Cyber insurance 2026: what insurers now demand from SMEs
🤖 AI-assisted content, editorially reviewed.
A topic I've noticeably run into more often in client conversations during 2026: cyber insurance. Here's a vendor-neutral explainer, without recommending any particular insurer or broker.
The market is tightening: the German Insurance Association (GDV) has now presented model terms for cyber insurance, specifically tailored to companies with up to €50 million in annual revenue and up to 250 employees – exactly the size bracket I mostly work with.
Rejections are rising: according to market observations, almost one in three applications is now being rejected, noticeably more than the year before. The reason: after a wave of major ransomware losses, insurers have tightened their acceptance criteria considerably, and smaller companies in particular often lack the required security level.
The catch with proof requirements: even an existing policy doesn't automatically protect you. Broadly speaking, many providers now apply a rule along these lines: cover lapses retroactively to the extent that the technical and organisational measures assured in the risk questionnaire were not actually in place at the time of the claim.
What's actually required: multi-factor authentication everywhere, current patch management, EDR software, immutable backups following the 3-2-1-1-0 principle, a documented access-rights concept, demonstrable employee training, and an incident response plan. Many insurers now also specifically ask about NIS2 implementation status.
GDV model terms target companies up to €50m revenue / 250 employees
Around one in three applications is currently rejected
Cover can lapse retroactively if assured measures are missing
Standard requirements: MFA, patch management, EDR, 3-2-1-1-0 backup, training, incident plan
My tip: actually implement the measures assured in the risk questionnaire before signing – don't just tick the boxes. In a claim, that's exactly what gets checked, and it's exactly what decides whether the insurer really pays out.
Practice ·
Why computers, servers and storage are getting noticeably more expensive
🤖 AI-assisted content, editorially reviewed.
Anyone looking to buy a new computer, laptop or server right now notices it immediately in the price: costs have risen noticeably. The reason isn't the retailer – it's chip manufacturing itself.
What happened: memory (RAM) and SSD storage became more than twice as expensive in parts during 2026. The major memory manufacturers are increasingly shifting production toward specialised memory chips for large AI data centres – making ordinary memory for everyday computers and servers scarcer and pricier. Experts don't expect relief before around 2028.
My tip: if you have a purchase coming up anyway, I'd act sooner rather than later – a price drop isn't in sight for the next few years. It's also worth checking whether existing hardware can hold out a bit longer.
Cloud & Backup ·
3-2-1-1-0 backup strategy for SMEs
🤖 AI-assisted content, editorially reviewed.
Many people know the classic 3-2-1 rule: three copies of the data, on two different media, one of them stored off-site. In 2026 that has largely become 3-2-1-1-0: one of the copies must additionally be immutable – a so-called immutable backup that even an attacker with admin rights cannot later encrypt or delete. The zero stands for zero errors on restore, verified regularly.
Why the old rule is no longer enough: modern ransomware specifically hunts for backups and tries to encrypt them along with everything else before it strikes. An immutable backup stays intact even once the attacker already holds administrator rights on the network.
My practical tip: a backup only counts as protection once you have actually tested the restore – ideally in a quiet moment, not for the first time during a real incident.
Cloud & Backup ·
Microsoft 365 vs. Google Workspace: what fits SMEs?
🤖 AI-assisted content, editorially reviewed.
The honest answer: it depends heavily on your existing environment. Microsoft 365 is the standard among German SMEs, with deep integration into Windows environments, Active Directory and Intune. Google Workspace scores on simplicity and genuine real-time collaboration in Google Docs, and is often cheaper to get started with.
Three questions matter most: which systems are already in use? How heavily does the team rely on Excel and complex document templates? And is browser-based, collaborative work the priority?
My recommendation: look at how the team actually works day to day first, then pick the platform – switching later is possible, but it takes effort.
Cloud & Backup ·
Cloud cost trap: keeping AWS and Azure bills under control
🤖 AI-assisted content, editorially reviewed.
