Latest from isidaten
Stay informed about the latest developments in data protection and information security.
New here every day. Follow along: RSS-Feed · LinkedIn · X
Looking for a specific date? The compliance calendar lists deadlines and events, each with its legal source.

Grandfathering stops at reporting
Everyone knows 11 December 2027 for the Cyber Resilience Act. The date that matters is 11 September 2026: that is the day the manufacturers' reporting obligations begin. And unlike the rest of the regulation, they come with no grandfathering.
Read more
Whoever nods has three spreadsheets
We travelled to DIGITAL X in Cologne with a question rather than a demo. What that changes about a trade fair day, and why the answer is usually on someone's face before they say anything.
Read more
Nine dimensions, one number
A risk analysis ends in a number. The matrix, the priority and the measure all follow from it. What it does not say is what kind of damage is meant. Why the maximum principle stays the default and a weighted average is a decision you have to justify.
Read more
Half a year of green
A device with no findings and a device with no configuration look identical on a dashboard. That error ran for half a year in our own agent. What we built so the next one shows up within a week.
Read more
How bad is not how fast
Basic terms, part 2: protection needs assessment and business impact analysis both ask about damage, but about different damage. One has no clock, the other lives by it. Why the BSI itself warns against merging them, and what separates normal operation from emergency operation.
Read more
Four minutes, six solutions
On 8 September we will be at DIGITAL X in Cologne, in the Startup Harbour along the Rhine promenade. Three times a day there is business speed dating: six solutions in thirty minutes, four minutes per provider, no registration. What we show in those four minutes.
Read more
Keeping is not contacting
After a trade fair the contacts are there, and the question is usually whether you may keep them. That is the easier half. Why the GDPR permits storage, why German unfair-competition law still blocks the marketing email, and why the B2B relief is missing exactly there.
Read more
There is no expiry date for .de
DENIC publishes neither expiry date nor transfer lock for .de domains, while the registry returns both for .com. What that means for renewal reminders, and why an empty date field deliberately triggers no due date but is counted as a gap of its own.
Read more
The locking system only knows today
Who can unlock a door today is in the system. Who could yesterday, and why that ended, is not. Why a withdrawn authorisation is revoked rather than deleted, and why a deleted record proves nothing in an audit.
Read more
Microsoft is not a cloud service
One line in the supplier directory does not answer the cloud question: Exchange Online, Teams and Entra ID are three services with different data locations and exit routes. Why OPS.2.2 requires a reference object per service, and what a rehearsal date on the exit achieves.
Read more
A device list is not a network diagram
The inventory knows four hundred devices and not a single connection. Edges do not live in the inventory but in the devices' own neighbour tables. Why an SNMP query alone is not enough, and what an import fundamentally cannot deliver.
Read more
Three days before the deadline
On 8 September we are at DIGITAL X in Cologne, all three founders. Three days later the first binding obligation of the Cyber Resilience Act takes effect. And anyone who sat at our table in July would have seen a different product.
Read more
A threat is not a hazard
Basic Terms, part 1: threat, vulnerability, hazard and risk build on one another in IT-Grundschutz and mean four different things. Plus the term the BSI abolished in 2017 that almost everyone still uses.
Read more
The NDA obligation stays open
Ticking the "NDA required" box gets nothing done. Until a signature is recorded, the project keeps flagging the party as open. Why that is the whole point, and why a rejected security approval is worth more than an empty field.
Read more
The worst clause wins
Four of five sub-clauses met does not add up to eighty percent, it takes the status of the fifth. Why the standards cockpit deliberately does not average, what the middle value "partial" achieves, and why a justified exclusion is evidence in itself.
Read more
One VM, three witnesses
The hypervisor sees the virtual machine, so does the network scan, so does the software scan. Fail to merge them and it sits in your inventory three times, with an asset count that depends on how many scanners you run rather than how many machines you have.
Read more
Maintained twice is wrong once
The main process shows not a single link, although it is plainly critical. Everything sits on the sub-processes. Why maintaining things twice is the worse answer, and how a process can display links without owning them.
Read more
The old device checks in too
In a notebook replacement the old device checks in just as reliably as the new one. Ask a rollout's success verification only whether there was contact and every target comes back yes. Why the check hangs on the completion timestamp and why a failure never demotes.
