About us

Specialisation instead of generalist consulting.

Lehner & Szecsey is a young consultancy specialised in the Cyber Resilience Act. We combine scientific grounding with an eye for what is actually feasible in small teams.

About us

Two specialists. One focus: your CRA conformity.

We’re not a large consultancy with off-the-shelf slide decks. We specialise in the Cyber Resilience Act and work as equals with small teams – in plain language and in feasible steps.

  • Our own CRA framework from a master’s thesis, built on OWASP SAMM and ISVS and aligned with the technical guidelines of the German BSI.
  • Practical, not theoretical – risk management, SBOM, secure SDLC and conformity evidence that work in everyday operations.
  • Made for SMEs – understandable, focused and without unnecessary overhead.

Our hands-on assessment framework grew out of a scientific study of the CRA. We continuously sharpen it against the actual regulation and the technical guidelines of the BSI – and are currently extending it with integrated risk management.

Maximilian Lehner
CRA & Security Consulting

Author of the CRA compliance framework (M.Sc. Management Information Systems, University of Regensburg). Focus: cybersecurity for IIoT/OT systems, from gap analysis to CE conformity.

LinkedIn profile
Tamara Szecsey
CRA & Security Consulting

Information-security consulting with a focus on CRA conformity and security processes for small and medium-sized manufacturers.

LinkedIn profile
Our promise: After every conversation you should know exactly where you stand and what the next step is – no jargon, no fear-selling.

Our framework

A scientifically grounded compliance framework.

At the heart of our consulting is our own cyber-security compliance framework – created from a master’s thesis at the University of Regensburg and proven in industrial practice. It systematically determines the cyber-security maturity of connected IIoT and OT systems and turns the flood of requirements into a clear, actionable path.

The scientific concept

Instead of working through requirements standard by standard, the framework consolidates overlapping controls from standards and regulation into a single catalogue ordered by maturity:

  1. Foundation: OWASP SAMM

    The OWASP Software Assurance Maturity Model serves as a measurable maturity model. The first goal is Maturity Level 1 in “Policy & Compliance”.

  2. Structure: OWASP ISVS

    The OWASP IoT Security Verification Standard provides the structure and three security levels (SL1–SL3) as a common language.

  3. Map standards → SRC

    OWASP ISVS and IEC 62443 are mapped against each other, making overlaps and gaps visible. The result is the Standard Requirements Catalog (SRC).

  4. Refine with the CRA → CRC

    The SRC is enriched with the requirements of the Cyber Resilience Act, producing the Compliance Requirements Catalog (CRC).

  5. Order by level & extend

    All requirements are assigned to security levels SL1–SL3 and extended with documentation- and cloud-specific topics.

  6. Questionnaire & policy

    A compliance questionnaire makes the maturity measurable and comparable; a dynamic policy framework keeps it adaptable to your environment.

Proven & evaluated: The framework was developed together with TGW Logistics Group on real smart-warehouse systems and subsequently evaluated and refined through expert interviews.
Next expansion – risk management: We are currently extending the framework with integrated risk management, so that maturity and risk are considered together and measures are prioritised on a risk basis.

Built on established standards

  • OWASP SAMM
  • OWASP ISVS
  • IEC 62443
  • BSI TR-03183
  • CRA · EU 2024/2847
  • C5:2020

Contact

Let’s talk about your product.

A free, non-binding initial consultation usually clarifies the most important question right away: are you affected – and how big is the effort?

Note: we provide consulting on cybersecurity and CRA conformity – not legal advice.

Write to us

The fastest way to reach us is by email. Briefly describe your product and your question – we’ll get back to you promptly with a suggested time.

kontakt@ls-cybersecurity.eu

Send an email