MARKETS
Europe
Middle East
North America

Cybersecurity that holds up across borders.

Mentor 2 Secure delivers managed security operations and executive cyber advisory for regulated enterprises, critical infrastructure, and international organizations operating across Europe, the Middle East, and North America.
Built for the standards European regulators demand, the resilience Middle East transformation programs require, and the operational discipline US enterprises expect from cross-border security partners.
24/7 detection, response, evidence-grade
Let’s Secure What Matters
Capabilities, methodology, frameworks, sectors.
Explore the Cybersecurity practice
24/7 detection, response, evidence-grade audit trail.

Managed SOC

24/7 monitoring, detection, and response engineered for regulated environments.

Board-grade guidance on resilience and program design.

Executive Cyber Advisory

Board-grade guidance on resilience, compliance, and program design.

One partner, three regions, one delivery standard.

Cross-Border Operations

One cybersecurity partner across European, Middle Eastern, and US-facing scope.

ABOUT

A cybersecurity firm built for regulated, cross-border reality.

Mentor 2 Secure is a cybersecurity advisory and managed services firm serving enterprises, regulated industries, public-sector bodies, critical infrastructure operators, and international organizations. We combine executive-level guidance with hands-on security operations, so leadership decisions translate directly into measurable resilience.

Our work sits where regulation, technology, and operations meet. We help organizations design cybersecurity programs that satisfy demanding European frameworks, modernize security operations for Middle East transformation agendas, and give US enterprises a reliable execution partner for their international footprint. We do not chase trends. We build the security posture that survives audits, incidents, and scrutiny, the kind that boards, regulators, and operators can stand behind.

Regulated by design

Every engagement is shaped around the regulatory environment our clients actually operate in.

Operational, not theoretical

Advisory turns into runbooks, controls, and a SOC that responds when something is wrong.

Built for cross-border

One partner, consistent standards, three active regions.

Selected technology partners we deploy.

A curated portfolio of best-in-class security products. Each is chosen because it complements our practice, fits regulated environments, and delivers measurable resilience.

THREAT DETECTION & RESPONSE

Vectra

Complete threat detection and response platform with AI-powered, behaviour-based detection uncovering active threats from local network to Office 365.

WHY VECTRA?
  • 100% on-premise operation processes more data than cloud solutions for higher accuracy.
  • Behaviour-based detection independent of threat intelligence updates, catching past and unknown future threats.
  • Drastically reduces SOC team workload without false detections.

Acalvio

Automated deception system maintaining a network of traps, fake devices and services to attract attackers and enable instant response.

WHY ACALVIO?
  • The deception mesh updates automatically, no manual maintenance.
  • No active attention required, no false-positive alerts.
  • Fully automated breach detection that works with all security stacks.

Pcysys

Automated penetration testing platform that finds exploitable vulnerabilities, tests security response and increases real-life cyber resilience.

WHY PCYSYS?
  • Real exploits, real hacking, real attacks without real damage.
  • Run scheduled internal attacks to identify new exploitable vulnerabilities.
  • Focus attention on the most critical, practically exploitable security holes.
INFORMATION MANAGEMENT & SECURE COMMUNICATION

MailStore

Reliable email archival tool that organises all email communications into a searchable, locally available enterprise datastore. Supports many migration scenarios.

WHY MAILSTORE?
  • Store all emails and offload servers in a quickly searchable local database.
  • Independence from any cloud, all essential business emails kept in-house.
  • Supports retention policies with automatic deletion of personal data.

BabelApp

Feature-rich encrypted communication tool with on-premise or privately hosted servers. Robust end-to-end encryption makes eavesdropping impossible.

WHY BABELAPP?
  • High security without reliance on external servers, unlike WhatsApp, Signal, Teams or Viber.
  • Desktop client for Windows and Mac.
  • Blockchain-protected user identities defeat the most advanced man-in-the-middle attacks.

BigID

Data intelligence platform that applies machine learning across enterprise data to identify correlations, visualise data movement and fulfil security and compliance use cases.