Cloud services such as Azure or AWS look cheap at first, because you only pay for what you actually use. That is exactly what turns into a trap: without ongoing oversight, bills grow unnoticed because forgotten test servers keep running or resources are sized bigger than they need to be.
What to do: run a monthly cost review instead of only looking at the annual bill. Set up automatic budget alerts. Consistently tag every resource to a project. And actually shut down test environments you no longer need – don't just pause them.
Practice ·
IT procurement for SMEs: buy, lease or rent?
🤖 AI-assisted content, editorially reviewed.
Three models are on the table: buying – a one-off investment, with the full failure risk carried yourself. Leasing – predictable instalments, often with a replacement guarantee, usually more expensive than the purchase price over the term. Hardware-as-a-service or renting – full flexibility, but the highest ongoing cost.
The decision mainly comes down to usage period and liquidity: if you use hardware stably for a long time and have capital available, buying is usually cheaper. If you want to grow quickly, leasing or renting pays off – including tax-wise, since instalments can often be deducted directly as an operating expense.
My advice: don't just look at the purchase price – look at the total cost across the entire usage period, including maintenance, support and end-of-life disposal.
Practice ·
IT contract management: what to look for in SLAs
🤖 AI-assisted content, editorially reviewed.
A service level agreement sets out in writing which performance an IT provider guarantees – and what happens if it fails to deliver. Without a clear SLA there is no solid basis in a dispute, only differing expectations.
Four points belong in every SLA: response time after an incident, maximum recovery time, a concrete availability guarantee in percent, and clear consequences for non-compliance. Vague wording such as "prompt handling" is worthless when it matters, because it cannot be measured.
My tip: don't just read contracts when you sign them – review them at least once a year. Requirements and provider performance change, and the contract should keep pace.
AI News ·
The agentic AI trend in 2026: when AI decides for itself
🤖 AI-assisted content, editorially reviewed.
2026 is the year AI systems move from being pure tools to acting as independent agents. China was one of the first governments to publish, in May, a concrete rulebook for AI agents: developers must disclose which decisions an agent makes fully autonomously, which need approval, and which stay with a human.
The major providers are repositioning too: OpenAI's new flagship Sol is explicitly built for "long-horizon agentic work," and Meta is pitching its own terminal-based coding agent, Muse Code, against Anthropic and OpenAI.
My practical tip: before giving an AI agent access to your systems, write down which actions it may take on its own and which need approval first – exactly the principle China is now mandating by law.
Compliance ·
NIS2 grace period expired: around a third of companies still missing
🤖 AI-assisted content, editorially reviewed.
An important deadline passed at the end of July: the grace period the German BSI granted for NIS2 registration ended on 31 July 2026.
The numbers: of roughly 29,500 affected companies and public bodies, only about 19,000 had registered by then – around 11,000, nearly a third, are still missing. The actual statutory deadline had already passed back in March 2026, so those affected have formally been in breach since then.
Companies with 50 or more employees, or €10 million or more in annual revenue, in certain sectors such as energy, healthcare, IT or manufacturing are affected.
My tip: even though the grace period has passed, registering is still possible and explicitly recommended. If you're still unsure whether you're affected, get that clarified soon.
Security ·
Quantum computers and encryption: what businesses should know now
🤖 AI-assisted content, editorially reviewed.
A topic that still sounds abstract but is slowly becoming relevant: future quantum computers could eventually be able to break the encryption that virtually all encrypted internet traffic relies on today.
What's already happening: standards bodies have already finalised new encryption methods designed to resist this. Large organisations and government agencies are now starting to migrate step by step – a process that can take large enterprises eight to fifteen years, according to experts. For the vast majority of small and medium-sized businesses, there's no urgent action needed right now.
My tip: no need to worry today. But when you next buy new security software, a firewall, or a VPN, it's worth asking whether the vendor already has these new quantum-safe methods on its roadmap.
AI News ·
Open-weight models on the rise: Kimi K3 & DeepSeek V4-Flash
🤖 AI-assisted content, editorially reviewed.
