Skip to main content

Search...

Security, Regulation & Compliance

Security testing and regulatory, standards-based, and compliance requirements for software quality.

Articles

Security is Everyone's Business
Security is Everyone's Business

Security is Everyone's Business

Explore software security best practices to enhance user trust in digital services and ensure data safety. Join us in prioritizing security.

Security Tests with Static Analysis
Security Tests with Static Analysis

Security Tests with Static Analysis

Enhance your code's security with static analysis security testing to detect flaws early and ensure quality software development.

Testing Complex E-Government Systems
Testing Complex E-Government Systems

Testing Complex E-Government Systems

Explore E-Government Systems Testing strategies to enhance software quality and usability for optimal user experiences.

Podcast Episodes

Strategy First: How AI Enters Regulated Medical Labs
Strategy First: How AI Enters Regulated Medical Labs

Strategy First: How AI Enters Regulated Medical Labs

AI in a regulated medical lab sounds like a compliance nightmare. Here is how a strategy-first approach made it work without breaking the rules.

Developing security requirements as a team
Developing security requirements as a team

Developing security requirements as a team

Security requirements stay abstract until a team defines what the system actually protects. CIA goals and threat modeling make it tangible.

Security tests for AI systems
Security tests for AI systems

Security tests for AI systems

AI systems can be tricked into revealing protected data through clever prompts. Where the points of attack lie and what OWASP recommends.

Practical and safe development with IEC 62443-4-1
Practical and safe development with IEC 62443-4-1

Practical and safe development with IEC 62443-4-1

Standards do not make secure software by themselves - but 62443-4-1 shows how security really belongs in the process from the very first design step.

Legal pitfalls in software contracts
Legal pitfalls in software contracts

Legal pitfalls in software contracts

Two missing sentences in a software contract can drive a company into bankruptcy. Why agile software projects end up as contracts for work.

Using open source securely
Using open source securely

Using open source securely

Anyone installing open source needs a bill of materials, since it makes up 80 to 95 percent of software. Licenses, gaps and the Cyber Resilience Act.

Stop Inventing Your Own Encryption
Stop Inventing Your Own Encryption

Stop Inventing Your Own Encryption

Security built in from the start beats security bolted on at the end. Here is why threat modeling, defense in depth, and secure defaults change everything.

Fuzzy Testing
Fuzzy Testing

Fuzzy Testing

Fuzzing sounds like chaos but is a method that reveals security gaps systematically. Targeted test data beats pure randomness in practice.

Nudging for more security
Nudging for more security

Nudging for more security

85 percent of cyberattacks start with a human error. How nudging leads users to safe behavior without forcing them.

Automated security checks
Automated security checks

Automated security checks

Pen tests at the end of a project always find the same headers, misconfigurations and gaps. Security in the pipeline cuts that to a handful.

Cyber Resilience Act (CRA)
Cyber Resilience Act (CRA)

Cyber Resilience Act (CRA)

Mechanical engineers and the Cyber Resilience Act: What companies can expect, where the real hurdles lie and why early action brings a concrete cost advantage.

Secure by Design
Secure by Design

Secure by Design

Security is often the last item on the agenda - and that is precisely the problem. What defense in depth, threat modeling and secure defaults really mean.

Security analyses
Security analyses

Security analyses

Why security in the development team hardly gets through despite a high level of awareness, and which approach really works in practice.

Court expert
Court expert

Court expert

Software acceptance usually checks functions only and nothing beyond that narrow scope. Whether up to 12,000 hidden bugs count as normal.

Zero Trust at Deutsche Telekom
Zero Trust at Deutsche Telekom

Zero Trust at Deutsche Telekom

Zero Trust is more than just a buzzword: if you don't define it yourself, you're talking past each other. What it means in concrete terms and where to start.

Automotive testing
Automotive testing

Automotive testing

In automotive testing a windshield wiper already counts as a safety-critical system. What that means for test methods and for standards.

Criminals find every loophole
Criminals find every loophole

Criminals find every loophole

Out of 73 universities audited, they had to abandon one in five because there were too many gaps. What this means for software security.