IT topics that matter. Explained clearly.
Warnings, guides and honest assessments: written for people who make decisions, not for technicians.
AI-Driven Cyberattacks: What the Anthropic Case Means for Small and Medium-Sized Businesses
In November 2025, Anthropic disclosed an espionage campaign in which an AI tool carried out large parts of the attacks itself. What the case really shows and which protective measures matter now.
NIS 2 for Mid-Sized Companies: Who Is Affected and What to Do Now (as of July 2026)
The NIS 2 directive has been transposed into German law since December 2025, and around 29,500 companies are affected, many of them mid-sized. Based on the legal situation as of July 2026, this article explains who falls under the law, which duties and deadlines apply, and which steps let you approach implementation in a structured way.
Securing Microsoft 365: The Typical Gaps After a Standard Setup
A new Microsoft 365 tenant, meaning your company’s Microsoft 365 environment with all its accounts and data, is fully functional right after setup, but not automatically well secured. Six verifiable points show where the typical gaps lie and how to close them.
Recognizing phishing: seeing through attacks and responding correctly
Phishing does not target technology, it targets people. This guide shows which psychological levers attackers use, which channels attacks run through today, how to check for forgeries in concrete terms, what to do immediately after a click, and how to prepare your team without singling anyone out.
Critical security vulnerability in your VPN or remote access: the emergency plan for your business
When your VPN or remote access software has a critical security vulnerability, the order of your response counts at least as much as its speed. This emergency plan shows step by step what to do before, during, and after the incident.
Switching Your IT Service Provider: An Orderly Handover Instead of Starting Over Blind
Switching your IT service provider is not a breach of trust but sometimes the logical consequence of changed requirements. This guide shows how to recognize the right time, which access credentials and documents belong to you, and how a handover works in which no knowledge is lost.
The 3-2-1 Rule: How Data Backups Become Real Protection
Three copies, two types of storage, one copy off site: the 3-2-1 rule is the proven core of any data backup strategy. This article explains why one copy must be offline or immutable, why the restore test decides how a real emergency ends, and how to define recovery time and tolerable data loss for your business.
On-Premises Server or Cloud: A Decision Without Dogma
A server on your own premises or in the cloud: this question is often treated like a matter of faith. In fact, it can be answered with four sober criteria. This guide shows how to assess data, connectivity, costs, and outage risks, and why the answer usually turns out to be hybrid.
Passwords today: what has changed and what really matters
Longer passwords instead of cryptic character strings, no more forced changes, and in their place password managers, multi-factor authentication and passkeys: this guide explains what applies to passwords today and where it makes sense to start in your business.
AI in mid-sized businesses: where it really saves time and where it does not
Language models can save measurable time in everyday office work, but by no means everywhere. This article gives a sober assessment of which tasks are worthwhile today, which data may go into which tools, and how to scope a first project so that you can verify the benefit at the end.