Moonshot AI has released Kimi K3, the largest freely available model with open weights to date: 2.8 trillion parameters, a one-million-token context window, and a licence that permits commercial use. Shortly before that, DeepSeek officially released its V4-Flash model, which had already spent weeks as the most-used model on the OpenRouter platform.
Important in practice: "open-weight" means the model weights can be downloaded and self-hosted – but the training data and code usually remain closed. For companies that value data control or self-hosting, this is becoming a serious alternative to the closed cloud models.
AI News ·
New AI models in July: Claude Opus 5, Gemini 3.6 Flash & more
🤖 AI-assisted content, editorially reviewed.
A few days in July 2026 noticeably reshuffled the AI landscape: Anthropic released Claude Opus 5, a new flagship that comes close to its own top-tier intelligence at half the price of its predecessor. Almost simultaneously, Google brought out Gemini 3.6 Flash as a more efficient workhorse with a one-million-token context window.
Kimi K3 from Moonshot AI and DeepSeek V4-Flash followed – two strong open-weight models out of China. For businesses, that means the choice of models at different price-performance points has rarely been bigger than it is now.
Security ·
7-Zip: two flaws within a few months – don't forget to update
🤖 AI-assisted content, editorially reviewed.
7-Zip is one of the most widely used archiving tools around – and in 2026 it was hit by two serious vulnerabilities. In April a flaw in extracting certain archives came to light (fixed in version 26.01); in July a further one affecting specially crafted XZ files (fixed in version 26.02). In both cases, simply opening or extracting a manipulated archive file was enough to execute malicious code.
What to do: unlike many other programs, 7-Zip does not update itself. A quick check of the installed version and a manual update where needed is usually all it takes. Archives from unknown sources – especially email attachments – should be opened with caution regardless.
AI & Law ·
EU AI Act: first obligations apply from August
On 2 August 2026 the next stage of the EU AI Act takes effect for me and my clients – and it is a significant one. What I find most relevant are the new transparency duties: AI-generated or significantly altered content must, in certain cases, be clearly labelled.
What I keep encountering in conversations: many people assume this only affects developers of AI systems. In fact, it explicitly also covers companies that merely use AI – for example in recruiting, accounting or customer service.
Transparency and labelling duties from 2 August 2026
High-risk obligations postponed (Annex III to December 2027)
Supervisory authority in Germany: the Federal Network Agency
Fines up to €15m / 3% – up to €35m / 7% for prohibited practices
My practical tip: build an AI inventory, clarify responsibilities and introduce simple labelling for AI content. I am happy to help you with that.
Security ·
Citrix NetScaler: CitrixBleed is back
🤖 AI-assisted content, editorially reviewed.
NetScaler appliances handle remote access and single sign-on for many companies. In late June 2026, Citrix disclosed a flaw (CVE-2026-8451) from the same family as the notorious CitrixBleed of previous years: crafted requests could read memory fragments from the device without any login, in the worst case including session data. The first attacks started within 24 hours of disclosure.
What to do: install the Citrix-provided update immediately. If that isn't possible right away, temporarily disable the SAML feature on the device to remove the specific attack surface. After patching, reset all existing sessions as a precaution.
Security ·
Adobe ColdFusion: maximum-severity flaw, exploited within two hours
🤖 AI-assisted content, editorially reviewed.
Adobe ColdFusion is still used by quite a few companies for older web applications. In late June 2026 Adobe patched a flaw with the maximum possible severity score of 10 out of 10 (CVE-2026-48282): an insufficiently validated path allowed attackers to run their own code on the server with no login at all. Security researchers recorded the first exploitation attempt just two hours after the patch was released.
What to do: update immediately to the fixed version (affected versions are ColdFusion 2025 up to Update 9 and ColdFusion 2023 up to Update 20). Also check whether the vulnerable service needs to be reachable from the internet at all. Since working exploit code is already circulating publicly, this update shouldn't be delayed.
Security ·
TP-Link routers: flaw exploitable without any password
🤖 AI-assisted content, editorially reviewed.
