Übersicht-Illu Cybersicherheit

Cyber-secure – concise and clear

Cyberattacks no longer target only large corporations—small and medium-sized enterprises are also at risk. With the campaign "Cyber-secure – concise and clear," the German Chamber of Commerce and Industry (DIHK) provides understandable guidelines, practical assistance, and monthly podcasts to help integrate IT security into everyday business operations.

In times of growing digital interconnectedness, businesses of all sizes are increasingly becoming targets of professional cybercriminals. Protecting sensitive data and IT infrastructures is no longer just a technical issue—it is crucial in determining companies' competitiveness and future viability. The German Chamber of Commerce and Industry (DIHK) offers practical insights into essential considerations for businesses and highlights specific steps to identify and counter risks early on.

Cyberattacks have become a commonplace challenge in the business world—their methods are increasingly sophisticated, and their impacts ever more severe. No longer limited to large corporations, small and medium-sized enterprises as well as organizations are increasingly targeted by cybercriminals. IT system attacks, data theft, or digital extortion can disrupt production processes and significantly damage the trust of customers and business partners.

To support companies in strengthening their digital resilience, the German Chamber of Commerce and Industry (DIHK) consolidates practical information on cybersecurity on this page. The goal is to better evaluate risks and provide actionable recommendations, regardless of the size or technical setup of a company. The emphasis is on implementable measures that can be seamlessly integrated into daily business activities.

Importantly, the focus is not solely on technical solutions. Cybersecurity demands clear accountabilities, appropriate organizational structures, and well-informed staff. Even straightforward steps like regular data backups, secure access rules, or heightened vigilance with emails can significantly reduce vulnerability.

Complementing the written resources, DIHK offers a podcast series that delves into specific aspects of cybersecurity. In these episodes, DIHK cybersecurity expert Katrin Sobania converses with Prof. Dr. Sachar Paulus, Professor of IT Security at the Mannheim University of Applied Sciences, about current threats and practical protective strategies. The central theme is always how IT security can be realistically and effectively implemented in companies.

About the Person

Prof. Dr. Sachar Paulus is a Professor of IT Security at the Mannheim University of Applied Sciences and has been working for many years on how to implement IT security appropriately in smaller companies.

Learn more

 

The podcast episodes are released monthly, addressing various topics across the entire security process—from prevention and preparation to emergency response in IT incidents. The latest episode is available on this page.

Relevant in topic:
Key areas:
  • Cybersicherheit

All articles of this campaign

Einsen und Nullen bilden eine Waage

How to Prepare: Which Laws Do I Have to Comply With? What Awaits Me?

To address the growing threat of cyberattacks, many new laws have been enacted in recent years – in addition to the regulations that have been in place for some time.

Frau tippt auf Taschenrechner rum

How to Prepare: Cybersecurity: Cost Driver or Cost Saver?

Cybersecurity measures should always provide value. Instead of debating liability, it is more effective to illustrate which business processes can be digitised or enabled by appropriate protective measures (and thus assign costs accordingly). In doing so, these measures directly contribute to...

Zwei Personen werten Diagramme und Daten aus

How do I prepare: How to perform a cybersecurity risk analysis simply and pragmatically?

A cybersecurity risk analysis is actually quite simple: For each processing activity in your company, you record the major risks.

Zwei Computerprogrammierer arbeiten zusammen

Coordination made easy: How can my IT service provider help with cybersecurity?

IT service providers do not automatically consider cybersecurity. They face high performance pressure and often lack the time or budget for security measures.

Zwei Arbeiter beim Beladen und Kontrollieren eines Lastwagens

German Chamber of Commerce and Industry Coordination: What risks exist along the supply chain, and how can I contribute to cybersecurity with my products and services?

The connections to companies that are linked to one's enterprise along the supply chain are often particularly poorly protected.

Rotes Schloss über dem "Access Denied" steht

If it crashes... How do I protect myself against ransomware attacks?

The target of a ransomware attack is to encrypt a company’s data and thus extort the company. Attackers exploit insecure software, weak security settings and human weaknesses.

Rotes Warndreieck erscheint auf dem Bildschirm mit der Unterschrift "Malware"

When things go wrong... How do I prepare for IT emergencies? Why is waiting until the worst happens a bad idea? What should I do when something happens?

Assume that you will also be affected by a successful attack. Therefore, you should prepare yourself.

Zwei-Faktor-Authentifizierung mit Smartphone und Laptop

Specifically... How can I safeguard working practices in the home office and on the move?

During mobile work (whether at home or on the go), you are not surrounded by a protected corporate environment.

Serverraum

Specifically... How does the cloud help with my cybersecurity?

Providers of cloud solutions (at least above a certain size) must pay attention to good cybersecurity to avoid jeopardising their reputation.

Zwei Personen mit Schutzhelm stehen im Lager und schauen auf ein Display

Specifically... Why do my employees always behave insecurely?

Employees behave insecurely when a) they don’t understand the risks, b) they underestimate the risks, or c) they fear making mistakes.

Auf einer Platine leuchtet die Abkürzung "AI" (Artificial Intelligence)

Specifically... Can I use AI without compromising security?

Most Artificial Intelligences (AIs) are operated by private companies that profit from the knowledge of AI. Every document sent to an AI can be used to expand its knowledge—and is thus public. Therefore, you should never send confidential information to an AI. Moreover, the accuracy of AI...

Contact

Katrin, Sobania_quad

Dr. Katrin Sobania

Director Department for Information and Communication Technology | E-Government | Postal Services | IT Security