EASM & Attack Surface
Fundamentals of External Attack Surface Management
What is a security rating?
Security ratings measure IT security from an external perspective and make it comparable. How KPI-based ratings are developed, what they’re used for, and what their limitations are.
What is External Attack Surface Management (EASM)?
EASM Explained Simply: Definition, How It Works, How It Differs from Penetration Testing and Vulnerability Management, and Criteria for Selecting a Solution.
Regulatory Affairs & Compliance
NIS2, DORA, KRITIS, and More: Explained in Simple Terms
Third-Party ICT Risk Under DORA: Obligations and Implementation
Information Registers, Contractual Clauses, Exit Strategies: What DORA Requires Regarding Third-Party ICT Risks and How to Implement These Obligations in Five Steps.
NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG
The Ten Risk Management Measures Under Section 30 of the BSIG: What Is Required, How to Implement Them Successfully, and How They Map to ISO 27001.
NIS2 and Supply Chain Security: Managing Third-Party Risks
NIS2 Makes Supply Chain Compliance Mandatory: Requirements Under Section 30 of the BSIG, a Comparison of Methods, and a 5-Step Workflow with Security Ratings and VRM.
DORA: The Digital Operational Resilience Act Explained
What the Digital Operational Resilience Act Covers: Scope, Five Pillars, BaFin Oversight, Sanctions, and How It Differs from the NIS2 Directive.
NIS2 Directive: What Companies Need to Know Now
The NIS2 Implementation Act has been in effect since December 6, 2025. An overview of sectors, size thresholds, obligations, fines, and BSI deadlines.