In June 2026, TP-Link disclosed a flaw (CVE-2026-11834) in several router models: through the DHCP configuration, an attacker on the same network could run their own commands with the highest privileges, without any password. Devices in factory state or without a completed initial setup are hit hardest.
What to do: download and install the current firmware directly from TP-Link's website for your specific model – routers don't update themselves. As a general rule: set up every new router with your own password right after unboxing, instead of leaving it on the network in its factory state.
Security ·
Ubiquiti UniFi OS: three critical flaws, fully exploitable in combination
🤖 AI-assisted content, editorially reviewed.
Ubiquiti UniFi is one of the most popular network solutions, especially among smaller companies. In June 2026, three critical vulnerabilities in the UniFi OS Server came to light (CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910), two of them with the maximum possible severity score of 10 out of 10. Combined, they were exploitable with no login at all: an attacker could bypass authentication, access sensitive files, and ultimately take full control of the device.
Active exploitation confirmed: affected are UniFi OS Server versions 5.0.6 and earlier. US agency CISA added the flaws to its list of actively exploited vulnerabilities on 23 June 2026 – a clear sign that real attacks were already underway.
What to do: update immediately to UniFi OS Server 5.0.8 or later. Check whether the management interface is unnecessarily reachable from the internet, and if you suspect compromise, rotate all credentials and certificates on the affected setup.
My tip: precisely because UniFi devices often run on a "set up once and forget" basis, it's worth checking the controller software's update centre on a regular schedule.
Security ·
Ivanti Sentry: flaw with a maximum severity of 10 out of 10
🤖 AI-assisted content, editorially reviewed.
Ivanti Sentry manages secure access for mobile devices at many companies. In June 2026 a flaw with the maximum possible severity score of 10 out of 10 came to light (CVE-2026-10520): attackers could run commands with the highest privileges with no login at all. Internet-facing systems were compromised within a very short time – US authorities had to patch within three days.
What to do: update immediately to the fixed versions provided by the vendor. Check whether the system needs to be reachable from the internet at all. If you suspect compromise, investigate the entire device management setup, not just patch the one server.
Compliance ·
Cyber Resilience Act: 24-hour reporting from September
With the Cyber Resilience Act (CRA), I am watching one of the most significant changes in years take shape: for the first time, EU-wide mandatory security requirements for products with digital elements – from software to connected devices.
The first hard deadline is worth marking in your calendar: from 11 September 2026, actively exploited vulnerabilities and serious incidents must be reported to the BSI within 24 hours.
From 11 Sep 2026: 24-hour reporting duty
From 11 Dec 2027: only CRA-compliant products with CE marking
Duties: security by design, software bill of materials (SBOM), documentation, vulnerability management
Applies to manufacturers, importers and distributors
My tip: if you place software or devices on the market yourself, check early which of your products are affected – I am happy to help you assess it.
Practice ·
Wi-Fi 7 in the office: is the upgrade worth it already?
🤖 AI-assisted content, editorially reviewed.
The next Wi-Fi generation, Wi-Fi 7, is spreading through businesses at a remarkable pace – faster than any previous Wi-Fi generation.
What's the benefit: Wi-Fi 7 is noticeably faster and more reliable than current technology, especially when many devices are connected at once or several video calls are running simultaneously. Surveys show many IT departments already plan a Wi-Fi upgrade for 2026.
Do I need to switch now? Not necessarily. For a smaller office with a manageable number of devices, current technology is often still fine for a while.
My tip: no need to rush – but if you're replacing old access points anyway, or your network is noticeably overloaded, I'd go straight for the new generation. The extra cost over older technology is usually modest.
Security ·
Windows Netlogon: domain controllers at risk
🤖 AI-assisted content, editorially reviewed.
Every Windows domain controller uses Netlogon. In May 2026, Microsoft patched a critical flaw in it (CVE-2026-41089): an attacker on the network could run their own code with system privileges on the domain controller without any login at all. Reports of active exploitation piled up shortly after the patch.
