News & updates

Latest from isidaten

Stay informed about the latest developments in data protection and information security.

New here every day. Follow along: RSS-Feed · LinkedIn · X

Two lists nobody reconciles
23.07.2026

Two lists nobody reconciles

The data processing agreement and the register of processors describe the same service providers, from two angles. Legally they belong together, in practice they are two separate lists that drift apart. Why exactly this gap surfaces in an audit, and how the register entry can be derived from the contract itself.

Read more
An emergency plan is a sequence, not a list
22.07.2026

An emergency plan is a sequence, not a list

A recovery plan that merely lists what has to run again helps little in an emergency. Because nothing starts at once: the application needs the database, which needs the network, which needs power. Why sequence and the critical path decide the real recovery time, and why an estimated RTO rarely holds when it counts.

Read more
The break-in that looks like a working day
21.07.2026

The break-in that looks like a working day

For the first time in 19 years, stolen credentials are no longer the most common way into a network; exploited vulnerabilities have overtaken them. That sounds like relief for identity security, and it is not: across the full attack chain, credential abuse remains the most pervasive technique. Why a valid login raises no alarm, and only behavior gives it away.

Read more
The certificate nobody renewed
20.07.2026

The certificate nobody renewed

An expired TLS certificate blocks a service for every browser, loudly and instantly. Until now a manageable nuisance, because a certificate lasted about a year. But the CA/Browser Forum is cutting the maximum lifetime in stages from 398 to 47 days. Why manual certificate upkeep reaches its end, and what takes its place.

Read more
Software makes things visible, not secure
19.07.2026

Software makes things visible, not secure

Hardly a brochure does without the promise of compliance at the push of a button. But a tool closes no gap, it shows one. Why the honest role of software is that of a mirror, why visibility is the real service, and why a tool that flatters the state fails exactly when it counts.

Read more
§ 39 is every three years. Critical infrastructure is every day.
18.07.2026

§ 39 is every three years. Critical infrastructure is every day.

Healthcare operators of critical infrastructure must regularly prove their IT security, since the NIS2 implementation act under § 39 BSIG and now only every three years. The longer the interval, the larger the gap between two snapshots. Why the B3S catalog only describes the WHAT, the real work sits in the HOW, and how the audit sprint becomes a continuously measured state.

Read more
Security you can show
17.07.2026

Security you can show

Every B2B deal now starts with a security questionnaire, and half the questions are always the same. Still, someone answers them by hand every time. Why the questionnaire flood will not go away, why a static security PDF is no answer, and how a trust center handles half the due diligence proactively.

Read more
The reporting office nobody wants used
16.07.2026

The reporting office nobody wants used

Since July 2023, companies with 50 or more employees need an internal reporting office. In many organizations this became an email inbox, combined with the quiet hope that nothing ever arrives. Why exactly that defeats the purpose, which deadlines the German Whistleblower Protection Act sets, and why the return channel for anonymous reports is the real crux.

Read more
Deletion is a process, not a button
15.07.2026

Deletion is a process, not a button

The GDPR demands deletion, commercial and tax law demand retention, and both apply at the same time. Whoever deletes by gut feeling is guaranteed to violate one of the two duties. Why a deletion concept needs periods per data type, when a period even starts running, and why proving deletion is half the duty.

Read more
Awareness is not measured in attendance
14.07.2026

Awareness is not measured in attendance

The mandatory training is completed, the attendance rate looks good, the auditor is satisfied. And still, part of the workforce clicks on the next simulated phishing mail. Why attendance rate and click rate tell two different truths, and how simulation, findings and targeted training become a loop instead of a box-ticking exercise.

Read more
Hardening has an expiration date
13.07.2026

Hardening has an expiration date

Anyone can harden once: work through the benchmark, tick it off, done. Then everyday operations arrive, and the configuration drifts, quietly and without bad intent. Why configuration drift is the normal state in the absence of measurement, and how isidaten now checks daily against 28 hardening benchmarks, on Linux directly via OpenSCAP.

Read more
The first AI ransomware walked in through an open door
12.07.2026

The first AI ransomware walked in through an open door

In early July, Sysdig documented the first ransomware campaign an AI agent ran on its own, from reconnaissance to encryption. The unsettling part is not the AI: entry came through a known vulnerability, a second one from 2021 and default credentials. Why the fundamentals still defend against attackers moving at machine speed.

