Blog
Latest articles on information security, compliance and GRC

4 information security measures you can still implement before year-end
4 information security measures you can still implement before year-end. As 2024 draws to a close, IT teams can use the year-end period to secure budgets, strengthen backups, improve password security and lay the foundation for a structured ISMS for 2025.

What is an ISMS Tool?
Discover how an ISMS tool helps IT security professionals minimize risks and efficiently ensure compliance.

SOC 2 Costs 2024: Budget for Complete Compliance
SOC 2 Costs 2024: Plan and budget for a complete compliance strategy. Why SOC 2 matters and what companies should expect when preparing for certification.

The 7 Most Important Cybersecurity Trends for 2024
Discover the critical cybersecurity trends of 2024: From GenAI to third-party risks—stay proactive and protect your business effectively!

IT Security Situation 2024: Key Findings from the Latest BSI Report
IT Security Situation 2024: Key findings from the latest BSI report. The threat landscape is becoming more dynamic, attacks on critical infrastructure are increasing and many organisations still lack sufficient digital resilience.

9 Benefits of ISO 27001 Certification
Discover how ISO 27001 certification strengthens your security strategy and proactively shields you against cyber threats.

How Long Does ISO Certification Take?
Discover how efficient ISO certification boosts your IT security and unlocks new business opportunities.

What Is a Virtual CISO (vCISO) – And Does Your Team Need One?
What is a virtual CISO (vCISO) and does your team need one? Many organizations cannot afford a full-time CISO but still need strategic security leadership. This article explains the vCISO role, benefits and when it makes sense to bring one on board.

BSI IT Baseline Protection vs. ISO 27001: An Overview of the Differences
Uncover the differences between BSI IT-Grundschutz and ISO 27001 to discover which approach best enhances your IT security.

SOC 2 vs. ISO 27001: Which security standard is right for you?
SOC 2 vs. ISO 27001: Which security standard is right for you? SOC 2 and ISO 27001 are the most commonly chosen compliance standards. Nevertheless, many companies ask themselves...

Audit Readiness Assessment: Everything You Need to Know
Audit Readiness Assessment Data breaches cost companies an average of $4.88M this year. Preparing for audits helps close security gaps, reduce risks and ensure compliance with standards like ISO 27001, IT-Grundschutz or NIS2.

What Is IT-Grundschutz++?
IT-Grundschutz++ is the modernized security framework of the German BSI, launching in 2026. It introduces machine-readable JSON structures, reduces complexity, and enables more efficient, automated implementation of information security controls.