Industry & Manufacturing MedTech & Pharma 50 to 500 employees
Managed Security for Swiss SMEs

Finally know how secure
your company really is.Visible. Stable. Manageable.

We make cyber risks visible, stabilise your security posture within weeks and make security permanently manageable. With an operating process instead of yet another tool landscape.

In 30 minutes, you will know where you really stand. No obligation.

NIS2 ISO 27001 FADP GDPR Swiss Made
Detect.Stabilize.Control.
Scroll
The real problem

Your security has grown one extension at a time.

Many tools, no blueprint. Every provider has built one piece, but nobody sees the whole. The hardest question is not “Which tools do we have?” but “Have they actually made us more secure?”

01

Many tools, no overall view

Security is a collection of tools, not a system. Nobody sees the full picture and nobody can say where the gaps are.

02

Effectiveness cannot be demonstrated

Your controls are in place. Whether they reduce your actual risks or are merely “there” cannot currently be measured or demonstrated to the board.

03

The board asks, you have to guess

“How secure are we really?”

“I trust that our IT person has it under control.”

04

In a serious incident, you may be personally accountable

Insurance, NIS2 and supply-chain audits require evidence. When an incident happens, there is no defensible answer and nothing tangible to present.

The pattern is always the same: security as a collection of tools, not as an operating process. That is exactly where we start.

Our model

Detect. Stabilize. Control.

Three stages, one operating security process. Every measure contributes to the whole instead of becoming another tool in a patchwork.

Stage 01 · Detect

Make risks visible

We examine your external attack surface the way an attacker would. Vulnerabilities, exposed access points and compromised identities become visible.

Stage 02 · Stabilize

Stabilise the situation quickly

We address the highest-impact levers first. Your risk drops quickly and noticeably, without a lengthy preliminary project.

Stage 03 · Control

Make security manageable

We embed governance, maturity and reporting. Security becomes a management metric you can steer like any other business KPI.

We do not sell tools. We establish a process.
Compliance with NIS2, ISO 27001 and the FADP is the result of a functioning security process,
not an empty promise.

No in-house CISO?

That is exactly what we are built for: a Security Operating Model for organisations without their own security department.

Request a consultation

See in a short initial conversation how the process would work in your organisation. No obligation.

Services

Your security cockpit.
Everything in one place.

Instead of isolated tools, you get an ongoing service that monitors, protects and makes your security visible.

Attack Surface Management

Your attack surface stays continuously visible, not just once a year.

Threat- & Dark-Web-Monitoring

We identify threats and leaked credentials before they become incidents.

Smart MFA & Access

Access is properly secured without slowing down day-to-day work.

Management-Reporting

Your security posture becomes a clear metric you can present in every management meeting.

Request a consultation

Turn your security posture into a clear metric instead of guessing. Discuss it with us at no cost.

Why CTRL 42

Two minds. One method.

Scientific analysis meets operational IT leadership in regulated environments — a strong foundation of trust for MedTech and pharma in particular.

Dr. Rolf Schmid
// PROFILE_01 · Available

Dr. Rolf Schmid

Strategy · Analysis · Architecture · Governance

Scientific depth and architecture DNA. Translates complex risk situations into a manageable process and into language the board understands.

Antonio De Luca
// PROFILE_02 · Available

Antonio De Luca

Operations · High Availability · Safety-Critical Systems · Aviation

Strategic and operational IT leadership in aviation. 18 years of experience as an IT manager at Lufthansa, with a focus on aeronautical chart production. Specialist in highly available, safety-critical systems, complex IT infrastructures and the specific regulatory requirements of aviation.

Why now

Every day without control
costs you money.

// RANSOMWARE
+0%
Ransomware incidents in Switzerland, H2 2025 vs. previous year
// CYBERANGRIFFE
+0%
Increase in cyberattacks in Switzerland, Q1 2025
// BACS-MELDUNGEN
0
Cyber incidents reported to the NCSC since mandatory reporting began in 04/2025
// MELDEFRIST
0h
NCSC reporting obligation, with a fines regime from H2 2026

Sources: NCSC semi-annual reports 2025, Swiss SME Portal. Example manufacturing SME: production downtime costs CHF 50,000 to 100,000. Per day.

Straight talk

What you may be thinking,
answered plainly.

«Our IT provider already does that.»
Ihr Dienstleister runs operations. We add visibility, process and control above that. Your provider stays and works to a clear standard. This supports them instead of replacing them.
«But we already have tools.»
Tools without a process are isolated parts. We provide exactly the overall view, you are missing today and make it demonstrable whether your controls are actually effective.
«But we have cyber insurance.»
Cyber insurance only pays when there is evidence and is renewed only with a defensible security posture. We provide maturity evidence that supports your policy and premium instead of leaving you empty-handed after an incident.
«What does it cost?»
The right question is what downtime costs: CHF 50,000 to 100,000 per day, plus insurance and fines exposure. Our model is predictable and recurring instead of an unpredictable loss. It typically pays for itself in under twelve months, while avoided losses usually exceed the investment by a factor of five to ten.
How we start

Start small. Make an impact fast. Stay in control.

No months-long project up front. We start where impact is immediate and build the process step by step.

1
01
Step 01 · Detect

Security Assessment Recommended

A clear view of your attack surface and risks. Fast, concrete and without a large preliminary project.

2
02
Step 02 · Stabilize

Stabilisation

The most effective measures first. Your risk falls noticeably, with a defensible security baseline.

3
03
Step 03 · Control

Governance & Operations

Governance, reporting and ongoing managed-security operations. You stay in control and can demonstrate higher maturity quarter after quarter.

4
04
Step 04 · Evolve

Architecture & Resilience

From effective services to strategic security architecture: resilient over the long term, audit-ready and future-proof.

Request a consultation

We start only a limited number of new projects each quarter. If you want to plan 2027 properly, now is the time to begin.

Contact

Do you know whether you are truly secure?

Let us find out together. No obligation, peer to peer, with Swiss calm instead of sales pressure.

By submitting, you agree that we may contact you. We treat your data confidentially.

Thank you, we received your request.

We usually get back to you personally within one business day.