
Blog
Discover in-depth articles and updates on the most important trends and current developments in the digital world and the technology sector.
Find the right content that sparks your interests, helps you master your challenges, or stimulates exciting thoughts.
Filter by category

How much does ISO 27001 cost? The certificate is the cheapest part
How much does ISO 27001 cost for an SME? Why the certificate is the smallest item, where the money goes and how to keep the scope small. Read our breakdown. Read blog
CISO vs. information security officer: the difference
CISO or information security officer? We explain the difference between the two roles, the thinking error behind it and which setup your SME needs. Read blog
ISG ISMS Obligation by 2026: Are You Really Affected?
Information security management system (ISMS) obligation by the end of 2026: Very few Swiss SMEs are directly affected. Check whether you are in scope before you panic with certifications. Read blog
When 'isolated' is only an assumption
An AI model escaped an isolated test environment and breached Hugging Face. The real lesson has nothing to do with AI, but rather with network isolation. Read blog
Where the name ODCUS comes from (and how to pronounce it)
ODCUS is inspired by Odysseus. What the Greek hero has to do with modern IT security, and why the journey to the destination is rarely a straight line. Read blog
How much does a security assessment cost? Honest numbers for SMEs
How much does a security assessment cost in Switzerland? Honest price ranges, real cost drivers, and how to recognize a fair offer. Book your initial consultation now. Read blog
nDSG Liability for Managing Directors: Who Really Pays
For data privacy violations, the company doesn't pay—you do, personally, up to 250,000 CHF. What the new FADP means for managing directors and how you can protect yourself. Read blog
How much does a CISO cost in Switzerland? Honest figures
How much does a CISO cost in Switzerland? We compare full-time employment against CISO as a Service to show you which model is truly worthwhile for your SME. Read blog
Reverse Information Paradox: Why You Pay Twice for AI
Satya Nadella and Alex Karp warn: Anyone using AI transfers knowledge to the provider. What lies behind the Reverse Information Paradox and what you can do about it. Read blog
The New Operating Layer: How AI is Changing Your Enterprise Architecture
AI isn't changing the organizational chart, but rather the information architecture. Why companies are getting an AI operating layer—and why context is at its core. Read blog
Security Assessment vs. Penetration Test: What Your SME Really Needs
Security Assessment or Penetration Test? We explain the difference, when your SME needs which one, and how to avoid wasting your security budget. Read blog
Security Switzerland 2026: What the report means for SMEs
The NDB situation report 'Switzerland's Security 2026' sounds like espionage and terror. Why the hybrid threat hits Swiss SMEs more directly than you think. Read blog
Cyber Liability on the Board of Directors: More Tools Won't Protect You
Board of Directors' liability in cybersecurity: Why, under Art. 717 CO and the new FADP, it is not more security that protects you, but documented due diligence. Read blog
Are we building castles again?
AI drastically shortens the time to exploit new vulnerabilities. Why SMEs are failing to keep up with patching and must reduce their attack surface now. Read blog
Scaling AI Agents: When Humans Become the Bottleneck
Multiple AI agents are running, you review every output, and everything bottlenecks at your end. Why you are the bottleneck and how Quality Gates make agents more autonomous. Read blog
Cover Your Ass: How a Culture of Self-Protection Hollows Out Companies from Within
CYA culture doesn’t arise from cowardice, but from rational adaptation to systems that punish mistakes. What it costs and how it spreads. Read blog
Fractional CISO, vCISO, or CISOaaS: What’s really behind it?
