+49 6151 6290246
Knowledge

Understanding IT Security: Fundamentals, Regulations, and Best Practices

EASM & Attack Surface

Fundamentals of External Attack Surface Management

Cybersecurity Audit: Process, Effort, and Cost Factors

How to properly plan cybersecurity audits: audit scope, procedures, roles, evidences, cost drivers, and criteria for comparable quotes.

Vulnerability Scan, Penetration Test, Security Audit, or EASM: Which Approach Is Right for You?

Comparison of vulnerability scans, penetration tests, security audits, and EASM based on criteria such as scope, depth of testing, authorization, timing, and results.

Conducting an IT Risk Analysis: Process, Data Sources, and Results

Here's how to conduct an IT risk analysis—from scope, through data sources and context, to prioritization and documented risk treatment.

Preemptive Intelligence: Early Vulnerability Alerts Before NVD Enrichment

Preemptive Intelligence cross-references early vulnerability alerts with the external attack surface before NVD enrichment is complete.

EASM in the CTEM Process: What Role Does External Attack Detection Play?

CTEM combines scoping, discovery, prioritization, validation, and mobilization. EASM provides an external perspective on this, but does not cover the entire process on its own.

EASM, CAASM, and DRPS: Differences and Applications

EASM, CAASM, and DRPS provide different perspectives on assets and digital risks. This comparison highlights their functions, limitations, and how they interact.

Exposure Management vs. Vulnerability Management

A Comparison of Exposure Management and Vulnerability Management: Scope, data sources, prioritization, workflows, and results clearly categorized.

What a Company Domain Reveals About Its External Attack Surface—and What It Doesn't

DNS, certificates, services, email protection, and technical information provide external indicators. Their significance is limited to assignment, version, and internal controls.

Attack Surface Assessment: From Asset Discovery to Prioritization

Attack Surface Assessment Explained: Discover external assets, attribute findings, evaluate them in context, and prioritize appropriate measures.

What is a security rating?

Security ratings measure IT security from an external perspective and make it comparable. How KPI-based ratings are developed, what they’re used for, and what their limitations are.

What is External Attack Surface Management (EASM)?

EASM Explained Simply: Definition, How It Works, How It Differs from Penetration Testing and Vulnerability Management, and Criteria for Selecting a Solution.

Supplier Risk & TPRM

Third- and Fourth-Party Risk: How Far Does the Supply Chain Reach?

Identifying Third-Party Risk and Fourth-Party Risk: Dependencies, concentrations, subcontractors, and appropriate control measures.

Continuously Monitor Supplier Risks: Methods, Key Figures, and Escalation

This is how you connect supplier monitoring, external signals, key figures, and clear escalation paths into a robust management process.

What security certificates should be requested from IT service providers?

Select and review security evidence for IT service providers: certificates, SOC, C5, tests, policies, incidents, and disaster recovery.

Check IT Security of Service Providers: Questionnaire, Evidence and External Signals

A practical assessment path for IT service providers: define scope, evaluate evidence, clarify external signals, and document decisions.

Security Questionnaire vs. Security Rating: Strengths, Limitations and Combination

Security questionnaire and security rating comparison: type of information, currency, evidence, effort, sources of error, and sensible combination.

Security Rating Services in Third Party Risk Management

How Security Rating Services assess external signals, support supplier processes, and where validation and dialogue are required.

Supplier Risk Assessment: Criteria, Scoring, and Assessment Methods

A comprehensible model for criticality, inherent risk, controls, evidence, and residual risk in supplier assessment.

Third-Party Risk Management: Tasks, Process, and Technical Data Sources

How companies capture third parties, evaluate them by criticality, control them, and monitor them throughout the entire business relationship.

en_USEnglish