Read more
Old does not mean exempt
The Cyber Resilience Act applies from December 2027, and existing products are spared until then. For the reporting duty starting 11 September, exactly that does not hold: a separate paragraph explicitly withdraws the exemption.
Read more
Four times twenty is sixty
A room with four 20 kW cooling units does not carry 80 kW redundantly, but 60. Each unit may still be labelled N+1. The label is a promise, the arithmetic is reality.
Read more
The metric counts, not the number
A hundred installations are not a hundred licences. They are a hundred, twelve or none, depending on how the vendor counts. Deriving a licence position from an installation list answers the wrong question.
Read more
Not operable, not completed
A mandatory training with a 98 percent completion rate looks good. It says nothing about the missing two percent. Whoever could not operate the training appears in the report exactly like someone who did not want to.
Read more
The stopgap becomes a fixture
WiBA looked like an entry aid for small municipalities, to be swapped later for the real thing. The BSI has since decided otherwise: the checklists become a fixture of the successor to the IT-Grundschutz-Kompendium.
Read more
There is no good reason for that
Every security alert starts with the same question: was that one of us? A decoy answers it in advance. It has no operational purpose, so there is no harmless explanation for using it.
Read more
Non-binding, but machine-readable
The BSI has published TR-03183-1 in version 1.0.0: an entry aid into the Cyber Resilience Act, without presumption of conformity. The most interesting part sits at the margin: the selection of measures also comes in the machine-readable OSCAL format, though only on request.
Read more
Fine alone, critical together
The severity of a cloud misconfiguration comes from the catalog. But the catalog does not know the resource the check fired on. How we resolved that, and why a single risk factor raises nothing.
Read more
How would you notice?
For every attack technique the usual question is: do we have a control? The more uncomfortable question is about visibility. MITRE ATT&CK answers it, and we have now made that answer importable.
Read more
Required to delete, not allowed to
The retention period has expired but proceedings are still running. Three mechanisms govern this, and they get confused constantly: the period says when, sealing says do not change, the hold says do not delete.
Read more
An answer proves nothing at all
In March, NIST reissued its DNS deployment guide after thirteen years. We built the checks from it and learned along the way how easily a DNS test measures the wrong thing.
Read more
We can seal it, not open it
Emergency plans usually sit in exactly the system that is gone when it matters. Our new emergency kit therefore starts from an uncomfortable assumption: in an emergency, the platform itself is the compromised side.
Read more
The duty that already applies
With the Data Act, everyone points to 12 September 2026. Treating that as the starting gun misses two things: strictly speaking the cut-off is the day after, and the practically most useful duty has applied for a year already.
Read more
When both sides are right
A document sits in the e-file and in the ISMS. As long as only one side changes, reconciliation is easy. When both change, someone has to decide, and no tool can make that call in general.
Read more
Not clean, just unknown
A patch report usually knows two states: patched or gap. The third one is missing and quietly gets counted as the first: devices that were never surveyed. Why that deserves a field of its own, and what follows for distribution.
Read more
Whoever watches is watched
Remote support is the most far-reaching access in IT operations. It requires works council co-determination not because anyone intends to monitor, but because the tool could. Which is why our remote support module ships locked.
Read more
Non-conformant is a permitted answer
The accessibility statement is the only compliance document that has to name your own shortcomings in public. There are three conformance levels, and the worst one is permitted. What is missing is not the excuse but the substance behind it.
Read more
Two questions to ask a backup
Did the backup run? And where is it written that it had to run, how long copies are kept and whether anyone can still alter them? Those are two questions for two audiences. What the Cohesity connector therefore writes to two separate places, and where it deliberately writes nothing at all.
Read more
Exploitable is not exploited
On 11 September the reporting duty under the Cyber Resilience Act takes effect, two years before the regulation applies in full. 24 hours from awareness. But awareness of what exactly? The regulation distinguishes three kinds of vulnerability, and only the third triggers a report.
Read more
The law changes quietly
On 24 July the EU amended the AI Act. We noticed the change and still cited the wrong provision. What that mistake reveals about the level at which a legal register has to operate.
Read more
Forwarded is not reported
The click rate measures who fails. The report rate measures who protects. But then the reporting path has to be worth something, and forwarding is not just forwarding: the ordinary inline forward loses exactly the data needed to assess the mail.
Read more
How do you measure people without surveilling them?
