Our security concept

Security on every level

Security on every level:
physical, digital and organisational

ISO 27001 based on BSI IT-GrundschutzData centres in Germany24/7/365 operation and support

ISO 27001:BSI (IT-Grundschutz)

Our ISO 27001 certification on the basis of IT-Grundschutz from the Federal Office for Information Security rests on a large number of clear rules and processes that we actually live by.

More

PCI certification

The PCI standard is a set of rules that defines the security requirements for credit card payments.

More

5-zone security concept

Within our ISMS we address a wide range of topics to ensure permanently secure operation.

More

Business and Service Continuity

Within the ISMS, extensive emergency plans, strategies and escalation paths have been defined.

More

Independently audited: our certificates

Our information security management system is certified to ISO 27001 on the basis of BSI IT-Grundschutz. For our colocation services, physical security is additionally certified to PCI DSS v4.0.

  • Siegel: ISO 27001 auf Basis von BSI IT-Grundschutz

    ISO 27001 on the basis of BSI IT-Grundschutz

    Scope
    Data centres and cloud services
    Certificate no.
    BSI-IGZ-0552-2023
    More on the ISMS
  • Siegel: PCI DSS

    PCI DSS v4.0

    Scope
    Physical Security / Colocation Services
    More on PCI DSS

Certified security: an ISMS we live by

Our ISO 27001 certification on the basis of IT-Grundschutz from the Federal Office for Information Security rests on a large number of clear rules and processes that we actually live by.

The BSI ISO 27001 certification covers the data centre network in Hanover and its management. It includes all systems and processes required to run the data centre infrastructure, manage customers and deliver colocation services.

Applying ISO 27001 on the basis of IT-Grundschutz from the Federal Office for Information Security (BSI) covers the control objectives and controls from Annex A of ISO 27001 and the associated implementation advice and guidance on generally accepted practices from ISO/IEC 27002.

As a prerequisite for certification, kyberio went through a multi-stage audit covering the data centre and the organisational processes that go with it. This audit is repeated in a regular cycle.

In essence, the audit covers:

  • The business requirements of the company
  • Technical infrastructure
  • Management responsibility
  • Organisational processes
  • Risk management
  • Data protection

With kyberio, our customers also secure their own position with regard to IT security legislation. Since May 2018, the EU General Data Protection Regulation has further tightened data protection requirements and the associated liability risks. It provides for even harsher penalties for breaches of data protection law than the former German Federal Data Protection Act.

In fact, certification is not only a legal safeguard: together with improved security it also brings many business advantages. In summary:

  • Improved security of the IT infrastructure
  • Greater security awareness, from management to staff
  • Legal protection and reduced liability risk
  • Improved competitiveness
  • Cost savings by outsourcing security-relevant services that would take considerable effort to provide in-house
  • Building trust with customers and the public
  • The option of certifying your own applications on the basis of kyberio''s existing certification

PCI DSS v4.0 – the fitting complement

PCI DSS stands for “Payment Card Industry Data Security Standard”. The PCI standard is a set of rules that defines the security requirements for credit card payments. It is binding for all companies, institutions and organisations that process cardholder data.

Companies and organisations that process cardholder data (CHD) electronically in a cardholder data environment (CDE) must secure this environment against data misuse and unauthorised access in line with the PCI guidelines and protect its ongoing operation. The standard also requires a clear assignment of responsibilities for the different areas and tasks within the CDE. All access and every work step must be traceable. An important part of running such an environment is physical security and the processes needed to ensure it in data centre operation.

These requirements cover 12 areas:

  • Firewall concept
  • Security settings for passwords
  • Protection of cardholder data
  • Encryption of data
  • Virus protection
  • Maintenance of systems and applications
  • Restriction of access
  • User-based access control
  • Restriction and security of physical access to the server
  • Logging of access to data
  • Regular review of the systems
  • Compliance with information security policies

Traceability of entry to and access to the environment is ensured by professional entry controls and procedures, continuous video surveillance around the clock, the logging and unambiguous identification of everyone in the data centre, and data reconciliation with plausibility checks.

As a colocation customer in our data centre, you benefit from a service already PCI-certified by a qualified security assessor (“QSA”), which extends up to your own rack. This lets you concentrate on the compliance of the infrastructure you run in the rack and have the physical security of your rack (essential parts of requirements 9 and 12 of the PCI requirements catalogue and requirement 11.1 on wireless access points) attested through our certification. These points drop out of your own audit, because you build your certification on the certified PCI compliance of the data centre operator.

E-commerce providers, content providers, institutions and organisations of all kinds that offer services or products online by credit card, or accept donations, can therefore do so in a PCI-certified data centre environment in their own individually lockable 19" rack (with 21 or 42 height units). We will gladly provide you with our Attestation of Compliance (“AOC”) for this purpose.

