Blog
Latest articles on information security, compliance and GRC
SOC 2 vs. ISO 27001: Which security standard is right for you?
SOC 2 vs. ISO 27001: Which security standard is right for you? SOC 2 and ISO 27001 are the most commonly chosen compliance standards. Nevertheless, many companies ask themselves...
Audit Readiness Assessment: Everything You Need to Know
Audit Readiness Assessment Data breaches cost companies an average of $4.88M this year. Preparing for audits helps close security gaps, reduce risks and ensure compliance with standards like ISO 27001, IT-Grundschutz or NIS2.
What Is IT-Grundschutz++?
IT-Grundschutz++ is the modernized security framework of the German BSI, launching in 2026. It introduces machine-readable JSON structures, reduces complexity, and enables more efficient, automated implementation of information security controls.
ISO 27001 Certification: Process, Duration and Checklist 2026
ISO 27001 certification usually takes three to twelve months. This guide covers the process in eight phases, the checklist up to the audit and how to choose a certification body. As of 2026.
NIS2 Directive: What Companies Need to Know Now
The NIS2 Directive significantly tightens cybersecurity and incident reporting requirements across the EU. About 29,500 entities supervised by the BSI in Germany must implement risk management, ISMS and state-of-the-art security measures.