What to do: install the cumulative update from the May patch day immediately if you haven't already. Domain controllers should generally never be reachable directly from the internet. If you missed the patch, check the system event logs for unusual Netlogon activity.
Cloud & Backup ·
European cloud alternatives: why storing data in the EU matters more
🤖 AI-assisted content, editorially reviewed.
A topic that's gaining momentum: European alternatives to the big American cloud providers.
What it's about: around 70 percent of cloud services in Europe currently run through American providers such as Microsoft, Amazon or Google. Because US law can require access to data even when it's stored on servers in Europe, the EU is now actively funding European cloud providers that can demonstrably keep data within Europe.
Does this affect my business? Mostly relevant if you handle sensitive data, or have clients in regulated industries such as healthcare, finance or public administration. For many other smaller businesses, your current provider remains a perfectly reasonable choice.
My tip: ask your cloud provider specifically where your data is stored and which law applies – worth checking, especially for sensitive information.
Security ·
Ransomware figures 2026: over 33,000 attacks on small businesses in just four months
🤖 AI-assisted content, editorially reviewed.
A recent report delivers strikingly concrete figures: in the first four months of 2026 alone, over 33,000 ransomware attacks on small and medium-sized businesses were recorded.
Germany especially affected: with 433 confirmed ransomware attacks in 2025, Germany ranks among the three hardest-hit countries worldwide, behind the US and Canada. According to a Bitkom survey, 34 percent of German companies were affected within 12 months, and 15 percent have already paid a ransom.
A new scam: particularly devious are emails designed to look like official investigation documents, luring recipients into opening a password-protected attachment – once opened, malware installs itself in the background.
My practical tip: talk through this specific scam with your team – no one should open unexpected, supposedly official attachments. And test regularly whether your backup actually works when it matters.
Security ·
Security awareness training: what it does – and what it doesn't
🤖 AI-assisted content, editorially reviewed.
A term I keep running into in client conversations, understood very differently depending on who you ask: security awareness training. Time for a vendor-neutral explainer – without promoting any particular provider.
What it actually is: not a single product, but a training approach. Employees learn, through examples, simulated phishing emails and short learning units, to recognise suspicious messages and risky behaviour in everyday work. Many platforms from different vendors offer this – the underlying principle is similar across all of them, and none is the one objectively correct choice.
What it's good for: a recent study by G DATA CyberDefense, Statista and brand eins found that only 17 percent of employees feel confident they can reliably spot a dangerous email. Fittingly, roughly three-quarters of all security incidents are attributed to human error rather than missing technology.
Does it actually work: industry figures show that without training, employee phishing susceptibility in Europe sits at around 32 percent. After 90 days of continuous training it drops to about 20 percent, and after a year to roughly 5 percent. The key word is continuous: a single mandatory session once a year shows barely any measurable effect, by most accounts.
Not a product, but a training approach – can be implemented vendor-independently
Around 74% of security incidents are attributed to human error
Continuous training cuts phishing susceptibility from roughly 32% to roughly 5% after a year
A single annual session shows little effect
My tip: don't rely on a single mandatory annual session – use short, recurring units and realistic phishing simulations instead. The training format matters more than the vendor behind it.
Practice ·
Windows Server is getting more expensive – what that means for your next purchase
🤖 AI-assisted content, editorially reviewed.
If you're planning to buy a new server or renew licences soon, brace for higher costs.
What's changing: with the current version of Windows Server, list prices have risen roughly 10 to 20 percent compared with the previous version. Also new: pay-as-you-go billing through the cloud, instead of a one-time purchase price.
Is it worth it for smaller businesses? Depends on usage. If your demand fluctuates, the usage-based cloud option is sometimes cheaper. If you run a server permanently on-premises, a classic purchase is often still the better deal.
My tip: get a quote early, before your next purchase or contract renewal – with current price increases, comparing options pays off more than ever.
Security ·
Ransomware increasingly targets SMEs
The good news first: investigations have largely taken down major groups such as LockBit and Alphv. The bad news: in my observation, new groups form worryingly fast and rely on modular attack toolkits.
