Ihr Experte für Fragen
Vladyslav Dunajevski
Director, Cyber Security & Privacy, PwC Germany
In the multi-cloud and hybrid reality with AWS, Azure, GCP and Kubernetes, the shared responsibility model applies: providers secure the platform, while you are responsible for configurations, identities, and workloads. At the same time, ransomware and supply chain attacks are increasing, skilled talent is scarce, and 24/7 operations as well as regulation (GDPR, NIS2, ISO 27001, BSI C5 catalogue; in critical infrastructure/the financial sector, e.g., DORA) add pressure.
To stay secure in this evolving landscape, companies need a trusted partner – such as PwC. We deliver in-depth multi-cloud expertise, backed up by continuous monitoring, intelligent risk assessment and end-to-end security services – all to help you reduce risk, enhance resilience and operate with confidence across every cloud in your estate.
“If a cloud security MSP charges extra for every process improvement and tighter controls despite continuous operations, that’s a quality issue. We deliver Managed Cloud Security that combines industry expertise, automation, and compliance – continuous optimisation included, not an extra charge.”
We’ll perform regular assessments of documentation, architecture and configurations across your landing zones, apps and workloads using our DARC assessment methodology (defence, architecture and engineering, risk and continuity management, cost efficiency). This includes expert workshops, risk identification, and evaluation of resilience, DevSecOps maturity, monitoring capabilities, IT risk controls and cost management practices.
This approach ensures a clear understanding of where there are security gaps and weaknesses, giving improved visibility of the security posture of your platforms and workloads. It also boosts resilience, reduces vulnerabilities, and delivers actionable recommendations that strengthen the foundations of your cloud systems and help ensure secure operations.
We provide ongoing visibility and control by identifying and inventorying resources across all your cloud platforms, ensuring adherence to regulations with automated compliance checks and policy enforcement. Risks are continuously assessed and prioritised based on their impact and likelihood, while integrations with SIEM, ticketing and reporting systems enable effective threat detection and response. Automated remediation reduces manual work, and continuous configuration assessment prevents drift. Ultimately, this ensures better compliance, smaller attack surfaces, quicker detection of suspicious activity, and a more secure, better‑governed multi‑cloud estate.
We integrate security tools directly into CI/CD pipelines, enabling automated scanning of code, applications, containers and infrastructure as code. Quality gates, security tests and real-time vulnerability detection all work to strengthen your software development life cycle. Our experts help you with creating policies, governing repositories, secret scanning, remediation workflows and managing waivers, and we’ll run workshops to help your development teams adopt secure-by-design practices. Outcomes include faster and more secure delivery cycles, fewer vulnerabilities in code pipelines, better developer enablement, and a clear roadmap for building mature DevSecOps capabilities aligned with your vision.
Senior Manager, Cyber Security & Privacy, PwC Germany
Tel: +49 160 8976 282