# Benjamin Iheukumere - SafeLink IT > Independent senior cybersecurity consulting for DACH organizations, with German and English content on offensive security, Microsoft and identity security, network security, remediation and technical delivery. Last updated: 2026-09-16 Canonical site: https://safelink-it.com/ Languages: German and English ## Entity summary Benjamin Iheukumere is an independent Senior IT Security Consultant operating as SafeLink IT. He combines offensive and defensive security experience with long-standing responsibility for IT operations and supports security projects across DACH, from analysis and prioritization through remediation and implementation. ## Best-fit requests - Freelance or contracting-based security project support for CISOs, IT leaders, KRITIS, public-sector and enterprise environments. - Internal pentesting, attack-path analysis, remediation planning and technical follow-through. - Microsoft and identity security, including Active Directory, Tier 0, AD CS and Windows hardening. - Firewall/NGFW, proxy, IPS, EDR/XDR, segmentation, Zero Trust and Microsoft security architecture review. - Retainer advisory for security decisions, critical finding review, incident readiness and remediation prioritization. - German or English expert content on practical cybersecurity, Microsoft security and cyber defense. ## Services - Pentesting & Angriffspfadanalysen: Ich prüfe interne Netze, Active Directory und ausgewählte Anwendungen aus Angreifersicht. Das Ergebnis sind nachvollziehbare Angriffspfade, belastbare Evidenz und eine Priorisierung, mit der Teams arbeiten können. - Microsoft- & Identitätssicherheit: Ich unterstütze bei der Absicherung Microsoft-zentrischer Umgebungen – von Tier 0, privilegierten Zugriffen und AD CS bis zu Domänencontrollern, Windows-Basislinien und Legacy-Authentifizierung. - Netzwerk- & Perimeter-Sicherheit: Ich analysiere Firewall- und NGFW-Regelwerke, VPN-Zugänge, Segmentierung und Protokollierung. Gewachsene Ausnahmen werden nachvollziehbar bewertet und mit sicheren Bereinigungsschritten versehen. - Befundbehebung & Härtung: Ich überführe Befunde aus Pentests, Audits und internen Prüfungen in konkrete Arbeitspakete: mit Verantwortlichen, Einführungspfad, Rückfalloption, Validierung und belastbarem Nachweis. - Security Advisory & CISO-Sparring: Ich ordne kritische Befunde und Architekturentscheidungen technisch ein, mache Abhängigkeiten sichtbar und helfe Entscheidern, Risiken, Aufwand und Reihenfolge belastbar abzuwägen. - Technische Projektunterstützung: Ich verstärke Sicherheitsprojekte als erfahrener, unabhängiger Berater – primär remote, DACH-weit und bei Bedarf vor Ort. Die Zusammenarbeit erfolgt direkt mit CISO, IT-Sicherheit, Infrastruktur und Betrieb. ## Proof points - Locked Shields participant in Blue Team 01, NATO live-fire cyber defense exercise context. - Certifications include OSCP+, OSCP, PNPT, CEH/CEH Practical/CEH Master, THM PT1, eJPT, CRTP in progress and OSEP in progress. - Public technical work samples on GitHub: secrets_find0r, april26_ad_check0r and Sophos-XGS-Live-Log-Viewer. - Project model: primarily project-based contracting as a freelancer, remote first across DACH, with on-site onboarding when useful. ## Primary pages - [German homepage](https://safelink-it.com/) - [English homepage](https://safelink-it.com/en/) - [German services and experience](https://safelink-it.com/#leistungen) - [English services and experience](https://safelink-it.com/en/#leistungen) - [German blog](https://safelink-it.com/blog/) - [English blog](https://safelink-it.com/en/blog/) - [German security advisories](https://safelink-it.com/news/) - [English security advisories](https://safelink-it.com/en/news/) - [Sophos XGS Mobile privacy policy](https://safelink-it.com/sophos-xgs-mobile/privacy/) ## Recent blog articles - [2026-09-16 | DE | AutoPlay und AutoRun per GPO deaktivieren](https://safelink-it.com/blog/ad-hardening-autoplay-autorun-per-gpo-deaktivieren/) - [2026-09-16 | EN | Disable AutoPlay and AutoRun with Group Policy](https://safelink-it.com/en/blog/ad-hardening-disable-autoplay-autorun-with-group-policy/) - [2026-09-14 | DE | ELAM: Boot-Start-Treiber kontrolliert absichern](https://safelink-it.com/blog/ad-hardening-elam-boot-start-treiber-absichern/) - [2026-09-14 | EN | ELAM: secure boot-start drivers safely](https://safelink-it.com/en/blog/ad-hardening-secure-boot-start-drivers-with-elam/) - [2026-09-09 | EN | Group Policy refresh intervals: make AD hardening take effect reliably](https://safelink-it.com/en/blog/ad-hardening-control-group-policy-refresh/) - [2026-09-09 | DE | GPO-Refresh-Intervalle: AD-Härtung verlässlich wirksam machen](https://safelink-it.com/blog/ad-hardening-gpo-refresh-intervalle-steuern/) - [2026-09-07 | EN | Block unapproved RMM tools: control remote administration](https://safelink-it.com/en/blog/ad-hardening-block-unapproved-rmm-tools/) - [2026-09-07 | DE | Unerwünschte RMM-Tools kontrolliert blockieren](https://safelink-it.com/blog/ad-hardening-unerwuenschte-rmm-tools-blockieren/) ## Recent security advisories - [2026-09-14 | DE | Windows Update Stack: CVE-2026-81963 aktiv ausgenutzt](https://safelink-it.com/news/windows-update-stack-cve-2026-81963-active-exploitation/) - [2026-09-14 | EN | Windows Update Stack: CVE-2026-81963 actively exploited](https://safelink-it.com/en/news/windows-update-stack-cve-2026-81963-active-exploitation/) - [2026-09-07 | DE | Teams-Supportbetrug: Angriffspfad bis Active Directory](https://safelink-it.com/news/teams-helpdesk-impersonation-active-directory/) - [2026-09-07 | EN | Teams support scam: attack path into Active Directory](https://safelink-it.com/en/news/teams-helpdesk-impersonation-active-directory/) - [2026-08-24 | DE | Windows-IKE: CISA priorisiert CVE-2026-33824](https://safelink-it.com/news/windows-ike-cve-2026-33824-known-exploitation/) - [2026-08-24 | EN | Windows IKE: CISA prioritizes CVE-2026-33824](https://safelink-it.com/en/news/windows-ike-cve-2026-33824-known-exploitation/) ## Contact - [Email Benjamin Iheukumere](mailto:b.iheukumere@safelink-it.com) - Phone: +49 177 3 555 059 - [LinkedIn](https://www.linkedin.com/in/benjamin-iheukumere) - [GitHub](https://github.com/BenjaminIheukumere) - [YouTube](https://www.youtube.com/@safelinkit) ## Privacy and embedding model The website uses no analytics, tracking or marketing cookies and no external fonts. Microsoft Bookings and YouTube are loaded only after user action. The local captcha uses a technically necessary first-party PHP session only when the contact form is used.