Three terms, three different models. What vCISO, Fractional CISO, and CISOaaS mean, which model is right when, and what you should pay attention to when choosing. Read blog
Why IT operations do not replace a security strategy
Good IT is not enough. What the security leadership gap is, when it becomes a problem, and what a fractional CISO concretely changes for Swiss SMEs. Read blog
Build, Buy, or Outsource: The Decision Nobody Gets Right
71% of internal IT builds fail. The alternative? Not much better. What really goes wrong in the build-vs-buy decision—and how to do it better. Read blog
Supply Chain Security: The Blind Spot in Your IT Security
Your firewall won’t protect you from the next SolarWinds. Why supply chain security is the biggest blind spot — and what you can do now. Read blog
Why AI Strategies Fail: The 5 Most Common Mistakes
AI strategy often fails not because of the technology, but because of organizational mistakes. The 5 most common patterns—and how to avoid them. Read blog
IT Vendor Contract Clauses: 5 Points Your Service Provider Won’t Want to Negotiate
These 5 IT vendor contract clauses really protect you — but hardly any service provider offers them voluntarily. Here’s what you should demand. Read blog
SaaS Sprawl: Why Your Company Is Paying Too Much
80–120 SaaS tools per SME, but IT knows only half of them. We show how SaaS sprawl happens and how you can recover 30–40% of the costs. Read blog
The Hidden IT Cost Driver: Getting License Management Right
IT License Management: How to uncover shelfware, zombie licenses, and tier mismatches and permanently save 15–30% on software costs. Read blog
IT Cost Management Framework: From Cost Center to Management Tool
Don’t just reduce IT costs—manage them strategically. Our framework shows how SMEs can build real cost control in 5 steps. Read blog
IT as a Business Advantage: Controllable, Secure, Cost-Efficient
IT is not a cost center—it is a competitive advantage. We show what Business Centric IT looks like in practice and what that means for your company. Read blog
The AI Competence Team: How to Build AI Expertise Across the Organization
AI initiatives fizzle out because they depend on individual people. Here is the pragmatic AI competency team model for SMEs - small, effective, without overhead. Read blog
Why SME IT Looks the Same Everywhere, and What You Can Do About It
SME IT looks the same everywhere. Not because it’s best practice, but because MSP standards, vendor marketing, and a lack of strategy are all pushing in the same direction. Read blog
EU AI Act: What Swiss companies need to know now
The EU AI Act also affects Swiss companies. Risk categories, timeline, and concrete steps for implementation. Read blog
The 30-minute IT assessment for managing directors
5 strategic questions that every managing director should be able to answer in 30 minutes. Read blog
Cybersecurity for CFOs: What You Really Need to Know
CFOs don’t need technical cybersecurity expertise—just the right questions. What you, as a CFO, need to know about cyber risk, costs, and insurability. Read blog
Cloud Repatriation: When Pulling Back from the Cloud Makes Sense
Cloud repatriation saves Swiss companies 30–40% on stable workloads compared to the public cloud. When moving back pays off—and how to calculate it. Read blog
Cyber risk is just one of many: how to classify it correctly
Cyber risk is real — but it is only one of many business risks. How to assess it proportionately and allocate your budget correctly. Read blog
Legacy System Liabilities: What Your Legacy Systems Really Cost
Legacy System Costs: Why your legacy system is not an IT problem, but a financial risk. Read blog
nDSG: The new Swiss Data Protection Act and what it means for your IT
nDSG Swiss Data Protection Act: What has changed since 2023, how it differs from the GDPR, and what Swiss SMEs now need to do specifically. Read blog
Data classification: Which of your data is truly worth protecting?
Implement data classification pragmatically: four protection levels, concrete measures, and a half-day workshop as a starting point. For SMEs that need structure rather than theory. Read blog
AI Agents in Companies: What They Can Do — and What They (Still) Can’t
AI agents are more than chatbots, but they are not a cure-all. We show where agentic AI works today, where it fails, and how you can get started with the right pilot project. Read blog
Board-Ready IT: How IT Leaders Build Trust in the Boardroom
Board-ready IT starts with the right language. Here’s how to communicate as an IT leader with the board of directors — clearly, credibly, and on equal footing. Read blog
The IT Maturity Check: Where does your company really stand?
Assess IT maturity yourself: 5 dimensions, 4 stages, 1 clear picture. Find out where your company really stands—before something breaks. Read blog
Incident Response: Are you ready for an emergency?
