Insights
Ideas, solutions and in-depth articles from practice — secure cloud and AI adoption in regulated companies.
Operationalizing the Software Bill of Materials: What Dependency-Track Delivers — and Where It Fails Silently
Dependency-Track continuously evaluates SBOMs against CVE data. Why a silent H2 fallback becomes a false sense of security — and what CISOs should take from it.
Read more →
Assess Your SDLC and Kubernetes Maturity Yourself — Offline, Audit-Ready, in Days
How CISOs can determine the security maturity of their software supply chain and Kubernetes environment themselves — offline, no data leakage, aligned with BSI and CIS.
Read more →
Why 'Lift and Shift' Usually Fails in Regulated Clouds
One-to-one migrations shift risk instead of reducing it — and change how you evidence compliance under NIS2/§30 BSIG. Here is how to approach it.
Read more →Tools
SDLC & Kubernetes Security — the self-check (in German)
64 weighted controls from our assessment catalogue (maturity 0–4) with references to NIS2/§30 BSIG, ISO 27001, CIS Kubernetes and BSI IT-Grundschutz. No data leaves your browser, no account — export the result as a report.
Start the self-check →