Read more
IT documentation ends at the rack. Power does not.
11.07.2026

IT documentation ends at the rack. Power does not.

Server rooms are often documented down to the last rack unit. But the sub-distribution board in the hallway that the whole rack depends on lives in another world: the electrical binder. The NetBox community has been asking for DIN rails since 2018, most recently classified as out of core scope. isidaten now brings the distribution board into the model.

Read more
Registered is not implemented
10.07.2026

Registered is not implemented

On 31 July, the BSI sets the final NIS2 registration deadline. Around 29,500 organizations are affected, a good half have signed up, but only about a third have actually implemented the directive. Why the deadline is about signing up, not about security, and what really counts after 31 July.

Read more
An asset inventory is not a device list
09.07.2026

An asset inventory is not a device list

Most asset inventories are really device lists: hostname, IP, serial number. But an auditor rarely asks whether a device exists, they ask who is responsible, where it stands, what software runs and who accesses it. Why an inventory is a web of relationships, and why the most reliable source for it usually already sits in IT operations.

Read more
The most important connector is in nobody's catalog
08.07.2026

The most important connector is in nobody's catalog

Vendors advertise hundreds of ready-made integrations. But the one that matters when it counts is for your in-house tool, your legacy system, your niche software, and that one is in no catalog. Why integrability depends on the open interface, not on the length of the connector list.

Read more
Containers in the asset inventory: the platform counts, not the pod
07.07.2026

Containers in the asset inventory: the platform counts, not the pod

A pod often lives for minutes. Whoever inventories every single one produces noise; whoever leaves the container layer out entirely has a blind spot exactly where production runs. Why the right question is not whether but at which level, and what belongs in the inventory for good.

Read more
The consent banner that sets cookies before anyone clicks
06.07.2026

The consent banner that sets cookies before anyone clicks

A study of one million websites found in 2025: on roughly 43 percent, tracking cookies run without valid consent. The TDDDG requires the opposite. Why the gap almost always comes down to nobody knowing what their own site really loads, and how to find out.

Read more
Cyber Resilience Act: why the 24-hour reporting duty forces preparation
05.07.2026

Cyber Resilience Act: why the 24-hour reporting duty forces preparation

From 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours, followed by a full notification in 72 hours and a final report in 14 days. The deadlines are not a formality but a test of whether the groundwork is done. What the Cyber Resilience Act really demands and why the real work happens beforehand.

Read more
Why half the CVE list is a waste of time
04.07.2026

Why half the CVE list is a waste of time

A scan against one exposed host finds 672 known vulnerabilities, from 2009 to today, critical ones next to scoreless ones. Patching by pure CVSS means chasing the theoretically worst holes instead of the truly dangerous ones. Three questions that turn a CVE into a real risk, and why prioritization without asset context stays blind.

Read more
Everyone is building compliance agents now. The interesting question is who controls them
03.07.2026

Everyone is building compliance agents now. The interesting question is who controls them

Within a few weeks, Vanta, Drata and ServiceNow all unveiled AI agents for compliance. At the same time, Gartner expects four in ten companies to scale their autonomous agents back by 2027. A story about a race, an old pattern in new clothes, and three questions to answer before your first agent goes live.

Read more
You don't type an asset inventory, you let it be scanned
02.07.2026

You don't type an asset inventory, you let it be scanned

A hand-maintained inventory has two flaws: it ages faster than you can type, and it only contains what someone entered. The dangerous part is what was forgotten. Why a living inventory is discovered rather than recorded, and why a single source is never enough.

Read more
The ICT third-party register: the DORA duty that even NIS2-ready firms are unprepared for
01.07.2026

The ICT third-party register: the DORA duty that even NIS2-ready firms are unprepared for

DORA has applied since January 2025 and demands more than good contracts: a complete register of all ICT services, linked to functions, criticality and exit plans. Why this goes beyond NIS2 supply-chain work, what a living register looks like, and why contracts alone are not enough.

Read more
Data center documentation that doesn't lie: why static plans fail
30.06.2026

Data center documentation that doesn't lie: why static plans fail

Every data center has a nice diagram that was correct the day it was drawn and has aged ever since. The moment someone swaps a server, repatches or a device fails, the documentation lies. Why static plans fail systematically, what living documentation changes, and why the data center inventory is also compliance substance.