WHY BIGID?
  • New AI-based approach to security and actionable intelligence.
  • Collects and analyses all enterprise data sources at petabyte scale.
  • Hidden data relationships unlock new business and security use-cases.
INDUSTRIAL & OT SECURITY

Stormshield

Europe's leading firewall vendor, part of the Airbus Group. Develops robust industrial firewalls to enforce security policies within OT networks.

WHY STORMSHIELD?
  • Most trusted European network security vendor with EU and NATO certifications.
  • Understands and protects a wide range of industrial protocols.
  • Brings the full UTM firewall feature set deep into the critical network.

Bayshore

Easy-to-deploy, automated industrial security with a real OT mindset. Practical, cost-efficient solutions to secure critical networks on any budget.

WHY BAYSHORE?
  • Simple, efficient cabinet protection that deploys quickly.
  • Airgap gateways reduce the attack surface while keeping regular business usage.
  • Automated industrial firewalls under €1,000 make OT security possible at every company size.

Vectra & Acalvio for OT

Vectra's network threat detection and Acalvio's deception mesh passively secure any industrial or critical system, without network changes.

WHY THIS COMBINATION?
  • Vectra delivers instant threat visibility and response in critical networks.
  • Acalvio adds a passive last line of defence by replicating OT devices to mislead adversaries.
  • Both deploy without disrupting industrial operations or requiring agents.
IDENTITY, ACCESS & ACTIVITY MANAGEMENT

Xton

Easy and cost-efficient Privileged Access Management that simply works. Provides a secrets and password vault and a web-based portal for recorded access.

WHY XTON?
  • Simple and fast deployment, easy licensing, affordable pricing.
  • From employee password management to approval workflows for supplier remote access.
  • Weekly feature updates help meet all customer needs.

Teramind

Full-featured user activity management with data loss prevention to secure the home office. Easily extends to all workstations and laptops.

WHY TERAMIND?
  • Almost unlimited device control in a single, intuitive interface.
  • Instant incident resolution with enterprise-wide screen search and forensic capabilities.
  • Risk scoring and work performance dashboards.

Varonis

Complete user behaviour analysis platform with data discovery and permission management. Works server-side and in the cloud, without endpoint agents.

WHY VARONIS?
  • Supports almost all unstructured, employee-generated data, from file shares to Office 365.
  • Detailed Active Directory audits resolve toxic permission conditions.
  • Automation tools, self-service portals, supports many security use-cases for catching external attackers.
Cyber Security Practice

Cyber Security Practice

A combined advisory and operations practice for regulated enterprises and critical infrastructure operators. We design the program, build the controls, and run the SOC.

24/7

Managed SOC coverage across regions and time zones

3

Active regions, one delivery standard

2

Business days to a structured engagement outline

90d

Structured uplift milestones during onboarding

CAPABILITIES

Two reinforcing capabilities. One accountable partner.

A Managed SOC for continuous detection and response, and a Cybersecurity advisory and engineering practice for program design, resilience, and regulated-sector compliance.

Managed SOC Services

24/7 detection, response, and security monitoring for regulated environments and critical infrastructure. Telemetry across users, endpoints, identities, cloud workloads, and OT systems, with the evidence trail audits demand.

  • Threat detection and response
  • Critical infrastructure and OT visibility
  • Incident response readiness and on-call escalation
  • Use-case engineering for regulated sectors
  • SOC maturity assessments and uplift

Cybersecurity Advisory and Operations

Executive-level guidance paired with engineering depth, with deep specialization in critical infrastructure protection. We design and operate cybersecurity programs from board-level strategy to control implementation.

  • Cybersecurity program design and governance
  • Critical infrastructure and OT protection
  • Compliance-aligned cybersecurity (NIS2, DORA, GDPR, sector regulations)
  • Vulnerability and risk management
  • Executive cyber advisory and board reporting
Sectors

Critical infrastructure at the centre.

Critical infrastructure is the operating context that shapes how we engineer, operate, and report. The sectors we serve share a common reality: the cost of a cyber incident is measured in service continuity, public trust, and regulatory exposure.

Energy and utilities

OT-aware monitoring, segmentation, vendor-risk discipline, and incident response readiness for generation, transmission, and distribution.

Transport and aviation

Operational resilience, incident reporting, third-party assurance, and SOC use cases tuned to safety-critical systems.

