordination of technical specialties.

Contribution: Design and cross-functional leadership across organization, processes and technical specialties.

Technical audit

WAF audit against BSI IT-Grundschutz

Review of documented requirements and processes for governance, access controls, cryptography, administration, logging, SIEM integration, patch management, network architecture and planned effectiveness testing.

Outcome: Audit report with prioritized technical and organizational findings.

TISAX / Audit Readiness

Closing requirements at two industrial companies

Gap analysis, prioritized requirements closure, quality assurance for policies, statement of applicability and evidence, and audit preparation.

Outcome: Both companies passed their audits.

CISO / ISMS

Multi-year support in a regulated environment

Support for a CISO function during ISMS development, including security design, risk and threat analysis, awareness and technical deep dives.

Engagement: Multi-year, recurring support for the CISO function in building and developing the ISMS.

Working principle

Information security becomes effective when decisions connect across the organization.

Complex security programs stall when mandates, priorities, technical work and management decisions do not connect. The engagement focuses on these interfaces.

Orientation for management and delivery teams

  • Make decision needs and dependencies visible
  • Structure risks and requirements clearly
  • Translate priorities into actionable next steps
  • Structure accountability and evidence so they remain usable across teams and decisions

What you can expect from the engagement

  • a clear view of feasible options and open issues
  • cross-disciplinary technical leadership
  • decision-ready working outputs instead of presentation-only work
  • discretion in sensitive situations
Engagement approach

Security leadership that connects management and delivery.

I structure complex security situations, translate between management and technical teams, and bring specialized contributions together into a reliable overall picture.

This creates a clear basis for decisions, traceable accountability and a reliable path from analysis into delivery.

DirectDecision needs and next steps are stated clearly.
SystemicTechnology, organization, risk and regulation are considered together.
AuditableActions, decisions and outcomes are documented in a traceable way.
Implementation-focusedAnalysis is translated into work packages, accountable owners and evidence.
Next step

Clarify the project situation and define the next practical step.

In an initial conversation, we structure the current situation, immediate pressure and target state. This identifies the right starting point: analysis, management decision, implementation leadership or audit readiness.