When It Hits the Fan: Why Your Incident Policy is Useless Without a Playbook

When It Hits the Fan: Why Your Incident Policy is Useless Without a Playbook

. . If you are running a 50-user small business, an emergency phone list and a hard rule to “pull the internet plug” might just save your neck during a cyberattack. But if you are operating in the upper mid-market, the enterprise sector, or critical infrastructure (KRITIS), relying on improvised emergency responses is operational suicide. I have spent decades building Security Operations Centers and optimizing ITIL processes for highly complex environments, including international telecom providers and clinical infrastructure. I have […]

The Cybersecurity Bullshit Bingo: Stop Buying Snake Oil and Start Doing Your Job

The Cybersecurity Bullshit Bingo: Stop Buying Snake Oil and Start Doing Your Job

.. Let’s not mince words: The cybersecurity industry is utterly broken, and the primary culprits are the vendors peddling snake oil to terrified executives. If you have ever sat in a boardroom listening to a security software pitch, you know the drill. A slick sales rep in a tailored suit fires off a barrage of buzzwords—”Advanced Persistent Threats,” “Next-Gen,” “AI-Driven,” “Zero-Trust”—designed to do exactly one thing: scare you into opening your company’s checkbook. I have been navigating this industry for […]

ISO 27001: No-Bullshit Implementation – Cutting Through the Documentation Nightmare

ISO 27001: No-Bullshit Implementation – Cutting Through the Documentation Nightmare

. . Mention “ISO 27001” in a boardroom, and you can usually watch the collective life drain from the management team’s eyes. The immediate association is always the same: endless months of consultant interviews, massive Excel matrices, and hundreds of pages of abstract policies that nobody will ever read, let alone understand. Many Small and Medium-Sized Enterprises (SMEs) view an Information Security Management System (ISMS) purely as a painful, paper-pushing exercise required to get a certificate on the wall to […]

AI in Security Architecture: The New Attack Vectors and How to Survive Them

AI in Security Architecture: The New Attack Vectors and How to Survive Them

. . The cybersecurity industry is currently drowning in Artificial Intelligence marketing. Every vendor suddenly offers an “AI-driven” appliance or software platform guaranteed to solve all your security problems. Let me be perfectly blunt: buying a black box simply because it has an “AI” sticker on it will not save you. However, ignoring the technology is not an option either. We are in the middle of a massive arms race, and the attackers are currently moving faster than the defenders. […]

Modern Incident Management: Surviving the Worst-Case Scenario in Critical Infrastructure

Modern Incident Management: Surviving the Worst-Case Scenario in Critical Infrastructure

… When a ransomware syndicate breaches a manufacturing plant, it is a massive financial disaster. But when that same attack hits a hospital or critical infrastructure (KRITIS), we are no longer just talking about downtime and lost revenue. We are talking about patient safety, disrupted emergency care, and potentially life-or-death situations. Despite these high stakes, the incident management processes I frequently encounter in clinical environments are dangerously unsuited for a severe cyber crisis. The core issue lies in a misunderstanding […]

The Virtual CISO: Why SMEs Need C-Level Strategic Security, Not Just More Tools

The Virtual CISO: Why SMEs Need C-Level Strategic Security, Not Just More Tools

. . Let’s stop pretending that buying more security tools equals actual security. Most mid-sized companies today have moved past the naive era of relying solely on a basic firewall and an off-the-shelf antivirus. Today, I usually see Endpoint Detection and Response (EDR) agents deployed, Multi-Factor Authentication (MFA) enforced, and perhaps some cloud-based threat protection running in the background. But despite this arsenal, they are still being compromised. Why? Because they are accumulating technology without a strategy. Management often delegates […]

The SecretPi – The secret agent privacy guard for Managers, Reporters, Dissidents and People like you and me, keeps nosy people out.

The SecretPi – The secret agent privacy guard for Managers, Reporters, Dissidents and People like you and me, keeps nosy people out.

The Motivation (How the SecretPi came to be) Whilst creating a Raspberry Pi3B for a friend in Turkey, who want’s to watch German TV programs over the internet and do not want to have the Government monitoring his behaviour (mail, browsing etc.), an idea came to my mind. As my friend only needs a VPN which is maintained by the Raspberry and automatically starts where ever / when ever he is connected to the internet via his DSL Router, I […]

Are SIEM’s dead ?

Are SIEM’s dead ?

The SIEM is dead….cause we killed it ! When I came first in contact with a SIEM, namely the SOC-Product from Computer Associates about 2004, my colleagues and I said “Wow, that’s the way to go !”. With log-file collection, correlation and the way how it was visualized it would definitely help customers to analyze their data better and faster, to detect attacks. Anyway at this time we had less log-sources, no BYOD and so on. But I had my […]

Digitization – the big challenge for IT security

Digitization – the big challenge for IT security

While I was researching for this blog article, I realized that digitization is currently on everyone’s lips, used in many ways, actually only the umbrella term for the change in our society, in which everything – both in the private and in the corporate sector – becomes faster and closer meshed without being aware of the impact on society. So, as I write in the blog articles for companies, we should actually take a closer look at the term “digital […]

The SOC methodology

The SOC methodology

First, let the extract of an SOC workflow (next graphic) takes effect on you (the shift transfer, the daily routine tasks and the end of the shift are missing for a better overview). Please remember, the SOC handles the fast processing of events. If these are known – or easy to solve – this is forwarded from the SOC to the relevant division (IT-Security, Networking, Servers etc.). If events are not easy to solve or completely unknown, they will be […]