Financial services

DORA-aligned ICT risk, resilience testing, and oversight of critical third-party providers.

Healthcare

Identity-first defence, medical-device exposure management, and breach response readiness under sector regulation.

Public sector and government-adjacent

NIS2 alignment, supply-chain assurance, and SOC build-out for entities with national-scale scrutiny.

Smart-city and industrial ecosystems

Cross-domain visibility, OT and IoT segmentation, and continuous monitoring for high-growth digital ecosystems.

Methodology

From assessment to operation, in four phases.

Every engagement follows the same disciplined arc. Phases compress or extend with scope, but the structure does not change.

01

Assess

Map current state, regulation, controls, and OT exposure. Output: prioritized improvement plan.

02

Design

Translate priorities into target architecture, governance, and SOC use cases tied to regulation and risk.

03

Build

Implement controls, instrument telemetry across IT and OT, codify runbooks. Engineering and advisory move in parallel.

04

Operate

24/7 detection and response, executive reporting, continuous tuning. The team that designed it runs it.

Frameworks and focus areas

We translate regulation into operating reality.

We work in the regulations that actually shape our clients' risk posture and reporting obligations, and we map every control we recommend to the relevant clause.

PRACTICE STATEMENT

Counsel. Operate. Protect.

Trusted advisory. Operational delivery. Critical infrastructure, end to end.

Use Cases

Engagement scenarios.

Each scenario can be scoped as advisory, managed delivery, or a combined program.

A US enterprise operating securely across Europe and the Middle East

A US-headquartered organization expands into European and Middle Eastern markets and needs cybersecurity execution that aligns with EU regulatory expectations, regional incident response capability, and a SOC that operates in their hours and their counterparts'. Mentor 2 Secure stands up the regional security operating model and runs it.

Engage on this scenario

A European regulated enterprise meeting NIS2 and DORA

A financial services or critical infrastructure operator must close the gap between its current security program and NIS2 / DORA expectations. We translate the regulation into controls, instrumentation, and SOC use cases, and stay on to operate them.

Engage on this scenario

A Middle East organization modernizing cybersecurity operations

A government-adjacent or large enterprise client in the Gulf is scaling rapidly and needs to move from fragmented tooling to a coherent SOC, mature incident response, and a cybersecurity program ready for national-scale scrutiny. Mentor 2 Secure delivers the design and the operational uplift.

Engage on this scenario

Critical infrastructure and OT protection

Energy, utilities, transport, aviation, and industrial operators need security that respects operational technology constraints and reflects sector regulation. We build the architecture and the monitoring around the realities of OT.

Engage on this scenario

Executive cyber advisory for boards and CEOs

Leadership-level support for boards, audit committees, and CEOs facing cyber-resilience questions, regulatory engagement, or post-incident scrutiny.

Engage on this scenario

Third-party and supply-chain cyber resilience

For organizations whose risk surface extends through dozens or hundreds of vendors, we design and operate the assurance program, the contractual baseline, and the monitoring required to keep it credible.

Engage on this scenario
For your sector

Pick the page that names your situation.

Six landing pages, each written so the trigger you are facing is the first sentence. Tier-2 supplier, regional bank, regional clinic, smart-city operator — the page is for you.

MANUFACTURING

Tier-2 / Tier-3 automotive & machinery

NIS2, TISAX, OEM cybersecurity questionnaires.

→ Book a sector call
ENERGY & UTILITIES

Regional energy, water, grid operators

In the new NIS2 essential-entity perimeter.

→ Book a sector call
FINANCIAL SERVICES

Regional banks, insurers, asset managers

DORA translated into 14 controls and 6 SOC use cases.

→ Book a sector call
HEALTHCARE

Hospital networks & clinic groups

§ 75c SGB V and NIS2 — at the same time.

→ Book a sector call
TRANSPORT & LOGISTICS

Mid-market logistics, ports, aviation suppliers

NIS2 essential-entity scope. Operational resilience first.

→ Book a sector call
NIS2 READY

Six weeks. Fixed €19,000.

The productized engagement that fits any sector above.

