K09 / PATTERNS

Flows, step by step.

Every flow carries data-step attributes and ends in a contextual next step. UV marks the conversion step; red marks the emergency exit.

Emergency lane

Works without JS, on slow mobile

Live →
  1. Any page
  2. Header lane / mobile button
  3. tel: call
  4. or phone-only callback
  5. "Do this now" steps

Intent routing

Emergency first and distinct

Live →
  1. Get in touch
  2. Pick intent
  3. Emergency → hotline
  4. Details (5 fields)
  5. Book named expert
  6. Confirmation

NIS2 check

No email gate for the result

Live →
  1. Sector
  2. Size
  3. Supply-chain role
  4. Result + obligations
  5. Book readiness assessment

Pentest scoping

Configuration travels with the lead

Live →
  1. Test types
  2. Scope sliders
  3. Ballpark
  4. Request scoping call
  5. NDA → fixed price

Managed IT quote

Price before form

Live →
  1. Users
  2. Modules
  3. Live price
  4. Get a quote
  5. Written proposal ≤ 2 days

Retainer signup

Before an incident

Live →
  1. IR page / case study
  2. Retainer terms
  3. Request a retainer
  4. Onboarding call

Gated report

Progressive profiling: ask once, then less

Live →
  1. Report card
  2. Name + email
  3. Double opt-in
  4. Download
  5. Next visit: 1 field

Responsible disclosure

No third-party scripts on this page

Live →
  1. security.txt
  2. Report (PGP optional)
  3. Ack ≤ 1 business day
  4. Fix + credit
  5. Hall of fame

Documentation with NDA

Public docs stay ungated

Live →
  1. Pick documents
  2. Click-through NDA
  3. Request
  4. 7-day link

Alert triage (portal)

Everything written to the audit log

Live →
  1. Queue
  2. Select row
  3. Detail + context
  4. Acknowledge / ask SOC
  5. Audit log entry

Authentication

MFA default, FIDO2 preferred

  1. Email
  2. SSO or password
  3. FIDO2 / app code
  4. New-login notice
  5. Session timeout 30 min, warned at 25

Consent

Equal weight, nothing pre-checked

Live →
  1. First visit
  2. Reject all = Accept all
  3. Settings in footer
  4. No analytics on D03/disclosure

STATES

EMPTY

All quiet.

No open alerts. The SOC checked 14,212 events in the last hour.

LOADING

Filtering noise…

Noise-to-signal loader; skeleton rows keep layout stable.

ERROR

That didn't go through.

Your data is safe. Try again, or call us if it's urgent.

SUCCESS

Done. Logged at 03:12 UTC.

Every success names what happened and when.

OFFLINE

You're offline.

The hotline number is cached: +49 431 555 0000.

DEGRADED

Exports are slow.

Detection and response are not affected.

K10 / DATA VISUALIZATION

No scare scaling. Ever.

  • Source and date on every threat statistic
  • CVSS version always stated
  • Units always (min, h, %)
  • Axes start at zero
  • No red below Critical
  • Illustrative data labeled
  • Animate once, then rest
  • Text alternative for every chart
MTTD & MTTR · minutes12 months
0 20 40

— MTTR 19 - - MTTD 4 Illustrative · axis from 0

Risk matrix · likelihood × impact12 risks

Rows: impact 5→1 · cols: likelihood 1→5 · sequential UV, no red

Patch compliance · % within 14 daysQ1–Q3 2026

Bars from 0% · target 95%

Phishing simulation · click rate6 campaigns
23% 9%

Illustrative · y-axis 0–30%

Incident Gantt · T+ timeINC-0412
KPI tiles with sparklines30 days

Alerts triaged

1,284

Incidents

3

MTTR

00:19

Coverage

99.8%

Data table · sortable (click headers)Export CSV
Nordhafen Logistik121001
[REDACTED] Mfg1799.64
Werft AG1999.33
Example GmbH2199.12
Kliniken Nord2598.46

More live charts: SOC funnel (D01, D02) · ATT&CK heatmap (D02) · severity distribution (D04) · vulnerability aging (D12) · uptime strips (D10) · SLA attainment (D06).