For executive management & the board

IT risk, liability, costs – answered on a single page.

You do not need to understand IT the way your admin does. But there are three questions you should be able to answer at any time – to your supervisory board, your insurer and, if it comes to it, a regulator. We make sure those answers stand up.

The three questions you must be able to answer

“Are we personally liable?”

NIS2 explicitly holds executive management responsible – delegation alone does not discharge that duty. What counts is demonstrable implementation of appropriate measures. Our operations produce exactly that evidence as a matter of course.

Answer: NIS2 & compliance →

“What would an attack cost us?”

87% of the surveyed companies were affected by data theft, espionage or sabotage within the last twelve months (Bitkom 2025); for a mid-sized business, a single ransomware incident can quickly cost several times the annual IT budget. The counter-calculation: a fixed monthly rate for professionally operated security.

Answer: cyber defence →

“Why does IT keep getting more expensive?”

Because nobody controls unplannable costs: outages, ad-hoc contractors, licence spirals. Managed services turn all of this into a budgetable, predictable monthly cost.

Answer: predictable costs →

What this means commercially

Metric Today (typical) With managed services
IT costs Fixed salaries + unpredictable spikes Fixed monthly rate, budgetable years ahead
Cyber risk Unknown – and uninsurably expensive when it happens Measurably reduced, documented to insurance standard
Compliance evidence A project before every audit Generated automatically in day-to-day operations
Dependence on individuals Knowledge monopolies; risk whenever someone leaves Documented processes; a team instead of one person
Scalability Growth = a recruiting problem Growth = a package adjustment
“You run your business. We make sure that IT is never the thing that keeps you awake at night.”

Michael Bölk · Managing Partner, mosaic IT GmbH – 30 years in IT.

Frequent questions from executive teams

How quickly will we see results?
The IT Health Check delivers a documented assessment of where you stand. The first managed services are typically in regular operation after 4–8 weeks.

Will we become dependent on you?
No – that is a design principle: your documentation belongs to you, contracts can be terminated on fair terms, and we work with open standards. We retain clients through quality, not lock-in.

What is the first step?
A 30-minute conversation – ideally together with your Head of IT. Afterwards you will know where you stand, what it costs and whether we are a good fit.

Further reading

PDF report

Cybersecurity Benchmark Report 2026

10 min read · management-ready

How does your company compare with the wider mid-sized sector? Figures you can use in your next strategy meeting.

Download the free report
Interactive tool

Savings calculator

3 inputs · instant result

How much budget is tied up in routine IT operations – and how much of it could you save?

Start the calculator

30 minutes your finance team will appreciate

In a free initial consultation we talk about risk, liability and budget – in your language, with concrete figures.

Free IT health check

Where does your IT really stand? Our structured IT health check reveals risks, gaps and opportunities – concise, clear and with no strings attached.

Go to the IT health check →