→ Read NIS2 Ready
Products

Productized cybersecurity for the regulated mid-market.

Four fixed-scope, fixed-price SKUs designed so a CFO can sign without booking three more calls. Each SKU plays a distinct role in the lifecycle of a regulated mid-market organisation — one-shot compliance, ongoing executive ownership, ongoing monitoring, and ongoing incident-response capability.

01

NIS2 Ready

€19,000
fixed · 6 weeks

One-shot compliance setup. From panic letter to audit-ready evidence in six weeks.

  • Gap assessment against NIS2 Article 21
  • Asset and supplier register
  • 12-month improvement plan
  • Incident-response runbook
  • Board summary deck
  • Two follow-up review calls
Best for: First-time NIS2 entities, 50–500 employees.
Scope NIS2 Ready
02

vCISO Light

from €2,200
/ month · 12-month commitment

Ongoing executive ownership. A named senior advisor your board and regulator can point to.

  • Named senior advisor
  • Quarterly board report
  • Two policy reviews per year
  • Questionnaire support
  • Strategic cyber guidance
Best for: Mid-market without an in-house CISO.
Scope vCISO Light
03

Watch

from €1,500
/ month per protected unit

Ongoing monitoring and detection with audit-grade evidence and triage.

  • 24/7 monitoring
  • Quarterly tuning
  • Incident triage callback
  • Audit-grade evidence trail
  • EU data residency
Best for: Mid-market wanting monitoring without hiring analysts.
Scope Watch
04

Incident Ready

€4,500
/ year + €450 / hour on incident

Ongoing incident-response capability with regulator-notification support.

  • IR playbook tailored to your environment
  • Annual tabletop exercise
  • 2-hour callback commitment
  • Quarterly playbook tuning
  • Forensic-evidence preservation procedure
Best for: Mid-market that needs the IR leg of NIS2 covered.
Scope Incident Ready
THE PACK

Mid-Market Cybersecurity Pack

All four productized SKUs in one programme. Year 1 €58,000 (saves €9,900). Year 2 onwards €42,000. Most regulated mid-market organisations end up here — at under €60k Year 1 and under €45k recurring, this is what mid-market cybersecurity should actually cost in DACH.

Need a custom scope beyond these four SKUs? Custom Advisory engagements begin at €25,000. Managed SOC for full enterprise scope from €5,000 / month. Integrated Programs by quotation. See engagement modes →
Where we fit

Between Big-4 prices and the local IT shop, a third option.

Mid-market buyers compare against two real alternatives. Same trigger, three different responses. Pick the row that fits your situation.

LOCAL IT SHOP

€5-25k

Cheap, accessible. Often fails an audit.

  • Adds a firewall rule
  • No regulatory understanding
  • Disappears at the first incident
BIG 4 / INTEGRATOR

€50k–€500k+

Credible but expensive. Senior pitches, junior delivers.

  • 6-week scoping cycle
  • Junior delivery teams
  • Multi-quarter procurement
Mentor 2 Secure is the option mid-market buyers reach when they have outgrown the IT shop and are not ready to pay Big-4 rates.
Case Studies

Outcomes regulators and auditors signed off.

Three engagements, anonymised for client confidentiality. All DACH. All regulated mid-market. References available on request.

CRITICAL INFRASTRUCTURE · ENERGY GRID

Regional energy distribution operator

380 employees · Bavaria · KRITIS + NIS2 essential entity
TRIGGER

A BSI registration letter under NIS2 landed two days before the KRITIS reporting cycle began. The IT manager had no SOC, no incident-response runbook, and no documented OT segmentation. The board needed an answer to the regulator within 30 days.

APPROACH
  • 8-week NIS2 Article 21 gap assessment, mapped to BSI IT-Grundschutz baseline
  • Passive OT visibility across substation control networks — no agents, no downtime
  • 24/7 Managed SOC stood up across IT and OT in 12 weeks; EU-only named analysts
  • Annual tabletop exercise with the regulator-facing crisis team
0 findings on first BSI NIS2 review
9d → 11h OT incident MTTR
-18% cyber-insurance premium at renewal
14 / 14 supplier questionnaires from one evidence base
“Mentor 2 Secure took us from a BSI registration letter to a passed review in fourteen weeks. They stayed on as our SOC. Best money we have spent this decade.”

