Sarah Berger

Sarah Berger

Sarah Berger is an expert for information security and open source software compliance.

The State of IT Security in Germany 2024

The State of IT Security in Germany 2024

The new BSI report on IT security in 2024 documents yet another year of increasing cyber threats. The report clearly shows that IT security is becoming more important every day and has long since become a matter for senior management. The daily threat posed by cyberattacks is diverse and increasingly systemically relevant due to attacks on critical infrastructure.

Read More
How ISO 27001 and Open Source Standards Together Strengthen Security and Compliance

How ISO 27001 and Open Source Standards Together Strengthen Security and Compliance

Open source software is no longer a niche topic—it’s a fundamental part of modern IT architectures. Today, hardly any software project is developed without using open source components. At the same time, companies face growing regulatory pressure to systematically and transparently manage information security—such as through a certified Information Security Management System (ISMS) according to ISO/IEC 27001.

Read More
From Licensing to Security with ISO/IEC 18974

From Licensing to Security with ISO/IEC 18974

What do the security incidents Spring4Shell, OpenSSL Heartbleed, and the XZ Utils backdoor have in common? They all involved open source software components—and all led to significant security breaches through tampered code within those components. These are just a few examples that show how vulnerable our software supply chains are today. The use of open source software components has become an integral part of modern software development.

Read More
ISO/IEC 5230 as the Foundation for Secure Open Source Management

ISO/IEC 5230 as the Foundation for Secure Open Source Management

Every day, over 20,000 new open source software components are released. A modern software project without open source is virtually unthinkable. But with the many advantages also come responsibilities: What license applies to which code? What needs to be shipped alongside it? What legal or security risks are involved? When companies use open source at scale, they need clear and repeatable processes. That’s exactly where ISO/IEC 5230 comes in.

Read More
Cyber Resilience Act: How Companies Can Prepare for the New Security Requirements

Cyber Resilience Act: How Companies Can Prepare for the New Security Requirements

The number of digital products has grown significantly in recent years—whether SaaS platforms, connected consumer devices, or industrial systems. However, many of these products have historically lacked adequate cybersecurity, which has led to serious attacks. The Cyber Resilience Act (CRA) is the first EU regulation that sets minimum cybersecurity standards for all connected products available on the European market.

Read More
SBOM and the Cyber Resilience Act

SBOM and the Cyber Resilience Act

The Cyber Resilience Act is the first European regulation to define a minimum level of cybersecurity for all connected products available on the EU market. This includes not only IoT devices, but also SaaS products and smartphone apps. As a result, virtually all software vendors need to address the Cyber Resilience Act.

Read More
What is Software Composition Analysis (SCA)?

What is Software Composition Analysis (SCA)?

The increasing use of open source and third-party components has brought significant advantages—faster development and cost savings among them. However, these benefits come with risks to security and compliance. Software Composition Analysis (SCA) helps identify and mitigate these risks.

Read More
SBOM: The Foundation for Secure Software Supply Chains

SBOM: The Foundation for Secure Software Supply Chains

When shopping for groceries, we almost always look at the back of the package to study the list of ingredients. After all, as consumers, we want to know exactly what’s in our food. Over the past years and decades, labeling requirements have become significantly stricter.

Read More