
Sarah Berger
Sarah Berger is an expert for information security and open source software compliance.
The State of IT Security in Germany 2024
The new BSI report on IT security in 2024 documents yet another year of increasing cyber threats. The report clearly shows that IT security is becoming more important every day and has long since become a matter for senior management. The daily threat posed by cyberattacks is diverse and increasingly systemically relevant due to attacks on critical infrastructure.
Read MoreHow ISO 27001 and Open Source Standards Together Strengthen Security and Compliance
Open source software is no longer a niche topic—it’s a fundamental part of modern IT architectures. Today, hardly any software project is developed without using open source components. At the same time, companies face growing regulatory pressure to systematically and transparently manage information security—such as through a certified Information Security Management System (ISMS) according to ISO/IEC 27001.
Read MoreFrom Licensing to Security with ISO/IEC 18974
What do the security incidents Spring4Shell, OpenSSL Heartbleed, and the XZ Utils backdoor have in common? They all involved open source software components—and all led to significant security breaches through tampered code within those components. These are just a few examples that show how vulnerable our software supply chains are today. The use of open source software components has become an integral part of modern software development.
Read MoreISO/IEC 5230 as the Foundation for Secure Open Source Management
Every day, over 20,000 new open source software components are released. A modern software project without open source is virtually unthinkable. But with the many advantages also come responsibilities: What license applies to which code? What needs to be shipped alongside it? What legal or security risks are involved? When companies use open source at scale, they need clear and repeatable processes. That’s exactly where ISO/IEC 5230 comes in.
Read MoreCyber Resilience Act: How Companies Can Prepare for the New Security Requirements
The number of digital products has grown significantly in recent years—whether SaaS platforms, connected consumer devices, or industrial systems. However, many of these products have historically lacked adequate cybersecurity, which has led to serious attacks. The Cyber Resilience Act (CRA) is the first EU regulation that sets minimum cybersecurity standards for all connected products available on the European market.
Read MoreSBOM and the Cyber Resilience Act
The Cyber Resilience Act is the first European regulation to define a minimum level of cybersecurity for all connected products available on the EU market. This includes not only IoT devices, but also SaaS products and smartphone apps. As a result, virtually all software vendors need to address the Cyber Resilience Act.
Read MoreWhat is Software Composition Analysis (SCA)?
The increasing use of open source and third-party components has brought significant advantages—faster development and cost savings among them. However, these benefits come with risks to security and compliance. Software Composition Analysis (SCA) helps identify and mitigate these risks.
Read MoreSBOM: The Foundation for Secure Software Supply Chains
When shopping for groceries, we almost always look at the back of the package to study the list of ingredients. After all, as consumers, we want to know exactly what’s in our food. Over the past years and decades, labeling requirements have become significantly stricter.
Read More