— IT Director, regional energy distribution operator, Bavaria
MANUFACTURING · AUTOMOTIVE SUPPLY

Tier-2 automotive component supplier

220 employees · Baden-Württemberg · TISAX + NIS2
TRIGGER

A German OEM customer issued an updated cybersecurity questionnaire that the supplier could not answer. A failed answer meant losing the next contract. TISAX Level 2 was due in five months. NIS2 added a third deadline on top.

APPROACH
  • 6-week NIS2 Ready: Article 21 gap, 12-month plan, IR runbook, board deck
  • TISAX Level 2 readiness layered on the same controls — single evidence base
  • Watch SOC across email, identity, endpoint with EU-only data residency
  • Reusable supplier-questionnaire library; 23 customer questionnaires in three months
TISAX L2 attained on first attempt
14d → 24h questionnaire response time
2 new Tier-1 contracts won, citing security posture
0 remediation items in OEM Tier-1 audit
“We were losing deals because we couldn’t answer security questionnaires fast enough. Mentor 2 Secure built us a reusable evidence base. We won the next two contracts.”

— Managing Director, Tier-2 automotive supplier, Baden-Württemberg
HEALTHCARE · HOSPITAL NETWORK

Regional hospital and clinic network

1,400 employees · 6 sites · Bavaria · § 75c SGB V + NIS2
TRIGGER

An attempted ransomware incident hit two months earlier — caught at the perimeter, but it surfaced gaps. The board demanded a named cybersecurity owner. § 75c SGB V audit was 12 months away. NIS2 essential-entity classification was confirmed.

APPROACH
  • Post-incident review of the attempted ransomware: full forensic timeline + board paper
  • vCISO Light retainer with named senior advisor; quarterly board reporting from week 1
  • Watch SOC tuned for medical-device telemetry, HIS identity, AD changes
  • Incident Ready retainer; annual tabletop with crisis team and DPO
§ 75c SGB V passed with one minor finding (resolved 30d)
7 min MTTD for identity-based attacks (was: unknown)
3 identity attacks caught before lateral spread
0 successful ransomware events in 14 months
“After our near-miss, the board demanded a named cybersecurity owner. We hired Mentor 2 Secure as our vCISO. Twelve months later we passed § 75c with one minor finding and the SOC has caught three identity attacks before they spread.”

— CEO, regional hospital network, Bavaria
Engage

Let’s Secure What Matters

Three precise ways to engage Mentor 2 Secure. Each is scoped to outcomes, integrates with the way your organization already operates, and is delivered end to end by the same accountable team.

4 to 12 weeks, optional retained advisory.
01 ADVISORY

Advisory Engagement

Executive cyber advisory and program design. Targeted, time-boxed, and delivered to a senior accountable partner.

  • Cybersecurity program design and governance
  • Regulatory gap assessment (NIS2, DORA, GDPR, sector regulation)
  • Board reporting and audit-committee support
  • Post-incident review and remediation oversight
  • Optional retained advisory after delivery
Onboarding follows a 90-day maturity uplift.
02 OPERATIONS

Managed SOC Engagement

24/7 detection, monitoring, and response, engineered for regulated environments and critical infrastructure.

  • 24/7 SOC across users, endpoints, identities, cloud, and OT
  • Use-case engineering tied to your regulation and risk
  • Incident response readiness and on-call escalation
  • Audit-grade evidence trail and executive reporting
  • 90-day structured maturity uplift during onboarding
One accountable partner across advisory and operations.
03 INTEGRATED

Integrated Programs

Strategic advisory and operational delivery under a single accountable partner. Designed for multi-region scope and high-stakes transformation.

  • Single delivery standard across Europe, Middle East, and North America
  • Program design and SOC operations under one team
  • Multi-region rollout, post-incident rebuild, and M&A integration
  • Continuous executive reporting and governance
  • The team that designs the program runs it
How to start. Share scope, region, and regulatory context. We respond within two business days with a structured engagement outline.
Where we operate

Three active regions. One delivery standard.

