Strategic Business Transformation
We drive enduring success with a holistic strategic transformation: We unite innovation, strategy, customer excellence, organization, regulatory expertise and M&A for real business impact.
Consulting services
Featured
Building base-led consumer growth and outcome-led B2B
Discover how base-led growth, real-time decisioning and outcome-led B2B solutions help telecom operators unlock new revenue streams.
Process & Application Modernization
NEW: IREB CPRE Foundation training courses
Build a solid RE foundation in two days and prepare effectively for the IREB CPRE Foundation exam with our training courses in the DACH region.
Technology & Infrastructure Transformation
Accelerate your digital transformation with tailored strategies for IT, architecture, cloud, and autonomous networks.
Whitepaper: The great telco unbundling
As growth slows and capital pressure rises, telcos are rethinking ownership models. Infrastructure separation and NetCo strategies are redefining how value is created across the industry.
Emerging Tech
Unlock new value with IoT, Quantum, AI, and Software-Defined innovation – future-proof your business today.
Two AI worlds, one robot: Why real business value only emerges when Physical AI and Agentic AI work together to make autonomous robots viable for real-world applications in manufacturing, logistics and beyond.
Cybersecurity, Governance & Resilience
Navigate today’s risks with integrated cybersecurity and GRC solutions – protect, comply, and thrive in a dynamic world.
Webinar: IT security in hospitals
In our webinar, we show how a structured IT security assessment for hospitals creates transparency about the IT security posture, systematically prioritizes risks, and provides solid decision-making foundations.
Automotive
We guide OEMs and suppliers through seamless digital transformations.
Energy
The energy market is highly competitive: new niche players, innovative business models, and technology-driven sectors are gaining ground.
Shaping the energy transition
How energy providers & municipal utilities are creating a sustainable future with data, smart technologies, and innovative customer services.
Health
Manufacturing
With AI, manufacturers reduce up to 40% defects, gain 25–30% efficiency, improve speed and agility in real time decision making and quality control.
Smart Manufacturing
Explore Smart Manufacturing solutions powered by 5G, 6G, IoT, Digital Twins, AI, and Quantum to drive your efficiency, flexibility, and growth.
Public
Cognitive Cities. Shaping the future of urban living.
Using AI, IoT, and data management to make urban spaces more efficient, sustainable, and safer- tailored to the needs of each cognitive city.
Retail
We support retail companies in building future-proof IT systems – from greenfield projects to the transformation of efficient organizations and system landscapes.
Telecommunications
Disruption, pressure, regulation: Telcos face a new era. Turning change into growth – with vision and strong partnerships.
Telco state of the industry
From optimizing existing business models to unlocking new value creation: a strategic perspective on the telco transformation in the AI era.
Travel, Transport & Logistics
Detecon blends management consulting with deep rail-tech know-how to guide clients through the digital transformation of rail networks.
InnoTrans 2026 in Berlin
How we work
Working with us means achieving more together – with deep expertise, bold thinking, and reliable delivery across your digital journey.
Insights
Fresh perspectives from Detecon: Explore cutting-edge insights at the intersection of business, technology, and society — shaping tomorrow’s transformation today.
Detecon assessment & learning suite
Find our structured, self-service assessments as well as expert-led training courses.
Locations
We operate from 14 locations and have provided services to 136 countries.
Our locations by region
Our Company
We combine management consulting with deep technology expertise – to guide your digital transformation as a trusted partner.
More information
Your Career
Shape the future with us! We welcome curious minds and bold thinkers. If you’re ready to start your career or take it to the next level, find out how you can grow with us.
Contact
Let’s connect! Have you got any questions, ideas or opportunities you’d like to explore? Get in touch! We’re just a message away!
Menu
EN
Not what you are searching for?
Senior Manager
Principal
For a long time, IT security did not play a major role in many hospitals. The focus was understandably on patient care, staffing challenges, and the economic survival of the organization in day-to-day operations. IT was primarily seen as an operational factor – it simply had to work.
Today, this perspective is no longer sufficient. The increasing digitalization of clinical processes, connected medical devices, external service providers, and cloud integrations significantly expand the attack surface. At the same time, successful cyberattacks on hospitals have shown that IT security is not a theoretical risk. It can directly threaten hospital operations, patient safety, and ultimately the viability of the organization.
