Starting point
Regulations such as KRITIS, DORA, and NIS2 demand documented, auditable business impact analyses. In practice they are produced in Excel: countless files, no consistency, painful report assembly. The consultancy — a specialist in exactly this process — wanted to offer its clients a self-service product that directly reflects its methodology instead.
Solution
The platform models the BIA methodology directly: processes with an impact matrix across configurable downtime intervals and damage dimensions, automatically derived criticality tiers, recovery objectives (RTO, MTPD), and a dependency graph that surfaces single points of failure. Campaign workflows orchestrate the assessment across departments.
- One assessment satisfies several standards at once
- Compliance checklists for KRITIS, DORA, and NIS2
- Audit-ready PDF reports and Excel exports at the push of a button
- Campaign workflow with roles, deadlines, and approvals
- Complete audit trail and two-factor authentication
- Strict tenant isolation at the service layer
Results
Excel chaos became a single, structured source of truth. What used to cost consulting days of manual document assembly is now a button: standards-aligned reports generated from live data. Alongside its project business, the consultancy now has a scalable SaaS offering — with self-service signup, team management, and multi-tenancy from day one.
- One source of truth instead of scattered Excel files
- Audit-ready reports without manual preparation
- A scalable product business alongside the consulting work
- Solid answers to every security questionnaire from end clients