Blog

Practical knowledge from operations: IT security, compliance and infrastructure for mid-sized companies – written by the people who build it.

Since January 2026 · New articles appear regularly

  1. Security incidentBerlin State Network: What Lay Between All-Clear and Leak
  2. CRA Reporting from 11 September: What Must Be in Place
  3. SonicWall SMA1000: Critical Flaws, Actively Exploited
  4. TerminalFix: When Employees Paste the Attack Themselves
  5. Security incidentWhen the District Grinds to a Halt: Why Municipalities Become Targets
  6. EU AI Act: What Applies to Your Company Since August 2026
  7. Cloud Repatriation: When Moving Back In-House Pays Off
  8. VMware Licensing Costs Under Broadcom: Proxmox as an Alternative – Soberly Assessed
  9. Public AI or Your Own Model? The Right Mix
  10. AI on Your Data Is a Security Task: Why RAG Systems Leak Data
  11. Servers in Your Own House, Security from the Data Center
  12. Before Copilot Searches Your File Store: Clean Up Permissions
  13. NIS-2 Is Now Live: What Companies Must Catch Up On
  14. Cyber Resilience Act: Reporting Obligation from September 11, 2026
  15. Cisco FMC: Hardcoded Account Under Active Exploitation (CVE-2026-20316)
  16. Windows 10: The Free Extension Does Not Apply to Businesses
  17. TISAX 2027: What the New VDA ISA Catalog Means for Suppliers
  18. When the Attack Comes Through Your Service Provider
  19. Network Segmentation for Mid-Sized Businesses: Start Small, Big Effect
  20. Cisco SD-WAN Under Fire: Zero-Day Wave by UAT-8616
  21. PAN-OS in May 2026: Two Vulnerabilities, One Actively Exploited
  22. ISO 27001 for Mid-Sized Companies: A Realistic Way In
  23. What a NOC Really Delivers—and What It Doesn't
  24. DORA Affects Your IT Provider Too: Registers and Contracts
  25. F5 BIG-IP APM: CVE-2025-53521 Actively Exploited for Pre-Auth RCE
  26. Aruba AOS-CX: Admin Password Reset Without Login – CVE-2026-23813
  27. Immutable Backups: Why 3-2-1 Is No Longer Enough
  28. The First 60 Minutes After a Ransomware Discovery
  29. 950 Ransomware Attacks, 80% on SMEs: Lessons for Mid-Sized Companies
  30. Municipal Procurement in NRW: The Value Thresholds Are Gone
  31. IT Security Is a Board Matter by Law: § 38 BSIG for Managing Directors
  32. Review of 2025: The Year the Firewalls Themselves Became the Target

Questions about any of these topics?