The strong dependence of the healthcare sector on stable IT systems has compelled legislators to take action. With EU Directive 2022/2555 and the German NIS2 Implementation Act (NIS2UmsuCG), cybersecurity is becoming a legally binding obligation for a significantly broader range of organizations. The number of affected entities is increasing from around 4,500 to approximately 29,500, including many hospitals and medium-sized companies in the healthcare sector.
The law has been in force since December 6, 2025. For executive management, this means that IT security is explicitly a leadership responsibility. Senior management can be held personally liable if the implementation of requirements is not properly supervised, if training is neglected, or if documentation is outdated. Violations may result in substantial fines and personal liability. We have summarized the key aspects of NIS2 for you below.
NIS2 requires risk management, security measures, and incident reporting, which must be structured within an Information Security Management System (ISMS). The B3S standard maps these requirements to sector-specific frameworks such as IT-Grundschutz.
To systematically assess the status of your IT security, we consider the most important dimensions, aligned with B3S and NIS2:
Together, these dimensions form the foundation for an effective and auditable level of security in accordance with NIS2 and B3S, and therefore for stable and secure hospital operations.
Further information can be found below.
(Information) Risk Management (ISRM/RM): Establishment of a holistic and systematic risk management process for the consistent identification, assessment, treatment and tracking of information security risks for all critical information assets.
Suppliers & Third Parties: Risk-based supply chain management through the evaluation of service providers regarding their security measures, contractual definition of security requirements, and continuous monitoring.
Asset Management: Complete inventory of all information assets and IT systems (IT, medical technology, supply infrastructure, critical applications) with classification according to criticality and protection requirements.
Business Continuity Management (BCMS) & Emergency Management: Ensuring operational continuity and recovery of critical processes in the event of disruptions or failures through emergency plans, backup strategies, and regular testing.
Incident Detection and Response: Establishment of an incident response capability for rapid detection, containment, and remediation of security incidents with structured follow-up (lessons learned) and fulfillment of BSI reporting obligations.
Auditing and Continuous Improvement Process (CIP): Implementation of systematic and regular monitoring, audit and review measures to validate the effectiveness of implemented information security controls, identify deviations, and ensure continuous improvement of the information security management system.
Trainings and Awareness: Raising awareness and enabling employees through regular, target-group-specific training and cyber-hygiene awareness, as well as ensuring personnel availability through substitution arrangements and screening.
Technical Information Security (Endpoint AV, VPN, Firewalling, IDS/IDP; Incident Detection Systems such as SOC / SIEM): Implementation of all technical security controls for IT systems, networks and applications including access control, network segmentation, malware protection, encryption, logging/monitoring and secure development.
An Information Security Management System (ISMS) is far more than a single document. It represents a structured management system that controls information security through a process-oriented PDCA cycle (Plan–Do–Check–Act), reduces risks and continuously improves security.
Key benefits:
Focusing on measurable KPIs, regular audits and suitable security tools ensures that IT security becomes part of the organizational culture rather than a static compliance document.
In many German hospitals, a well-implemented ISMS can already cover around 80% of NIS2 requirements, significantly strengthening operational resilience.
Through a structured questionnaire, Detecon enables hospitals to conduct a rapid and realistic IT security assessment without extensive preparation.
The assessment is designed for IT leaders and hospital management and provides:
The result is not just an abstract score, but a solid basis for decision-making — for management, investment planning, and the next realistic steps toward stronger IT security.
Access the IT Security Assessment here (coming soon).
The NIS2 Act, officially the NIS2 Implementation Act (NIS2UmsuCG), transposes EU Directive 2022/2555 into German law and strengthens cybersecurity across a broader range of companies and institutions. It expands the number of affected organizations from approximately 4,500 to around 29,500, including medium-sized organizations in critical sectors such as energy, healthcare, finance and digital infrastructure.
The law entered into force on December 6, 2025, with a registration deadline at the German Federal Office for Information Security (BSI) on March 6, 2026.
The question today is no longer whether hospitals need to address IT security – but how quickly and how systematically they begin. Cyberattacks, regulatory requirements, and increasing digitalization make a structured security management approach essential.
A clear understanding of the current security posture is the first step toward reducing risks and establishing IT security as a sustainable part of hospital operations.
Select your location
You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
On this page
Get in touch
You are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
You are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
You are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.