30 Jun DDoS Red Teaming: Realistic Attack Scenario or Unnecessary Escalation? by Fabian Mittermair Red teaming is meant to be realistic. But when does realism become too much?
24 Apr The Return of Identity Theft: In the Age of Phishing and BEC by Thomas Langthaler Everyone talks about ransomware. Understandably so: encrypted data, ransom demands, PR disasters—it naturally attracts attention. But while we're focused on the skull-and-crossbones in the headline, an old discipline is quietly making its return to the cyber threat landscape: identity theft.
17 Apr Not All That Glitters Is Gold: Pre-Employment Screening by Christoph Zajic The Austrian Network and Information Systems Security Act (NISG) already requires operators to ensure that employees are trustworthy, aware of their responsibilities, and qualified for their assigned roles.
17 Mar Ransomware Attacks as Data Protection Incidents: GDPR Requirements and Reporting Obligations by Dzevad Mujezinovic Ransomware attacks reached a new record high in 2024, threatening organizations worldwide. Critical sectors such as healthcare and public authorities remain prime targets, but small and medium-sized enterprises (SMEs) are increasingly affected as well. Cybercriminals are increasingly stealing data to extort ransom payments.
19 Feb Responsible Disclosure: Handling Security Vulnerabilities Responsibly by Yuri Gbur, Sandro Einfeldt, Fabian Mittermair Software vulnerabilities are inevitable—but how they are handled makes all the difference. Responsible Disclosure helps ensure that security flaws are remediated before they can be exploited by attackers.
29 Jan Cybersecurity Outlook 2025: Process Consulting by Christoph Zajic, Process Consulting 2024 brought several major developments in cybersecurity—from the Cyber Resilience Act entering into force to the CrowdStrike incident during the summer. Now that we have entered 2025, the question is: What's next?