What strikes me most is the shift in targets – ransomware increasingly focuses on small and medium-sized businesses, exactly the clients I work with every day.
Offline or immutable backups – tested regularly
Consistent patch management, especially for internet-facing systems
MFA everywhere, above all for admin and remote access
Network segmentation and a rehearsed incident plan
My clear recommendation: the most effective protection is a backup an attacker cannot encrypt too – plus the certainty that recovery actually works. I test this regularly with my clients.
Security ·
Fortinet FortiClient EMS: attacks before the patch
🤖 AI-assisted content, editorially reviewed.
FortiClient EMS is the central management console for Fortinet endpoint software. In early 2026 a severe flaw came to light (CVE-2026-21643, maximum severity score): attackers could run their own commands on the server with no login at all – and it was actively exploited before many companies could patch.
What to do: update immediately to the fixed version provided by Fortinet. Check whether the EMS management interface really needs to be reachable from the internet – ideally it should only be accessible from the internal network or via VPN. If you patched late, review the logs from recent weeks for unusual activity around the EMS console.
Security ·
n8n: critical flaw in popular automation tool actively exploited
🤖 AI-assisted content, editorially reviewed.
n8n is one of the most popular platforms for automating workflows between different applications – especially for smaller companies building their own integrations without a large development team. In March 2026 the US cybersecurity agency CISA warned of active exploitation of a severe flaw (CVE-2025-68613, severity score 9.9 out of 10): n8n's expression evaluation engine could be abused to run arbitrary code on the server.
How big was the problem: according to security researchers, over 24,000 n8n installations worldwide remained unpatched and reachable at the time. The bug had already been fixed in December 2025 – anyone who hadn't updated promptly stayed vulnerable.
What to do: update to a patched version (1.120.4, 1.121.1 or 1.122.0 or later). If you self-host n8n, never leave the instance reachable from the internet unprotected, and secure access further.
My tip: automation and workflow tools like n8n often run quietly in the background for many clients and slip through patch management – tools exactly like this are worth checking for updates on a regular basis.
The three-month registration period under the German NIS2 Act ended on 6 March 2026 – and the numbers do not really surprise me: by then only about 11,500 of roughly 29,500 affected companies had registered.
The BSI has granted an extension until 31 July 2026. If you are affected, I would strongly encourage you to use this time.
Check whether you are affected: 50+ employees or €10m turnover in one of the 18 sectors
Complete your registration with the BSI
Document risk management and reporting processes
Management is liable – fines up to €10m
Unsure whether you are affected? A quick review of sector and key figures brings clarity fast – just get in touch with me.
Migration ·
VMware gets pricier: why many are now switching to alternatives
🤖 AI-assisted content, editorially reviewed.
A topic that keeps coming up in client conversations lately: frustration over VMware's pricing.
What VMware is: a widely used piece of software that lets businesses run several virtual servers on a single physical machine – a standard tool in many data centres.
What happened: since new owner Broadcom took over, one-time licences no longer exist, only subscriptions. Many customers have seen renewal prices rise several-fold, in some cases two to twelve times the previous amount. Many businesses are now evaluating alternatives such as Microsoft's Hyper-V or the open-source option Proxmox.
My advice: look at your next contract renewal date early, not just before it's due. As a vendor-neutral advisor, I'm happy to compare whether switching genuinely pays off in your case, or whether staying is cheaper.
AI News ·
OpenClaw: the viral AI agent that flooded the internet in February
🤖 AI-assisted content, editorially reviewed.
Hardly any tech topic was more present in February 2026 than OpenClaw – clients have asked me about it several times in recent weeks, sometimes under a slightly mixed-up name. Time for a clean explainer.
What it is: OpenClaw is an open-source, self-hosted AI agent by Peter Steinberger (founder of PSPDFKit), released in November 2025. It runs autonomously on your own computer or server, carrying out tasks independently – shell commands, browser control, file and calendar access – and can be operated through messaging apps such as WhatsApp, Telegram, Discord, Signal or iMessage. Completely free, no subscription, all you need is your own API key.
