<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>ZERODOTFIVE — Insights</title>
  <link>https://zerodotfive.com/en/wissen</link>
  <description>Ideas, solutions and in-depth articles from practice — secure cloud and AI adoption in regulated companies.</description>
  <language>en</language>
  <atom:link href="https://zerodotfive.com/en/wissen/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Operationalizing the Software Bill of Materials: What Dependency-Track Delivers — and Where It Fails Silently</title>
    <link>https://zerodotfive.com/en/wissen/dependency-track</link>
    <guid isPermaLink="true">https://zerodotfive.com/en/wissen/dependency-track</guid>
    <pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate>
    <description>Dependency-Track continuously evaluates SBOMs against CVE data. Why a silent H2 fallback becomes a false sense of security — and what CISOs should take from it.</description>
    <enclosure url="https://zerodotfive.com/wissen/dependency-track/assets/og.png" length="767789" type="image/png"/>
  </item>
  <item>
    <title>Assess Your SDLC and Kubernetes Maturity Yourself — Offline, Audit-Ready, in Days</title>
    <link>https://zerodotfive.com/en/wissen/sdlc-k8-compliance</link>
    <guid isPermaLink="true">https://zerodotfive.com/en/wissen/sdlc-k8-compliance</guid>
    <pubDate>Sat, 18 Jul 2026 09:00:00 GMT</pubDate>
    <description>How CISOs can determine the security maturity of their software supply chain and Kubernetes environment themselves — offline, no data leakage, aligned with BSI and CIS.</description>
    <enclosure url="https://zerodotfive.com/wissen/sdlc-k8-compliance/assets/og.png" length="781337" type="image/png"/>
  </item>
  <item>
    <title>Why &#39;Lift and Shift&#39; Usually Fails in Regulated Clouds</title>
    <link>https://zerodotfive.com/en/wissen/pipeline-smoketest</link>
    <guid isPermaLink="true">https://zerodotfive.com/en/wissen/pipeline-smoketest</guid>
    <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
    <description>One-to-one migrations shift risk instead of reducing it — and change how you evidence compliance under NIS2/§30 BSIG. Here is how to approach it.</description>
    <enclosure url="https://zerodotfive.com/wissen/pipeline-smoketest/assets/og.png" length="661763" type="image/png"/>
  </item>
</channel>
</rss>
