News & Insights
We are your first port of call for the latest news, analysis and background information on data protection, data strategy and IT security. We keep you informed with editorially prepared news and interesting facts. Subscribe directly to our newsletter and never miss a thing again.
05.08.2026
The 10 most important questions about data strategy
Data are, or should be, the most important foundation for business decisions in every company. Whether in marketing, finance, product development or HR, solid figures and facts lead to better outcomes. To achieve this, however, data must also be structured and accessible. That is only possible with a well-designed data strategy. We have summarised the 10 most important questions on this topic for you.
Read more … The 10 most important questions about data strategy
28.07.2026
The 4 most common reasons why ISO 27001 certifications fail
ISO 27001 certification rarely fails at the external audit stage; it fails at an earlier stage. ISO projects are often only worked on when there are no other urgent tasks in the company. If you want to ensure the success of your ISO 27001 project, there are a few decisive factors that have proven themselves time and again in practice.
Read more … The 4 most common reasons why ISO 27001 certifications fail
21.07.2026
Microsoft 365 & data protection: identify risks, implement measures and work in compliance with the GDPR
Whether Microsoft 365 can be used in compliance with data protection law cannot be answered with a blanket yes or no. What matters is the specific way in which it is used in the respective company. The situation has improved since 2022, but parts of the criticism previously raised by supervisory authorities remain. We explain the actual risks, the current position of the authorities and the measures that matter now.
16.07.2026
NIS2 Tools for SMEs: why tools help, but cannot buy compliance
No tool automatically makes a company NIS2-compliant. Tools only accelerate implementation if risks, responsibilities and processes have been clarified first. We show which tool categories you really need, what a pragmatic basic stack looks like and which questions you should answer before making any purchase.
Read more … NIS2 Tools for SMEs: why tools help, but cannot buy compliance
03.07.2026
Data protection & IT security in M&A: review framework for data value, risks and deal implications
Data increases enterprise value only if it is economically usable, legally exploitable and technically protected. Missing legal bases, weak IT security or unclear data quality can turn what appears to be a value driver into a concrete deal risk. We explain how private equity investors and deal teams can systematically assess data value, data protection and IT security in due diligence and translate the findings into concrete deal mechanics.
25.06.2026
Deploying AI agents lawfully: fom hallucination risks to privacy by design
AI agents can perform tasks independently, make decisions and interact with IT systems — and that is precisely what makes them challenging from a compliance perspective. Deleted databases, legally binding chatbot statements and autonomous smear campaigns show that the risks are no longer theoretical. We explain which legal requirements apply and how companies can use AI agents in a legally compliant manner.
Read more … Deploying AI agents lawfully: fom hallucination risks to privacy by design
04.06.2026
Cookie banners in 2026: what must they be capable Of and Is reform on the horizon?
Cookie banners are intended to safeguard data protection, yet many users now click “Accept” out of sheer frustration. At the same time, pressure for reform is growing at EU level. What does this mean for companies? And what requirements actually apply today? An overview of the legal framework, practical challenges, and available courses of action.
Read more … Cookie banners in 2026: what must they be capable Of and Is reform on the horizon?
29.05.2026
7 tips for more efficient data protection: why less Is sometimes more
Data protection does not have to be cumbersome in order to work in a legally robust way. Companies that clarify roles, simplify processes and prioritise risks in a targeted manner relieve the burden on data protection teams and make data protection more effective across the organisation.
Read more … 7 tips for more efficient data protection: why less Is sometimes more
20.05.2026
Vulnerability management: AI forces companies to rethink
The German Federal Office for Information Security (BSI) is warning that AI-supported systems could soon be able to identify security vulnerabilities at scale. For companies, this is no longer a future scenario. It is a reason to fundamentally rethink vulnerability management now. And the CRA clock is already ticking.
Read more … Vulnerability management: AI forces companies to rethink
12.05.2026
The external CISO in the financial sector: between DORA, cyber risks and ICT risk management
Financial institutions are under particular pressure: cyber risks are increasing, DORA is tightening requirements, and the management body remains responsible. An external CISO can help establish information security in a strategic, pragmatic and audit-ready way.