A CASB makes SaaS usage visible and controllable: detect shadow IT, enforce policies, prevent data exfiltration.
Read term → A content delivery network serves web content via edge servers distributed around the world and thereby noticeably shortens load times. This article explains how caching and anycast work, what protective effect a CDN offers and where its limits lie.
Read term → CI/CD pipelines build and deliver software automatically, which makes them a target in their own right: whoever controls the pipeline controls the software. This article shows how to secure secrets, dependencies and artefacts, and why segmenting the build environment is part of it.
Read term → Cloud Detection and Response (CDR) detects ongoing attacks in cloud environments on the basis of telemetry from the control plane, identities and data flows. This article explains how it works and its typical scenarios, distinguishes CDR from EDR and shows how detection and containment work together.
Read term → Cloud migration refers to the planned relocation of applications and data into cloud environments. This article explains the 6R strategies, examines network and security aspects such as private connectivity and shows when lift-and-shift is worthwhile and when modernisation is the better choice.
Read term → Cloud on-ramps are private entrances to AWS, Azure and co. — predictable performance and costs instead of the public internet.
Read term → Cloud security covers all measures that protect data, applications and infrastructure in cloud environments against attacks and misconfigurations. This article explains the shared responsibility model, shows the key protection layers and describes how companies can use the cloud securely and in line with regulations.
Read term → Cloud Workload Protection Platforms (CWPP) protect virtual machines, containers and serverless functions across their entire lifecycle. This article explains how they work and where they are used, shows the difference from CSPM and describes why visibility and segmentation form the core of effective workload protection.
Read term → Colocation means: your own hardware in someone else’s data center — with professional infrastructure and direct cloud onramps.
Read term → Common Criteria is the international standard for evaluating and certifying the security properties of IT products. This article explains protection profiles and the evaluation assurance levels EAL1 through EAL7, describes the role of the BSI and shows how this product standard differs from ISO 27001.
Read term → Conditional access decides per login based on context: who, from which device, from where, at what risk?
Read term → Container orchestration automates the distribution, scaling and self-healing of containerized applications across many servers. This article explains the core functions, the role of Kubernetes as the de facto standard, typical use cases and the distinction between the orchestrator and the container runtime.
Read term → Container security protects applications from the image build through the registry to runtime. This article explains scanning, signatures, minimal privileges and isolation, shows typical use cases and compares the security model of containers with that of virtual machines.
Read term → Credential stuffing tests leaked passwords against your logins automatically — hitting wherever passwords are reused.
Read term → Cryptojacking steals compute for crypto mining: no encryption, no alarm — just silent costs.
Read term → CVE uniquely names known vulnerabilities, while CVSS rates their severity on a scale from 0 to 10. This article explains how the two systems work together, which metrics lie behind the score and why the CVSS value alone does not yet determine patch priority.
Read term → The cyber kill chain breaks attacks into phases — and shows that defenders can interrupt at every stage.
Read term → Cyber resilience describes a company's ability to remain operational under attack and to recover quickly after disruptions. The approach combines prevention with containment and recovery, and thereby places the question of how operations survive an incident at the center.
Read term → The CRA makes cybersecurity a product duty: manufacturers of digital products are accountable for security across the lifecycle.
Read term → A cyberattack is a targeted attempt to gain unauthorized access to IT systems and cause damage there. Most attacks follow a recurring sequence that defenders can interrupt at several points if they know it.
Read term → Cybersecurity refers to all technical and organizational measures to protect IT systems and data against attacks and misuse. At its center are the protection goals of confidentiality, integrity and availability, implemented through disciplines ranging from network security to identity protection.
Read term → Cybersecurity compliance refers to the demonstrable adherence to legal and contractual security requirements, from the GDPR through NIS2 and DORA to ISO 27001. This article classifies the most important frameworks, describes evidence and audits and explains why compliance and actual security are two different goals.
Read term →