Blog
What supervisory authorities check and what audits ask for.
The articles come out of daily work on ISMS, BCMS, DSMS and AIMS, from the first scope check through evidence for measures to the audit itself.
18 articles
- 01ISMS without a security team: roles, effort, toolsBSI IT-Grundschutz requires at least one appointed person, not a team. This guide pulls the roles, duties and sources from ISO 27001, the BSI-Standards and the BSIG together into one matrix.18 September 2026 · 18 min readRead
- 02Management liability under § 38 BSIG: Risks beyond fines§ 38 BSIG requires management to implement measures, oversee them and attend training. Understand liability to the entity, fines and supervisory action.17 September 2026 · 6 min readRead
- 03What Does ISMS Software Cost? Pricing Models ComparedThe license fee is only one of six cost blocks. This article sorts the DACH market into three price tiers and shows what comes on top for rollout, internal effort, training, and operation.10 September 2026 · 20 min readRead
- 04Extortion Demand: Who Decides, and by What Criteria?When ransomware hits, the payment decision formally belongs to management, not IT, but it hinges on sanctions checks, insurance terms, and forensic findings a crisis team prepares. Here is who decides, what criteria matter, and why a payment can itself be illegal.5 September 2026 · 17 min readRead
- 05What does ISO 27001 certification cost for a mid-sized company?Auditor days are tied to accreditation and are not negotiable, the day rate is. Market ranges for the audit, consulting and internal effort.29 August 2026 · 16 min readRead
- 06Cyberattack on a small power plant in the United Kingdom: four days of downtime below the reporting thresholdA small power plant in the United Kingdom went offline for four days after a cyberattack in July 2026, but the case only became public four weeks later. What is documented, what is reconstructed, and which reporting duties would apply in Germany since December 2025.24 August 2026 · 13 min readRead
- 07KRITIS-Dachgesetz and NIS2: What Applies to Whom?KRITIS-Dachgesetz and NIS2 apply in parallel: physical resilience falls under the BBK, cybersecurity under the BSI. Thresholds, deadlines, and fines at a glance.21 August 2026 · 13 min readRead
- 08The cyberattack on Berlin's state network: seven days undetected, five days of data outflowAttackers were undetected in Berlin's state network for seven days. What is documented, who bears the damage once operations resume, and what other organisations can check for themselves.19 August 2026 · 20 min readRead
- 09Grundschutz++ from 2027: certifiable, but how mature?Grundschutz++ becomes certifiable on 1 January 2027. The methodology breaks with the old BSI IT-Grundschutz, but the risk assessment remains open.13 August 2026 · 13 min readRead
- 10Resilience Made Easy: The Path from GRC Filing Cabinet to Agentic WorkspaceWhy we're not building KaitoSec as a GRC filing system, but as an agentic workspace for continuous resilience, and what that means for the information security officer's daily work.5 August 2026 · 9 min readRead
- 11Do I Need an ISMS for NIS2? Mandatory or OptionalNIS2 does not require an ISMS or ISO 27001 certification. What the BSI actually demands, which structures §30 BSIG requires, and what SMEs need to know.11 May 2026 · 13 min readRead
- 12NIS2 Incident Reporting: When, What, and to Whom?Three-stage NIS2 reporting: early warning (24h), initial notification (72h), final report (1 month). Who reports what to whom, and what fines apply for violations?27 April 2026 · 14 min readRead
- 13Is ISO 27001 Enough for NIS2 Compliance?No, says the BSI. ISO 27001 is a solid foundation, but scope freedom, risk acceptance, and §32/§38 BSIG duties remain open. How to close the gaps.8 April 2026 · 12 min readRead
- 14Am I Affected by NIS2? How to CheckWhether your company falls under NIS2 depends on sector and company size. 18 sectors, size thresholds and special cases, explained step by step.25 March 2026 · 14 min readRead
- 15NIS2 Consultant or DIY? A Cost ComparisonAn NIS2 consulting project costs SMEs EUR 50,000–150,000. Which parts you can handle yourself, where a consultant pays off, and how the hybrid approach works, with concrete numbers.21 March 2026 · 11 min readRead
- 16NIS2 in Germany: What Do Companies Need to Know in 2026?The NIS2 Implementation Act has been in force since December 2025. Around 29,500 companies in Germany must now comply with registration, reporting, and risk management obligations. Duties, deadlines, fines, and implementation, the complete overview.19 March 2026 · 11 min readRead
- 17NIS2 and ISMS: What Your Existing System Doesn't CoverISMS tools manage controls and audits, but they don't provide a NIS2 implementation path. Why ISMS vendors upsell consulting, where the guidance gap lies, and how KaitoSec closes it.17 March 2026 · 9 min readRead
- 18NIS2 Fines: What Penalties Apply for Non-Compliance?NIS2 violations can cost companies up to EUR 10 million or 2% of global annual turnover. Learn about fines for different violations, personal management liability, and what two practical scenarios reveal.16 March 2026 · 12 min readRead
Keep reading