Getting started
BISA and BEIA Two paths to Management Clarity
The start of an engagement is clearly defined and takes place on your premises.
BISA examines in two modules how business, data, IT and security work together: first a baseline with immediate measures, then target picture and roadmap. BEIA, the Executive Fast Track, looks at the whole company across eight layers in a single cycle. Both end with Management Clarity: current state, risks, gaps, opportunities, target, priorities and plan.
45 minutes, free of charge, by video.
Which path fits? Twelve questions, about 3 minutes.

Module 1 of 2
BISA 1 Discover & Baseline
Where do we stand today, and where are our main risks and fields of action?
How it works
In interviews with the executive team, business units and IT, and during a day on site, we capture how business, data, IT and security actually work together today. We assess the findings from the perspective of business, operations, risk and management.
What we look at
Business context, infrastructure and network, identities and access, endpoints, cloud and SaaS, backup and recovery, data flows and interfaces, service providers and operational responsibility, and AI readiness.
What you receive
- Documented current state as the baseline
- Findings, backed by interviews, documents and the day on site
- Risks and critical gaps
- Priorities by risk, effort and benefit
- Immediate measures that work without a large project
Not included: Penetration tests are separate services.
Module 2 of 2
BISA 2 Validate & Advance
What have we achieved, and how do we develop a robust enterprise target architecture from it?
How it works
BISA 2 is not a repeat. We check the measures from BISA 1, assess what has changed since the baseline, re-rate the remaining risks and widen the view to the target architecture.
Prerequisite
A completed BISA 1. We agree the timing together, ideally once the immediate measures are in place.
What you receive
- Progress validation: implemented and effective?
- Residual risks, consciously accepted or treated further
- Target picture and architecture gaps
- Action plan with sequence and ownership
- Roadmap in stages, matched to budget and capacity
Direct path
BEIA Executive Fast Track
How is our company set up today, which risks exist, and which target architecture do we need for our business vision?
How it works
The complete enterprise view in one cycle instead of two stages: one day on site with both managing partners. Because your team provides the documents in advance, the day is fully available for interviews, walk-through, assessment and prioritisation.
- Before
- Your team provides the documents. We review them and agree the agenda with you.
- On the day
- Both managing partners conduct interviews and the walk-through, assess and prioritise.
- Afterwards
- We prepare the Enterprise Assessment Book and present it to the executive team.
What we look at
- Business
- Business context: goals and business model
- Organisation and control
- Capabilities, operating model, governance, service providers
- Foundation
- Data, applications, technology
- Cross-cutting
- Security, risk & compliance across all layers; AI readiness across business, data and technology
Enterprise Assessment Book: ten components, one basis for decision
- At a glance
- Executive Summary
- Where do we stand?
- Current State Architecture, Risk Register, Risk Heatmap
- Where do we want to go?
- Gap Analysis, Target State Architecture
- What needs to be done?
- Prioritized Action Catalogue, Investment Areas, Transformation Roadmap
- What follows?
- Management Decision Paper
Not included: Penetration tests, legal review, detailed technical planning and implementation.
Preparation
Well prepared, so the day on site delivers
For BEIA your team provides the key documents in advance. Open points come with us into the day as questions.
Ten days before · executive team
- Organisation chart and fixed contacts
- to plan the right conversations.
- Strategy, goals and current projects
- basis for business context and target picture.
- Fixed appointments with executives, IT and business units
- the day is tightly scheduled.
Five days before · IT lead, procurement, data protection
- Overview of systems and applications
- basis of the Current State Architecture.
- Infrastructure documentation and network plans
- show dependencies and weak points.
- Contracts with key service providers
- clarify responsibility and terms.
- Security and data protection concepts
- for requirements from GDPR, NIS2 and GoBD, for example.
- Known weaknesses and open issues
- feed into the Risk Register.
Questions
What managing directors ask before the appointment
When does BISA 2 start?
After a completed BISA 1, once your team has put the immediate measures in place. We agree the timing together.
What is not included in the entry?
Penetration tests are separate services for both BISA and BEIA. BEIA also excludes legal review, detailed technical planning and implementation. We take requirements from GDPR, NIS2 and GoBD into account from an architecture and risk perspective.
As of October 2026. Not legal advice.
Who from SIMO comes to the day on site?
For BEIA, both managing partners. They conduct the interviews and walk-through themselves and present the result to the executive team.
What happens after the entry?
You decide. With Management Clarity, current state, risks, gaps, target, priorities and plan are on the table; whether and with which service to continue is your call, with no obligation to take the next step.
Your next step
45 minutes, and you will know whether SIMO fits your decision.
An initial call by video, free of charge and without obligation, with one of the two managing partners. If working together makes no sense, we tell you openly.
45 minutes, free of charge, by video.
Rather place yourself first? Twelve questions, about 3 minutes.
Prefer to call? +49 6021 625 63 40
Note: the 3D visualisations on this page were created with AI.