Thoughts, explanations, and background on penetration testing, IT law, and everything else in my line of work.
Over 80% of companies examined already show signs of shadow AI. What the risk actually looks like — and what a pragmatic governance approach can do about it.
Read more →Microsoft, Apple, and Google are actively pushing passwordless logins. What makes passkeys technically different — and why rollout still stalls in practice.
Read more →A faked video call cost one company $25.6 million. How deepfake fraud actually works — and why process discipline protects more than detection software.
Read more →Germany ranks among the three most ransomware-affected countries worldwide. The real shift, though, is in attack methodology — not the raw numbers.
Read more →About 29,500 German companies now fall under NIS2 — with no grace period. Who's covered, what's required, and why it's now a board-level issue.
Read more →Section 202c of the German Criminal Code criminalizes providing attack tools — the very tools a legitimate penetration test relies on. What that means in practice for both clients and testers.
Read more →A good penetration test isn’t a one-off scan — it’s a structured, five-phase process. A behind-the-scenes look at how it really works.
Read more →