5-zone security : People, Technology, Processes

Within our ISMS we address a wide range of topics to ensure the permanently secure operation of our data centres and customer systems.

From the outside in
  1. 01 Site
  2. 02 Building shell
  3. 03 Interior rooms
  4. 04 Data centre
  5. 05 Mesh cage

Our concept

  1. 24/7/365 data centre access

    We respond quickly to every event and ensure the smooth operation of the data centres.

  2. Perimeter protection

    The business park in which the data centre is located is protected by barred gates. The data centre itself has additional perimeter protection. The gates to the customer car park and to the building are centrally controlled and monitored and remain locked to unauthorised persons around the clock.

  3. 24h video surveillance

    The outdoor area, all building entrances and the data centre floor space are monitored around the clock by cameras with motion detection. The live video is checked centrally and also stored in compliance with data protection rules for later review.

  4. Entry control

    Entry is only possible after prior registration, accompanied by authorised staff and, in line with the security concept, with two-factor authentication (2FA). Authentication uses the staff member's personalised RFID transponder (“possession”) combined with correct entry of their personal PIN (“knowledge”).

  5. Monitoring and alerting

    The building management system is fully integrated into our central monitoring solution and alerting processes. Compliance with defined operating parameters and any fault messages are signalled immediately both to data centre access and to our security service providers, who are connected via redundant communication channels. Depending on the type of message, the security service provider informs the police, fire brigade and building services on its own where necessary, or first consults data centre access.

  6. Fire protection concept

    To detect and prevent fires early, highly sensitive smoke detectors for very early fire detection (VESDA) are used. If additional fire detectors (two-line dependency) also detect a potential fire, an automatic nitrogen extinguishing system (N₂ extinguishing) is triggered after a warning that protects people on the technical floor. At the same time, the fire brigade and building services are informed and an emergency plan is activated.

  7. Redundant power supply

    A battery-backed uninterruptible power supply (UPS) combined with a diesel emergency generator keeps operations running if the public power grid fails. Both are sized so that all components, including cooling, can continue to run without restrictions.

  8. Multi-layered protection against cyber attacks

    Protecting networks and IT systems against cyber attacks is essential for us, and we continually adapt it to current threats. For customers and for our own systems, we have developed a multi-layered security concept based on, among other things, DDoS protection, threat detection (IDS / IPS), next-generation firewalls, malware protection and tamper-proof backups.

Business and Service Continuity

So that essential systems keep running in crisis scenarios or are restored quickly, three things work together: emergency planning, regular exercises and continuously tested technology.

  1. Plan

    Emergency plans and escalation paths

    Within the ISMS, extensive emergency plans, strategies and escalation paths have been defined to keep essential systems running with as little interruption as possible even in crisis scenarios (e.g. a fire, power outages or cyber attacks), or to restore them as quickly as possible.

  2. Practise

    Exercises, training and redundancy

    Alongside regular reviews of the documentation, processes and systems this requires, we hold recurring emergency exercises and training sessions with all staff and external service providers (e.g. maintenance companies). Critical systems required for operation (such as our monitoring) are designed redundantly and distributed across our two independent data centres.

  3. Test

    Maintenance, tests and standby

    All systems are continuously maintained and subjected to regular function tests (including load transfer to the emergency generator). Contractually agreed standby services with our maintenance companies also ensure a quick response in the event of a fault.

Security Support Centre

The Security Support Centre (SOC) is at the heart of your company's cyber security strategy. It continuously monitors your information systems in order to detect security incidents early and respond to them. With tailored security concepts and modern technologies, our SOC provides comprehensive protection against cyber threats. Use our extended services, such as proactive threat analysis and quick remediation of security vulnerabilities, to strengthen your company's resilience.

Continuous monitoring

Your security advantage

Detect

  • Qualified security staff on duty around the clock
  • In-depth threat analysis and continuous monitoring
  • Partnerships with established providers of security technology

Respond

  • Immediate ability to respond to security incidents
  • Direct support in fending off and analysing cyber attacks
  • Quick containment and remediation of security incidents

Support

  • Managed security services and individually tailored service level agreements (SLAs)
  • Integration of cyber security into every aspect of IT operations
  • Competent support and implementation of security projects from a single source

Our SOC serves as your forward line of defence against cyber threats and keeps your data and systems secure.

By combining advanced technology, proven methods and experienced staff, we offer a security service tailored to the needs and challenges of your company.

Together we will find the right solution

We take the time to understand your requirements and develop suitable solutions. We also explain complex technical matters clearly and precisely. Feel free to contact me directly and we will find a solution.

  • We will get back to you as soon as possible.
  • No obligation and free of charge.

How we process your details is explained in our privacy notice.