Computing a human risk index is technically trivial, the data has long been there. The hard part is what you may do with it afterwards. Why the defaults are the real statement in this metric, and what a minimum group size is for.
Read more
Deferred is not suspended
Today the EU AI Act becomes generally applicable. The high-risk obligations everyone talks about, however, were deferred to December 2027 at the end of July. What remains affects almost everyone: the transparency duties under Article 50.
Read more
99.9 percent of what?
An availability figure without a definition is an opinion. What counts as an outage, whether an HTTP 200 proves anything at all, and how maintenance windows enter the calculation shape the number more than the technology behind it.
Read more
Today's deadline is not in the law
The BSI's grace period for NIS2 registration ends on 31 July. The statutory deadline was 6 March. Why that difference matters, and why the actual obligations never depended on registration in the first place.
Read more
Save the date: isidaten at DIGITAL X in Cologne
On 8 September 2026 we will be at DIGITAL X in Cologne's Rheinauhafen, on Deutsche Telekom's partner floor. And all three founders will be there: the CISO, the data protection and the IT management perspective at one table.
Read more
It is in the contract. Nobody ever checked.
Response time, certificate, incident notification duty, deletion at contract end: security requirements get negotiated once and then never touched again. Why every requirement needs a direction and a form of evidence, and why provided is not a permanent state.
Read more
The passing scan that proves nothing
A green ASV scan says only one thing: nothing critical was found in what was scanned. It says nothing about the real question, namely whether the right things were scanned. Why the scan scope is the assessment point in PCI DSS, and why the chain of quarterly scans counts as much as any single result.
Read more
The biggest data store is a mailbox
No system accumulates as much personal data as an organization's email mailboxes: bank details, ID scans, sick notes, passwords in plain text. Two questions bring this to light, and both arrive under time pressure: what data do you hold about me? And: who is affected by this incident?
Read more
Where the incident arrives first
The first hint of a security incident is rarely an alert. It is a ticket: the computer is slow, the mailbox is locked, an email looked odd. Whether it becomes an incident in time is decided at the service desk, long before any security tool fires. Why helpdesk and security process belong on one platform.
Read more
The chain that must not break
With classified material there is no approximate answer. Who held which document and when, who signed for it, when was it destroyed and who witnessed that? Why in classified information protection the record is not documentation of the work but the work itself, and what that means for a paper-based classified register.
Read more
The binder next to the fire extinguisher
Fire safety is the oldest compliance in the building, and in many organizations it still runs on paper: the fire safety log in a binder, inspection dates on stickers, the marshal quota as an estimate. Why the deadlines here are especially hard to keep track of, and what happens when you manage them like an asset inventory.
Read more
Who sends mail in your name
A phishing mail with your sender address does not hit you, it hits your customers, partners and applicants. Whether that is possible is decided by a handful of DNS records. Why the most common mistake is not a missing DMARC but an existing one that only watches, and what isidaten now checks per domain.
Read more
Two lists nobody reconciles
The data processing agreement and the register of processors describe the same service providers, from two angles. Legally they belong together, in practice they are two separate lists that drift apart. Why exactly this gap surfaces in an audit, and how the register entry can be derived from the contract itself.
Read more
An emergency plan is a sequence, not a list
A recovery plan that merely lists what has to run again helps little in an emergency. Because nothing starts at once: the application needs the database, which needs the network, which needs power. Why sequence and the critical path decide the real recovery time, and why an estimated RTO rarely holds when it counts.
Read more
The break-in that looks like a working day
For the first time in 19 years, stolen credentials are no longer the most common way into a network; exploited vulnerabilities have overtaken them. That sounds like relief for identity security, and it is not: across the full attack chain, credential abuse remains the most pervasive technique. Why a valid login raises no alarm, and only behavior gives it away.
Read more
The certificate nobody renewed
An expired TLS certificate blocks a service for every browser, loudly and instantly. Until now a manageable nuisance, because a certificate lasted about a year. But the CA/Browser Forum is cutting the maximum lifetime in stages from 398 to 47 days. Why manual certificate upkeep reaches its end, and what takes its place.
Read more
Software makes things visible, not secure
Hardly a brochure does without the promise of compliance at the push of a button. But a tool closes no gap, it shows one. Why the honest role of software is that of a mirror, why visibility is the real service, and why a tool that flatters the state fails exactly when it counts.
Read more
§ 39 is every three years. Critical infrastructure is every day.
