
Zero Trust: from buzzword to workable strategy – and what becomes of the VPN
What zero trust actually means, why the VPN alone no longer holds, and in what steps a mid-sized company can make the shift – without doing it all at once.
Read moreExpertise, trends and practice from the world of information security.

What zero trust actually means, why the VPN alone no longer holds, and in what steps a mid-sized company can make the shift – without doing it all at once.
Read more
Default configurations are convenient – and a way in. How CIS Benchmarks harden systems measurably, where to start, and how to hold the state you reach.
Read moreEPSS, KEV and reachability: how a list of findings becomes a defensible ranking – and why the CVSS base score alone is not enough for the job.
Read more
Four in five reported attacks hit mid-sized firms. How to lower the risk, spot an incident early and get through the worst case – without paying.
Read more
A large study shows classic phishing training barely moves the click rate. What works instead – processes, phishing-resistant sign-in, a reporting culture.
Read more
What a pentest delivers, how it differs from a vulnerability scan, how the BSI classifies it – and how to recognise a good proposal.
Read more
It takes a median of 14 days to notice an attack. Why running a SIEM in-house fails and when outsourcing makes sense.
Read more
Why the BSI variant of ISO 27001 is more than a seal – how certification actually proceeds, what it takes, and where projects typically get stuck.
Read more
Exploits over phishing, 22 seconds to hand-off, extortion via data leaks: what the current figures show – and what pragmatically helps against them.
Read more
It is not the cloud that is insecure but its configuration. The most common pitfalls in Microsoft 365 and Azure – and how to defuse them quickly.
Read more
How IT forensics secures evidence after a security incident, investigates attacks and preserves its legal value for insurers, regulators and courts.
Read more
The Cyber Resilience Act sets EU-wide cybersecurity requirements for products with digital elements. Scope, obligations and timeline at a glance.
Read more
ISO 42001 is the first certifiable standard for AI management systems. Structure, core requirements, its link to the EU AI Act and ISO 27001 integration.
Read more
The EU AI Act regulates artificial intelligence on a risk basis. We explain the risk classes, obligations, application timeline and first steps.
Read more
KRITIS, BSIG obligations and the new KRITIS Umbrella Act: who is affected, which audits and reporting duties apply – and what operators should do now.
Read more
How to build a security awareness programme that works: target groups, methods, regularity and measurable KPIs instead of a tick-box annual training.
Read more
When does a company need an information security officer? The role and tasks, and when an external ISO or CISO as a Service is the right choice.
Read more
NIS2 extends cybersecurity obligations to thousands of companies. Who is affected, which duties apply – and what does Germany's NIS2UmsuCG now require?
Read more