A cyberattack can affect even well-protected companies. How up to date is your incident response plan, and has it ever been tested under real-world conditions? Read blog
Integrated Compliance Framework: Why the next audit must not become a project
Compliance as a project doesn’t work — as an ongoing operation, it does. Here’s how to permanently integrate compliance requirements into your processes. Read blog
IT cost allocation: How you finally know what you're paying for
IT cost allocation makes IT expenses visible by department. We explain showback, chargeback, and how you can get started pragmatically. Read blog
How to Read an IT Quote Correctly: 7 Places Where the Money Is Hidden
IT offers are intentionally difficult to compare. 7 places where costs are hidden, plus the checklist you can use to review any quote in 30 minutes. Read blog
AI Training for Employees: The Training That Becomes Mandatory
EU AI Act Article 4 makes AI training mandatory. What real AI literacy is and how to get started. Read blog
Prioritizing AI Use Cases: From Hype to Value Creation
Prioritizing AI use cases: 2x2 matrix, quick wins, and an evaluation framework from practice. Read blog
Cyber insurance: What you need, what you pay, and what is never covered
Cyber insurance for SMEs: What policies really cover, which exclusions can become costly in an emergency, and how you can lower premiums through better security. Read blog
FinOps: Why Cloud Costs Need Their Own Discipline
FinOps is more than just saving on cloud costs. How Swiss SMEs can get their cloud spending under control through transparency, clear accountability, and a monthly review. Read blog
IT Governance for SMEs: Structure without bureaucracy
IT governance for SMEs doesn’t have to be complicated. In five steps, establish clear IT decision-making structures that are truly put into practice. Pragmatic, without bureaucracy. Read blog
IT Operating Model: How to properly structure your IT organization
IT operating model for SMEs: How to clarify what stays in-house, what is outsourced, and who makes IT decisions. Practical, with a concrete real-world example. Read blog
Multi-vendor strategy: How many IT partners are enough?
Multi-vendor strategy for SMEs: The four-level model for three to five IT partners, with a decision-making framework and concrete guardrails against dependency. Read blog
AI Governance: Why Your Company Needs Rules for AI Now
Your employees are using AI, but without rules. How to build a pragmatic AI governance framework in 4 weeks that protects without slowing you down. Read blog
Cyber Resilience Act: What changes for software manufacturers and IT buyers
The EU Cyber Resilience Act makes SBOM, Security by Design, and CE marking mandatory. What Swiss software manufacturers and IT buyers need to know now. Read blog
Vendor Checklist: 15 Questions You Should Ask Your IT Service Provider
15 questions for your IT vendor evaluation that don’t appear in any standard RFP. Three blind spots that make all the difference. Read blog
IT Sourcing for SMEs: The Model That Fits You
IT sourcing decision guide for Swiss SMEs: four models, five criteria, common mistakes. Which model is right for your situation? Read blog
How to build a pragmatic ISMS (without losing your sanity)
An ISMS doesn't have to be complicated. Here is the pragmatic approach for SMEs: clear scope, phased implementation, and a system that fits the company. Read blog
How to Make IT Decisions That Don't End in Disaster
49% of IT project failures are caused by poor vendor selection. The 5 decision-making traps - and how to escape them. Read blog
AI in SMEs: Between ChatGPT Chaos and Real Business Value
Many SMEs buy AI tools before they know which problem they want to solve. How to structure your first AI pilot so it delivers real value. Read blog
Shadow IT: The symptom you think is the problem
80% of employees use shadow IT – despite policies and training. The uncomfortable truth: shadow IT is not the problem. It is a symptom. Read blog
Cloud costs out of control? Here's how to achieve transparency
84% struggle with cloud costs, 27-32% are wasted. Only 30% can identify what they are paying for. The path to transparency and 25-40% savings. Read blog
The Invisible Mortgage: Understanding and Managing Technical Debt
Technical debt costs large corporations an average of 370 million dollars annually. A concept your CFO needs to understand. Read blog
Pragmatic Cybersecurity: Why Fewer Tools Often Mean More Protection
65% have too many security tools. 74% of ransomware victims are juggling too many. The solution? Consolidation provides 4x ROI and 74 days faster detection. Read blog
The IT Lies Everyone Tells You
The 4 biggest IT lies that vendors and consultants like to tell – and what really lies behind them. With specific questions that uncover the truth. Read blog
The 5 Warning Signs Before Every IT Disaster
75% of project participants know that their project will fail. They just don't say it. The 5 warning signs you must not ignore. Read blog
What we find in every IT audit
The 7 IT issues we find in every SME – and why it's not your fault. With quick wins that cost nothing. Read blog
Why your IT projects always end up costing more than planned
70% of IT projects exceed their budget. Discover the structural reasons for cost overruns and how to budget realistically. Read blog
The AI Readiness Check: Is your company ready for AI?