The name changed twice in quick succession: in late January 2026 the project had to rebrand to "Moltbot" following a trademark request from Anthropic – the earlier name sounded too close to "Claude" – then, just days later, to "OpenClaw".
How viral it got: over 60,000 GitHub stars within 72 hours, more than 200,000 by February, plus a marketplace of roughly 1,700 community-built extensions ("skills"). On 14 February 2026, Steinberger announced he was joining OpenAI – the project itself has since moved to independent open-source foundation governance.
Why I'd urge caution as an IT consultant: an agent that runs autonomously on your system with access to email, calendar, file system and company chats is no harmless toy. Security researchers have since published several analyses of privacy, security and ethical risks in OpenClaw – with a marketplace of thousands of unvetted community extensions, that's not a theoretical risk.
My tip: before you or your employees run such an agent with access to company email, chats or systems, know exactly which skills are installed and what data the agent can actually see. Fine for personal tinkering – in a business context, it needs vetting first.
AI News ·
Record funding: Anthropic at $380bn, OpenAI at $840bn
🤖 AI-assisted content, editorially reviewed.
On 12 February, Anthropic closed a $30bn funding round, valuing the company at $380bn – revenue climbed within a year from roughly $10bn to about $14bn on an annualised basis. Shortly after, OpenAI followed with a $110bn round led by Amazon, Nvidia and SoftBank, and is now valued at $840bn.
For customers and businesses relying on these providers, this is above all a question of stability: both are now exceptionally well capitalised for years to come.
Security ·
Passkeys: the end of the password?
In my view, passwords are the Achilles' heel of IT security. Passkeys (based on the FIDO2/WebAuthn standard) aim to change that, and I am rolling them out for more and more clients.
Instead of a secret, a passkey uses a cryptographic key pair on your device – unlocked by fingerprint, face or PIN. There is simply nothing left to phish.
Phishing-resistant: the key never leaves the device
Available in Windows, Apple, Android/Google and Microsoft 365
Convenient: no more passwords to remember
Ideal with clean device and identity management
My advice for getting started: begin with the most critical accounts (admin, e-mail, M365) and roll out step by step. I am happy to guide you through it.
Compliance ·
Outlook 2026: the IT duties heading for SMEs
To me it is clear: 2026 is becoming the year of IT regulation. Several EU rules take concrete shape – here is my overview:
31 July 2026 – NIS2: end of the BSI extension for registration
2 August 2026 – EU AI Act: transparency duties for AI content
11 September 2026 – Cyber Resilience Act: 24-hour reporting duty
Ongoing: rising vulnerability numbers and ransomware against SMEs
My advice: see these dates not as red tape but as a reason to tackle IT security in a structured way.
Compliance ·
Germany's NIS2 Act is in force – what applies now
The Bundestag passed the NIS2 Act on 13 November 2025, the Bundesrat confirmed it on 20 November. Upon promulgation it entered into force on 6 December 2025 – with no transition period, which caught quite a few of my clients off guard.
Around 29,500 companies across 18 sectors must now implement appropriate cybersecurity measures.
Mandatory registration with the BSI
Binding risk management and technical minimum measures
Reporting duty for significant security incidents
Management liability; fines up to €10m
For reference: you are affected from 50+ employees or €10m turnover in a regulated sector. If in doubt, I am happy to check this with you.
Security ·
BSI 2025 report: 119 new vulnerabilities – per day
The BSI 2025 report (July 2024 to June 2025) shows, very clearly, the scale of what I deal with in my daily work: on average 119 new vulnerabilities per day – up 24%.
For ransomware the BSI counted about 950 attacks. Taking down large gangs brought only brief relief; add APT groups and botnets such as 'Badbox'.
The attack surface grows faster than many can secure it
SMEs are increasingly targeted
Basics work: updates, MFA, backups, monitoring
Security is a process, not a project
My own assessment matches the BSI's core message: Germany remains vulnerable – especially where basic protection is missing. That is exactly where I start with my clients.
