NIS2 for Mid-Sized Companies: Directive, Duties & Compliance
Read articleInformation security knowledge: fundamentals, regulation, practice
Guides, fundamentals and key terms on information security – all in one place.
Information security is a broad field: compliance requirements like NIS2, technical standards like ISO 27001 and IT-Grundschutz, plus ever-evolving threats. In the Knowledge Hub we group our expertise by topic – from concise guides to the most important terms. So you quickly find the right starting point, whether you are building an ISMS, clarifying your NIS2 applicability or hardening your defences.
Knowledge by topic
Compliance & standards
Understand your obligations and meet them verifiably: NIS2, KRITIS, ISO 27001 based on IT-Grundschutz and the role of the (external) ISB.
Regulation & AI governance
Stay ahead of new EU rules: the EU AI Act, ISO 42001 and the Cyber Resilience Act – what's coming for organisations.
Threats & defence
How current attacks work – and how to address ransomware, phishing and the human factor effectively, through to IT forensics when it counts.
Ransomware: prepare, detect, act when it happens
Read articlePhishing: why awareness training alone is not enough – and what actually helps
Read articleSecurity Awareness Training: how to build a programme that works
Read articleCyber threats 2026: what companies should prepare for now
Read articleIT Forensics: securing traces, investigating incidents
Read articleArchitecture & hardening
From the perimeter to Zero Trust: concepts and measures that make life hard for attackers.
Zero Trust: from buzzword to workable strategy – and what becomes of the VPN
Read articleSystem hardening with CIS Benchmarks: factory settings are open doors
Read articlePenetration testing: finding weaknesses before someone else does
Read articlePrioritising vulnerabilities: why a CVSS of 9.8 is not automatically urgent
Read articleManaged security & cloud
Continuous monitoring and secure cloud use – even without your own SOC team.
Key terms, briefly explained
- NIS2
- EU directive that extends cybersecurity and reporting duties to many more organisations – including many mid-sized companies via supply-chain requirements.
- ISO 27001
- International standard for information security management systems (ISMS). Certification proves a systematic, auditable approach to risk.
- IT-Grundschutz
- The German BSI methodology that backs ISO 27001 with concrete, practical building blocks – the common basis for certifications in the DACH region.
- DIN SPEC 27076
- A standardised procedure for a lightweight cyber risk check, tailored specifically to small and medium-sized organisations.
- Zero Trust
- Security model based on “never trust, always verify”: every access is verified – regardless of whether it originates from the internal network.
- SIEM & SOC
- A SIEM collects and correlates security-relevant log data; a SOC is the team that responds to it around the clock. Together they enable near real-time threat detection.
- Penetration test
- A controlled attack on your own systems to find exploitable weaknesses before real attackers do.
- Ransomware
- Malware that encrypts data and extorts a ransom. Effective protection combines prevention, detection and a tested backup concept.
- KRITIS
- Critical infrastructure – entities whose failure would endanger essential supply. Operators face specific proof and reporting duties (BSIG); the KRITIS umbrella law adds physical protection.
- EU AI Act
- The EU's AI regulation governs artificial intelligence by risk – from prohibited practices and high-risk duties to transparency requirements.
- ISO 42001
- International standard for AI management systems (AIMS) – a structured framework for AI governance, analogous to ISO 27001 for information security.
- Cyber Resilience Act (CRA)
- EU regulation setting cybersecurity requirements for products with digital elements: security by design, vulnerability management and reporting across the lifecycle.
- IT forensics
- Court-proof preservation and analysis of digital traces after a security incident – establishes what happened and secures evidence.