Healthcare operators of critical infrastructure must regularly prove their IT security, since the NIS2 implementation act under § 39 BSIG and now only every three years. The longer the interval, the larger the gap between two snapshots. Why the B3S catalog only describes the WHAT, the real work sits in the HOW, and how the audit sprint becomes a continuously measured state.
Read more
Security you can show
Every B2B deal now starts with a security questionnaire, and half the questions are always the same. Still, someone answers them by hand every time. Why the questionnaire flood will not go away, why a static security PDF is no answer, and how a trust center handles half the due diligence proactively.
Read more
The reporting office nobody wants used
Since July 2023, companies with 50 or more employees need an internal reporting office. In many organizations this became an email inbox, combined with the quiet hope that nothing ever arrives. Why exactly that defeats the purpose, which deadlines the German Whistleblower Protection Act sets, and why the return channel for anonymous reports is the real crux.
Read more
Deletion is a process, not a button
The GDPR demands deletion, commercial and tax law demand retention, and both apply at the same time. Whoever deletes by gut feeling is guaranteed to violate one of the two duties. Why a deletion concept needs periods per data type, when a period even starts running, and why proving deletion is half the duty.
Read more
Awareness is not measured in attendance
The mandatory training is completed, the attendance rate looks good, the auditor is satisfied. And still, part of the workforce clicks on the next simulated phishing mail. Why attendance rate and click rate tell two different truths, and how simulation, findings and targeted training become a loop instead of a box-ticking exercise.
Read more
Hardening has an expiration date
Anyone can harden once: work through the benchmark, tick it off, done. Then everyday operations arrive, and the configuration drifts, quietly and without bad intent. Why configuration drift is the normal state in the absence of measurement, and how isidaten now checks daily against 28 hardening benchmarks, on Linux directly via OpenSCAP.
Read more
The first AI ransomware walked in through an open door
In early July, Sysdig documented the first ransomware campaign an AI agent ran on its own, from reconnaissance to encryption. The unsettling part is not the AI: entry came through a known vulnerability, a second one from 2021 and default credentials. Why the fundamentals still defend against attackers moving at machine speed.
Read more
IT documentation ends at the rack. Power does not.
Server rooms are often documented down to the last rack unit. But the sub-distribution board in the hallway that the whole rack depends on lives in another world: the electrical binder. The NetBox community has been asking for DIN rails since 2018, most recently classified as out of core scope. isidaten now brings the distribution board into the model.
Read more
Registered is not implemented
On 31 July, the BSI sets the final NIS2 registration deadline. Around 29,500 organizations are affected, a good half have signed up, but only about a third have actually implemented the directive. Why the deadline is about signing up, not about security, and what really counts after 31 July.
Read more
An asset inventory is not a device list
Most asset inventories are really device lists: hostname, IP, serial number. But an auditor rarely asks whether a device exists, they ask who is responsible, where it stands, what software runs and who accesses it. Why an inventory is a web of relationships, and why the most reliable source for it usually already sits in IT operations.
Read more
The most important connector is in nobody's catalog
Vendors advertise hundreds of ready-made integrations. But the one that matters when it counts is for your in-house tool, your legacy system, your niche software, and that one is in no catalog. Why integrability depends on the open interface, not on the length of the connector list.
Read more
Containers in the asset inventory: the platform counts, not the pod
A pod often lives for minutes. Whoever inventories every single one produces noise; whoever leaves the container layer out entirely has a blind spot exactly where production runs. Why the right question is not whether but at which level, and what belongs in the inventory for good.
Read more
The consent banner that sets cookies before anyone clicks
A study of one million websites found in 2025: on roughly 43 percent, tracking cookies run without valid consent. The TDDDG requires the opposite. Why the gap almost always comes down to nobody knowing what their own site really loads, and how to find out.
Read more
Cyber Resilience Act: why the 24-hour reporting duty forces preparation
From 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours, followed by a full notification in 72 hours and a final report in 14 days. The deadlines are not a formality but a test of whether the groundwork is done. What the Cyber Resilience Act really demands and why the real work happens beforehand.
Read more
Why half the CVE list is a waste of time
A scan against one exposed host finds 672 known vulnerabilities, from 2009 to today, critical ones next to scoreless ones. Patching by pure CVSS means chasing the theoretically worst holes instead of the truly dangerous ones. Three questions that turn a CVE into a real risk, and why prioritization without asset context stays blind.
