Blog
Latest articles on information security, compliance and GRC

Who Needs ISO 27001 Certification? The Complete 2025 Guide
NIS2 makes ISO 27001 relevant for thousands of companies. Learn when certification is mandatory, when it is strategically beneficial, and which alternatives you can choose from.

ISO 27001 vs. TISAX®: The Ultimate Comparison for 2025
ISO 27001 or TISAX® - which standard is right for your company? Learn the crucial differences, commonalities, and when you need both standards.

KRITIS in the Compliance Jungle: Successfully Leveraging Synergies Between Laws and Standards
Navigate the compliance jungle: Leverage legal and standard synergies to make KRITIS efficient and secure.

NIS2 Reporting Requirements in Government Draft: What Companies Need to Know Now
The NIS2 government draft introduces a four-stage reporting procedure. Learn which deadlines apply, who is affected, and how to prepare.

IT-Grundschutz++ 2025: The Revolutionary Path to Measurable Cybersecurity
Measurable CIA metrics instead of checklists, 5-tier system for all company sizes, and continuous GitHub-based development. Learn how the BSI introduces the paradigm shift from static to dynamic security with this framework.

What is the PDCA Cycle? The Complete Guide for ISO 27001 & BSI IT-Grundschutz
The PDCA cycle forms the methodological foundation for continuous improvement in ISO 27001 and BSI IT-Grundschutz. Learn how this iterative four-step approach systematically optimizes your information security and creates a culture of continuous development.

Are Your Service Providers Secure? The Value of Strong Third-Party Risk Management
Are your service providers secure? Third-party vendors are increasingly at the center of cyber incidents. Learn why strong third-party risk management is essential and how organisations can evaluate, document and control supplier risks effectively.

What is ISO 42001? The First International Standard for AI Management Systems
ISO 42001 is the world's first certifiable standard for AI management systems. Learn how it helps organizations use AI responsibly, manage risks, ensure transparency, and comply with regulations like the EU AI Act and GDPR.

Does NIS2 Apply to You? Overview with Infographic
Does NIS2 apply to your organisation? With the new EU directive, cybersecurity becomes mandatory for more sectors than ever. This overview explains criteria, affected industries, exceptions and how to determine your NIS2 status.

Transparency for AI: Why We Need an SBOM for AI
AI systems are becoming more complex and opaque. An SBOM for AI brings transparency to models, data and components—strengthening security, supporting audits and building trust across the entire AI supply chain.

KRITIS Identification – Does My Organization Fall Under KRITIS?
KRITIS Identification – Does my organization fall under KRITIS? Companies must assess whether they operate critical infrastructure and meet the thresholds defined in the KRITIS Regulation.

What Constitutes Critical Infrastructure? The Complete KRITIS Guide 2025
KRITIS (Critical Infrastructures) are essential for the functioning of society. Learn which 9 sectors fall under KRITIS, what thresholds apply, and what obligations operators must fulfill – including NIS2 requirements.