Skip to content

Category

Legal

23 articles

Subcategories

Latest

  • NIS2 explained in detail for small and medium-sized enterprises

    The NIS2 Directive will affect around 29,500 companies in Germany from 2026, including many SMEs. In future, management will bear personal responsibility for information security, risk management, and business continuity. Fines can be up to €10 million or 2 percent of turnover. Core obligations include the introduction of an ISMS (e.g., ISO 27001 or VdS 10000), the systematic anchoring of risk management and business continuity, and compliance with incident reporting requirements (24 hours, 72 hours, 1 month). In addition, companies must take into account overlaps with the GDPR, the Supply Chain Act, and the Cyber Resilience Act. Conclusion: NIS2 is not purely an IT issue, but a matter for top management. Acting early strengthens security, resilience, and trust in the supply chain.

    IT-Security & Cyber SecurityChristopher Schroer13 minutes

  • Data Protection and BCM: Why Resilience Only Works When Combined

    How are data protection and BCM related? The GDPR demands more than just data security; it requires availability and crisis resilience. In practice, however, data protection and business continuity management are often separated organizationally. This article shows why effective data protection fails without coordinated BCM and how companies can successfully integrate reporting requirements, recovery times, roles, and responsibilities.

    ITChristopher Schroer14 minutes

  • Data protection and DSGVO - 5 stumbling blocks for SMEs

    For small and medium-sized enterprises (SMEs), it is often difficult to meet the data protection requirements according to the GDPR. Even with few resources for this topic, the data protection requirements apply to SMEs just as they do to larger companies, and so SMEs are not spared from audits by the data protection supervisory authorities. However, the need to act in a data protection-compliant manner should not only be seen in connection with possible fines and loss of reputation, but should also be used as a competitive advantage in view of the growing importance of data protection for end customers as well as in B2B business.

    Data protectionDIGITAL BREAKFAST7 minutes

  • Innovation management according to ISO 56002

    ISO standards such as ISO 9001 and ISO 14001 are among the most popular management systems for companies worldwide. With the ISO 56000 family, the International Organization of Standards is currently introducing a new series for innovation management. This article explains the components of the standard, the benefits for companies, and the innovation management systems guide ISO 56002, which is at the heart of this series.

    ProcessesDr. Marcus Liehr9 minutes

  • Cybersecurity in home office times: 5 tips for secure network(s)

    Virtually overnight, the "analog" virus Corona is turning the classic working world upside down: home office is suddenly running like an assembly line, or as others say: "going viral". Not only the health of employees must be at the top of the agenda, but also the integrity of information worth protecting. Because this "analog" virus also serves as a backdoor for its digital cousins. The article explains how companies can protect themselves against cyberattacks in Corona times.

    IT-Security & Cyber SecurityIldikó Bruhns5 minutes

  • Hard times for data transfer to third countries - "Privacy Shield" falls

    With the decision (Case C-311/18), the European Court of Justice (ECJ) has declared the so-called "Privacy Shield" for data transfers to the USA to be invalid. The use of so-called standard contractual clauses must also be viewed critically in light of US surveillance laws. Possible courses of action for data-exporting companies have therefore been restricted. This article on international data traffic shows what companies must now do.

    Data protectionKarin Dietl4 minutes

  • Understanding the New EU Standard Contractual Clauses (SCC) - What to do?

    Sch-rems II rulings have shaken up international data transfers. The Privacy Shield agreement with the US was declared invalid and now most companies have resorted to the so-called EU Standard Contractual Clauses (SCC). In a second ruling, however, the ECJ also commented on the SCCs and new SCC contract sets were put on the table, which now have to be transferred.

    Data protectionYves Gogniat5 minutes

  • Blockchain in medicine & healthcare

    Most people know mainly Bitcoin as a cryptocurrency. And Bitcoin was the first cryptocurrency based on such a technology, namely the blockchain. However, the blockchain is much more than just a cryptocurrency. Blockchain can be used to implement numerous different use cases. I would like to discuss a few from the medical, pharmaceutical & health sectors here.

    Healthcare & Social AffairsEugen Grinschuk7 minutes