Read more
Supply chain risk: responsibility does not end at your firewall
29.06.2026

Supply chain risk: responsibility does not end at your firewall

Your own security level is only as high as that of your service providers. Yet many organizations treat supplier review as a one-time questionnaire that gets filled in and forgotten. NIS2 turns it into a continuous obligation. isidaten manages suppliers, contracts and processors as traceable objects instead of an Excel silo.

Read more
Attack surface management: you can't protect what you can't see
28.06.2026

Attack surface management: you can't protect what you can't see

The way into a network is rarely the spectacular zero-day. More often it is the forgotten asset nobody had on their radar anymore. isidaten makes the attack surface continuously visible from outside and inside, and matches it automatically against current vendor advisories.

Read more
New Veeam connector: turning backups into provable recoverability
27.06.2026

New Veeam connector: turning backups into provable recoverability

isidaten now connects directly to Veeam Backup & Replication. Backup jobs, sessions and repositories flow automatically into the central object base, turning the mere existence of backups into provable recovery evidence.

Read more
NIS2: The first audit evidence is due, and why it shouldn't be a deadline
26.06.2026

NIS2: The first audit evidence is due, and why it shouldn't be a deadline

Around 30 June 2026 the first NIS2 evidence becomes due for many affected entities. Scrambling for proof at the deadline doesn't solve the real problem. Why evidence should be a state, not a one-off effort.

Read more
Firewall governance through a single agent: isidaten captures rule sets from eight vendors
25.06.2026

Firewall governance through a single agent: isidaten captures rule sets from eight vendors

Orphaned rules, sprawling rule sets, no overview: isidaten reads firewall configurations from FortiGate to host firewalls via the isidaten agent and makes them auditable, across vendors on a single object base.

Read more
isidaten makes GRC AI-ready: New MCP module for secure AI access
22.06.2026

isidaten makes GRC AI-ready: New MCP module for secure AI access

With the new MCP module, AI assistants access your isidaten data in a controlled, tenant-separated and permission-based way, via the open Model Context Protocol.

Read more
isidaten expands integration portfolio: New Ubiquiti connector available
01.12.2025

isidaten expands integration portfolio: New Ubiquiti connector available

isidaten continues its course towards maximum connectivity and presents another important building block of its integration strategy: the Ubiquiti connector.

Read more
isidaten continues integration strategy: New SoSafe connector available
30.11.2025

isidaten continues integration strategy: New SoSafe connector available

isidaten continues its integration strategy and expands the platform ecosystem with a new SoSafe connector.

Read more
isidaten offers API integration with Wazuh XDR SIEM solution
12.11.2025

isidaten offers API integration with Wazuh XDR SIEM solution

isidaten expands its portfolio with seamless API integration to the leading open-source XDR SIEM platform Wazuh.

Read more
isidaten implements new ISO Standard 20153:2025 with vulnerability management module
23.07.2025

isidaten implements new ISO Standard 20153:2025 with vulnerability management module

With the brand-new ISO/IEC 20153:2025 standard, isidaten implements state-of-the-art CSAF-compliant vulnerability management.

Read more
isidaten officially listed by BSI as IT-Grundschutz tool
09.07.2025

isidaten officially listed by BSI as IT-Grundschutz tool

isidaten is officially recognized and listed by the Federal Office for Information Security (BSI) as an IT-Grundschutz tool.

Read more
isidaten signs cooperation agreement with Telekom Deutschland
13.04.2025

isidaten signs cooperation agreement with Telekom Deutschland

For partnership cooperation, isidaten has signed a cooperation agreement with Telekom.

Read more
isidaten actively shapes the new BSI IT-Grundschutz++
11.03.2025

isidaten actively shapes the new BSI IT-Grundschutz++

As an officially recognized BSI IT-Grundschutz tool, we are actively engaged in the development of the future IT-Grundschutz++

Read more
isidaten is now an official BSI IT-Grundschutz tool
21.02.2025

isidaten is now an official BSI IT-Grundschutz tool

isidaten has concluded a license agreement with BSI for processing data from the IT-Grundschutz catalogs

Read more

Questions about an update?

Talk to us – we are happy to show you the latest features and integrations in a demo.