Migration ·
Double end of support: Windows 10 and Exchange 2016/2019
14 October 2025 is a big one – and I started preparing my clients for it months in advance: support ends for Windows 10 and for Exchange Server 2016 and 2019. Without updates these systems become a risk.
For Exchange, companies with their own mail server are hit hardest – it is the heart of communication.
Windows 10: check the move to Windows 11 (TPM 2.0!) or ESU/alternatives
Exchange: move to Exchange Online or upgrade to the Subscription Edition
ESU only as a bridge – a second period arrived in April 2026
Plan the migration path early: mailboxes, certificates, DNS, clients
No need to panic, but time to act: a planned migration path is cheaper than an emergency fix. I am happy to plan it with you.
Migration ·
Windows 10 end of support – act now
On 14 October 2025 support for Windows 10 ends – no updates, no fixes, no support. In my experience, a lot of clients still haven't got this on their radar.
The catch, as I always explain: many working PCs do not meet the Windows 11 requirements, especially TPM 2.0 and certain CPU generations.
Check whether the hardware is Windows 11 compatible
Weigh alternatives such as ESU or Linux
Deliberately keep older but capable devices in use
Move to a secure, future-proof state in good time
Need help with device checks and migration planning? I guide you from inventory to roll-out.
Practice ·
macOS vs. Windows in business – a comparison
Which system fits better – macOS or Windows? The honest answer I give my clients: it depends on the use case.
Criterion
Windows
macOS
Adoption
Very high, standard
Design, media, development
Cost
Wide choice, low entry
Higher entry price
Management
AD, Intune, GPOs
MDM such as Jamf, Mosyle
Security
Improved, popular target
Fewer attacks, more restrictive
My recommendation: office/ERP IT tends to Windows; design and app development tend to macOS. Mixed environments are possible but need a proper strategy.
To me, what matters is use case, IT team and budget – not personal preference.
Security ·
Zero trust: never trust, always verify
In modern IT security, I increasingly rely on zero trust – a model that never assumes trust, not even inside the internal network.
Principle: trust no one – verify everything
Every access is authenticated, authorised and logged
Micro-segmentation: services isolated, data flows controlled
Least privilege by default
To me, zero trust is not a product but an approach that I introduce with my clients step by step.
Security ·
Cyber attacks: new methods – how to protect yourself
Cybercriminals are getting more sophisticated – I see this in my work almost daily. Three trends stand out to me in particular:
AI-powered phishing e-mails: hard to tell from real ones
Attacks on IT providers/MSPs: many victims at once
Supply-chain attacks: malicious code via insecure tools/plug-ins
Security awareness training
Enable MFA everywhere
Software only from verified sources
Introduce the zero-trust principle
In my experience, people remain the number-one target – regular awareness training works best.
Security ·
MFA/2FA – duty or nice-to-have?
I now recommend multi-factor authentication (MFA/2FA) to every one of my clients – and it is increasingly mandatory too. Even if a password is compromised, access stays protected.
2FA: two factors, e.g. password + app code
MFA: even more, e.g. + fingerprint
Prime candidates: admin, e-mail/M365, VPN/RDP, cloud
GDPR (Art. 32): missing MFA can count as negligence
In my view, MFA is a simple step with big impact – for your security and your liability.
Practice ·
Leak alert: are your credentials affected?
Through hacks, phishing and leaks, credentials constantly end up online – something I see with my clients again and again. The good news: you can check for yourself whether you are affected.
Use check services such as 'Have I Been Pwned' with your e-mail
On a hit, change the password immediately
Never reuse passwords
Use a password manager, enable MFA
My tip: many browsers now warn automatically about compromised passwords – take these warnings seriously.
Compliance ·
NIS2 in practice: what companies must implement
NIS2 raises cybersecurity to a whole new level for many of my clients. Affected are companies with 50+ employees or €10m turnover in critical or important sectors.
Risk analysis: identify critical systems
Measures: patch management, access controls, encryption, BC