Evidence, auditability, continuity at regulatory scrutiny.

Europe

Mentor 2 Secure supports regulated industries, public-sector bodies, and critical infrastructure operators across Europe. Engagements typically address NIS2 and DORA implementation, GDPR-aligned security, supply-chain cyber resilience, and the operational uplift required to keep pace with European regulatory scrutiny. We deliver in environments where evidence, auditability, and continuity carry as much weight as detection.

Scaled to national-priority cybersecurity programs.

Middle East

We support cyber modernization across the Middle East, with a focus on national transformation programs, critical infrastructure, energy, aviation, financial services, and large-scale digital ecosystems including smart-city and government-adjacent initiatives. Engagements address SOC build-out, incident response readiness, regulated-sector compliance, and the executive guidance required when cybersecurity becomes a national priority.

Trusted regional execution for international footprints.

North America

We support US- and Canada-headquartered enterprises and regulated organizations operating internationally. Typical engagements address cyber resilience for cross-border operations, SOC maturity, third-party and supply-chain risk, alignment with European, US (NIST CSF, SEC), and Canadian regulatory expectations (OSFI, PIPEDA, provincial privacy law), and trusted regional execution across European and Middle Eastern footprints.

Contact

Speak with Mentor 2 Secure.

For engagement enquiries, regulatory questions, or confidential incident-related discussions.

Pick a time that works for you.

Book a 30-minute confidential call with a senior advisor. No form required.

or send a written enquiry
  • Protected against spam — Cloudflare Turnstile, honeypot, and submission timing.
DIRECT LINE +49 163 1705292
URGENT RESPONSE

Available 24/7. Our team of experts can stand up a secure virtual war room within hours, with senior advisors, SOC analysts, and incident-response engineers on the line.

CONFIDENTIAL / ENCRYPTED CHANNEL

Available on request — PGP, Signal, or Threema.

RESPONSE COMMITMENT

Reviewed by a senior advisor. Reply within two business days.

LANGUAGES

Engagements conducted in English and German.

HEADQUARTERS

Nsquare GmbH · Zeppelinstraße 33, 85748 Garching b. München

SECOND LOCATION

Frankfurt am Main, Germany

OPENING Q3 2026
Trust & Credentials

The credibility chain behind every engagement.

Mentor 2 Secure delivers cybersecurity that holds up to a regulator, an auditor, and a board. The credentials below — held by the team, by our specialist partners, and by the technology stack we deploy — are the verifiable foundation of that delivery.

SENIOR ADVISOR CREDENTIALS

Held personally by Mentor 2 Secure senior advisors. Verifiable on AXELOS, PeopleCert, and individual LinkedIn profiles.

PRINCE2®

Foundation

PRINCE2®

Practitioner

PRINCE2 Agile®

Practitioner

ITIL® 4

Foundation

ITIL® 4

Managing Professional

ITIL® 4

Strategic Leader

ITIL® 4

Specialist · Create, Deliver and Support

ITIL® 4

Specialist · Drive Stakeholder Value

ITIL® 4

Specialist · High Velocity IT

ITIL® 4

Strategist · Direct, Plan and Improve

ITIL® 4

Leader · Digital and IT Strategy

SPECIALIST PARTNERS

Where Mentor 2 Secure delivers in partnership with a specialist firm, the partner's credentials are part of the engagement.

Each partner credential below is held by the partner organisation and surfaced here for verification.

CIVERA

Partner showcase

CIVERA

NIS2 Cyber Governance & vCISO Intelligence Platform

Operational governance platform whose credentials underpin our NIS2 engagement deliveries. We operate the CIVERA platform on behalf of the client; the platform's audit-grade evidence engine is what the regulator accepts.

  • NIS2 governance methodology
  • vCISO workflow framework
  • Operational cyber-resilience evidence engine
  • EU data residency by design
CERTIFICATIONS (AS PUBLISHED ON CIVERA.EU)
ISO/IEC 27001
SOC 2 Type II
GDPR · DSGVO
BSI C5
CSA STAR
EU data residency

Logstail

Logstail

Cloud-native SIEM & log management platform

Where Mentor 2 Secure delivers Watch (Managed SOC starter), Logstail provides the underlying log-aggregation and security-analytics engine. Cloud-native, EU-hostable, with compliance-grade retention and real-time threat detection — built so a mid-market organisation gets SOC-grade telemetry without enterprise-grade integration cost.

