Skip to content
SECURITYSQUAD

Information security knowledge: fundamentals, regulation, practice

Guides, fundamentals and key terms on information security – all in one place.

Information security is a broad field: compliance requirements like NIS2, technical standards like ISO 27001 and IT-Grundschutz, plus ever-evolving threats. In the Knowledge Hub we group our expertise by topic – from concise guides to the most important terms. So you quickly find the right starting point, whether you are building an ISMS, clarifying your NIS2 applicability or hardening your defences.

Topics

Knowledge by topic

Compliance & standards

Understand your obligations and meet them verifiably: NIS2, KRITIS, ISO 27001 based on IT-Grundschutz and the role of the (external) ISB.

Regulation & AI governance

Stay ahead of new EU rules: the EU AI Act, ISO 42001 and the Cyber Resilience Act – what's coming for organisations.

Threats & defence

How current attacks work – and how to address ransomware, phishing and the human factor effectively, through to IT forensics when it counts.

Architecture & hardening

From the perimeter to Zero Trust: concepts and measures that make life hard for attackers.

Managed security & cloud

Continuous monitoring and secure cloud use – even without your own SOC team.

Glossary

Key terms, briefly explained

NIS2
EU directive that extends cybersecurity and reporting duties to many more organisations – including many mid-sized companies via supply-chain requirements.
ISO 27001
International standard for information security management systems (ISMS). Certification proves a systematic, auditable approach to risk.
IT-Grundschutz
The German BSI methodology that backs ISO 27001 with concrete, practical building blocks – the common basis for certifications in the DACH region.
DIN SPEC 27076
A standardised procedure for a lightweight cyber risk check, tailored specifically to small and medium-sized organisations.
Zero Trust
Security model based on “never trust, always verify”: every access is verified – regardless of whether it originates from the internal network.
SIEM & SOC
A SIEM collects and correlates security-relevant log data; a SOC is the team that responds to it around the clock. Together they enable near real-time threat detection.
Penetration test
A controlled attack on your own systems to find exploitable weaknesses before real attackers do.
Ransomware
Malware that encrypts data and extorts a ransom. Effective protection combines prevention, detection and a tested backup concept.
KRITIS
Critical infrastructure – entities whose failure would endanger essential supply. Operators face specific proof and reporting duties (BSIG); the KRITIS umbrella law adds physical protection.
EU AI Act
The EU's AI regulation governs artificial intelligence by risk – from prohibited practices and high-risk duties to transparency requirements.
ISO 42001
International standard for AI management systems (AIMS) – a structured framework for AI governance, analogous to ISO 27001 for information security.
Cyber Resilience Act (CRA)
EU regulation setting cybersecurity requirements for products with digital elements: security by design, vulnerability management and reporting across the lifecycle.
IT forensics
Court-proof preservation and analysis of digital traces after a security incident – establishes what happened and secures evidence.