Read more
Everyone is building compliance agents now. The interesting question is who controls them
Within a few weeks, Vanta, Drata and ServiceNow all unveiled AI agents for compliance. At the same time, Gartner expects four in ten companies to scale their autonomous agents back by 2027. A story about a race, an old pattern in new clothes, and three questions to answer before your first agent goes live.
Read more
You don't type an asset inventory, you let it be scanned
A hand-maintained inventory has two flaws: it ages faster than you can type, and it only contains what someone entered. The dangerous part is what was forgotten. Why a living inventory is discovered rather than recorded, and why a single source is never enough.
Read more
The ICT third-party register: the DORA duty that even NIS2-ready firms are unprepared for
DORA has applied since January 2025 and demands more than good contracts: a complete register of all ICT services, linked to functions, criticality and exit plans. Why this goes beyond NIS2 supply-chain work, what a living register looks like, and why contracts alone are not enough.
Read more
Data center documentation that doesn't lie: why static plans fail
Every data center has a nice diagram that was correct the day it was drawn and has aged ever since. The moment someone swaps a server, repatches or a device fails, the documentation lies. Why static plans fail systematically, what living documentation changes, and why the data center inventory is also compliance substance.
Read more
Supply chain risk: responsibility does not end at your firewall
Your own security level is only as high as that of your service providers. Yet many organizations treat supplier review as a one-time questionnaire that gets filled in and forgotten. NIS2 turns it into a continuous obligation. isidaten manages suppliers, contracts and processors as traceable objects instead of an Excel silo.
Read more
Attack surface management: you can't protect what you can't see
The way into a network is rarely the spectacular zero-day. More often it is the forgotten asset nobody had on their radar anymore. isidaten makes the attack surface continuously visible from outside and inside, and matches it automatically against current vendor advisories.
Read more
New Veeam connector: turning backups into provable recoverability
isidaten now connects directly to Veeam Backup & Replication. Backup jobs, sessions and repositories flow automatically into the central object base, turning the mere existence of backups into provable recovery evidence.
Read more
NIS2: The first audit evidence is due, and why it shouldn't be a deadline
Around 30 June 2026 the first NIS2 evidence becomes due for many affected entities. Scrambling for proof at the deadline doesn't solve the real problem. Why evidence should be a state, not a one-off effort.
Read more
Firewall governance through a single agent: isidaten captures rule sets from eight vendors
Orphaned rules, sprawling rule sets, no overview: isidaten reads firewall configurations from FortiGate to host firewalls via the isidaten agent and makes them auditable, across vendors on a single object base.
Read more
isidaten makes GRC AI-ready: New MCP module for secure AI access
With the new MCP module, AI assistants access your isidaten data in a controlled, tenant-separated and permission-based way, via the open Model Context Protocol.
Read more
isidaten expands integration portfolio: New Ubiquiti connector available
isidaten continues its course towards maximum connectivity and presents another important building block of its integration strategy: the Ubiquiti connector.
Read more
isidaten continues integration strategy: New SoSafe connector available
isidaten continues its integration strategy and expands the platform ecosystem with a new SoSafe connector.
Read moreisidaten offers API integration with Wazuh XDR SIEM solution
isidaten expands its portfolio with seamless API integration to the leading open-source XDR SIEM platform Wazuh.
Read more
isidaten implements new ISO Standard 20153:2025 with vulnerability management module
With the brand-new ISO/IEC 20153:2025 standard, isidaten implements state-of-the-art CSAF-compliant vulnerability management.
Read more
isidaten officially listed by BSI as IT-Grundschutz tool
isidaten is officially recognized and listed by the Federal Office for Information Security (BSI) as an IT-Grundschutz tool.
Read more
isidaten signs cooperation agreement with Telekom Deutschland
For partnership cooperation, isidaten has signed a cooperation agreement with Telekom.
Read more
isidaten actively shapes the new BSI IT-Grundschutz++
As an officially recognized BSI IT-Grundschutz tool, we are actively engaged in the development of the future IT-Grundschutz++
Read more
isidaten is now an official BSI IT-Grundschutz tool
isidaten has concluded a license agreement with BSI for processing data from the IT-Grundschutz catalogs
Read moreQuestions about an update?
Talk to us – we are happy to show you the latest features and integrations in a demo.