  • Real-time SIEM with built-in correlation rules
  • Centralised log aggregation across cloud, on-prem, OT
  • Compliance-ready retention (NIS2, DORA, GDPR audit trails)
  • Threat-intelligence feeds and MITRE ATT&CK mapping
CERTIFICATIONS (AS PUBLISHED ON LOGSTAIL.COM)
ISO/IEC 27001
SOC 2 Type II
GDPR · DSGVO
EU data residency
PCI-DSS-ready
HIPAA-ready
THREATDEFX

Partner showcase

ThreatDefX

Boutique offensive security partner

Where an engagement requires red-team, ransomware-resilience, or purple-team work, ThreatDefX delivers under joint scope. Their credentialled practitioners are the offensive layer of every Integrated Programme.

  • OSCP / OSCE / OSEP credentialled team
  • Ransomware resilience exercises
  • Penetration testing & phishing simulations
  • Purple-teaming with Mentor 2 Secure SOC
CERTIFICATIONS (AS PUBLISHED ON THREATDEFX.COM)
OSCP
OSCE
OSEP
CREST
CEH
CISSP
ISO/IEC 27001

MEMBERSHIPS & AFFILIATIONS

APPLIED BSI Allianz für Cyber-Sicherheit
APPLIED ENISA Stakeholder Community
APPLIED BVMW · Mittelstand Association
APPLIED TeleTrust Bundesverband IT-Sicherheit
IN PROGRESS ISO/IEC 27001 — Nsquare GmbH
Trust Architecture

The documents we publish before you sign anything.

A cybersecurity firm without a published privacy policy, AGB, DPA, sub-processor list, and SOC data-handling statement is an immediate disqualification for serious buyers. The eight documents below are how Mentor 2 Secure passes that test before the first call.

01

Privacy Policy

GDPR Art. 13/14 disclosure: controller, purposes, legal bases, retention, recipients, rights.

02

Cookie Policy

TTDG-compliant disclosure with granular opt-in. Banner active on every page.

03

Terms of Engagement (AGB)

German B2B terms: liability, confidentiality, IP, termination, governing law (German), jurisdiction (Munich).

04

DPA Template

GDPR Art. 28 processor agreement template, SCC-aligned. Available as signed PDF on request.

05

Sub-Processor List

Live, public, dated. Cloud providers, email, SOC tooling, billing — all listed with purpose and region.

07

Information Security Policy Summary

Public extract of internal ISMS: encryption at rest and in transit, access controls, incident response, vendor management.

08

Acceptable Use Policy

For Watch and Managed SOC clients: what the service can and cannot do, scope discipline, evidence requests.

06 · OUTLINE

SOC Data-Handling Statement — outline

Most cybersecurity vendors do not publish anything close to this. The outline below is on the public site; the full statement is provided on request to info@mentor2secure.com . Here is what it commits to:

WHAT WE COLLECT

Authentication events, network metadata, EDR telemetry, email metadata, OT telemetry where applicable. We do not collect file contents, message bodies, or screen recordings.

WHERE WE STORE

EU-region hosting only. AES-256 encryption at rest, TLS 1.3 in transit, dual-control key management.

HOW LONG WE RETAIN

Default 12 months. Configurable per client up to 7 years for regulated retention.

WHO CAN ACCESS

Named SOC manager, role-based access for analyst pool, dual-control for retrieval, full audit trail. Personnel vetted to BSI Grundschutz baseline.

WHERE THE ANALYSTS SIT

Munich and (from Q3 2026) Frankfurt. EU citizens or EU residents only. Background checks aligned to BSI personnel-security baseline.

WHAT HAPPENS ON INCIDENT

2-hour callback. NIS2 24h/72h/1-month notification support. Forensic-evidence preservation procedure agreed in writing per client.

HOW CLIENTS VERIFY

Read-only client portal access to your own SOC events. Optional quarterly third-party-attested report.