DIN SPEC 27076 describes a structured CyberRisikoCheck for small and medium-sized enterprises. A qualified adviser conducts an interview-based assessment, evaluates defined requirements and provides a report with prioritized recommendations.
The check creates an accessible entry point and an overview of basic cyber risks. It is not a certification, a complete audit or a technical penetration test. Findings may show where deeper analysis is necessary.
What is the intended result?
Management receives a comprehensible current-state assessment and a practical sequence of improvements. Its value depends on honest information, clear scope and follow-up; the report alone does not reduce risk.
How does the CyberRisikoCheck proceed?
- Preparation: Clarify the organization, contacts, scope and available records.
- Interview: A qualified adviser collects the implementation state against the defined requirements.
- Assessment: Answers and evidence are classified consistently and uncertainties remain visible.
- Report: Document management-level findings, risks and prioritised recommendations.
- Follow-up: Assign owners, dates and any deeper technical assessments.
Which topics are typically considered?
The check is intended for small and micro enterprises and covers organizational and technical foundations: ownership, asset and patch management, backup, identities, malware protection, networks, cloud and suppliers, awareness and incident handling. Its purpose is an accessible entry point, not compressing a complex ISMS into one short interview.
When are further assessments necessary?
An interview does not automatically verify technical effectiveness. Web applications, exposed systems, sensitive data or special regulatory duties may justify configuration reviews, recovery tests, vulnerability scans or penetration tests. The CyberRisikoCheck helps prioritise those next steps.
Thank you for your feedback! We will review it and optimize this content.