AI projects fail not because of the technology, but because the fundamentals are missing. Our 5-dimension check shows whether your company is ready for AI. Read blog
Allocate the Security Budget Correctly: Where Your Money Has the Greatest Impact
80% of your security effectiveness comes from 20% of the measures. Find out how Swiss SMEs prioritize their security budget—with frameworks and concrete figures. Read blog
Minimum Viable Operations: Why 70% Capacity is More Valuable Than Perfect Recovery
Perfect redundancy is priceless. MVO defines the minimum to continue working. We show you how to develop fallback options for critical processes. Read blog
Crisis Decisions in 15 Minutes: How to Replace Chaos with Structure
In times of crisis, speed matters more than perfection. We show you how to build clear decision-making structures that work under pressure. Read blog
Why Your Business Continuity Plans Fail in Case of Emergency
Most BC plans don't fail due to missing documents but because of the wrong focus. We'll show you why IT-focused DR plans won't save your business. Read blog
NIS2 and FINMA as Competitive Advantage: How to Turn Compliance into a Resilience Framework
Regulation as a burden? Or as a checklist for what you need anyway? We'll show you how NIS2 and FINMA structure your operational resilience. Read blog
The 5 Dimensions of Operational Resilience: A Framework for Businesses
Operational resilience goes beyond IT disaster recovery. We will show you the 5 dimensions that truly make your company resilient. Read blog
CISO-as-a-Service: How medium-sized companies benefit from external security expertise
Medium-sized companies need security leadership but cannot afford a full-time CISO. This is how CISO-as-a-Service works in practice. Read blog
"We urgently need AI": Why most projects fail
More than two-thirds of AI projects do not deliver the expected ROI. Here you'll learn why and how to do it differently. Read blog
Your supplier was hacked and now you're affected as well
Your security is only as strong as your weakest supplier. SolarWinds, MOVEit, Log4j - learn here how to manage your supplier risk. Read blog
Outsourcing saves money. Or does it?
Outsourcing seems cheaper - until you add everything up. Discover here what in-house and outsourcing actually cost. Read blog
You want to change, but you can't
Vendor lock-in costs you money, flexibility, and bargaining power. Find out here how to identify lock-in—and how to get out. Read blog
The old system still works, but for how long?
Legacy systems cost more than you think. Here, you'll find out when you should migrate, replace, or keep them—and how to make the right decision. Read blog
You pay for 100 licenses, but only 40 are used
30% of your SaaS costs are probably wasted. Here’s where the money is leaking—and how you can recover it. Read blog
You have chosen the wrong MSP and now you are
A wrong MSP can cost you years of frustration. Learn how to find the right one - and which warning signs should immediately make you move on. Read blog
Business Impact Analysis: Identifying Critical Business Processes
Most companies do not know which processes are truly critical to their business. A Business Impact Analysis provides clarity – here is the practical introduction. Read blog
NIS2 Directive for Swiss Companies
NIS2 Directive Switzerland: Practical implementation guide for Swiss companies. Requirements, deadlines, penalties, and implementation roadmap. Learn more now. Read blog
Your IT project is statistically likely to fail
70% of all IT projects miss the budget, deadline, or scope. Learn here why - and how you can be among the successful 30%. Read blog
Reduce Cloud Costs - 15 Immediately Actionable FinOps Strategies for SMEs
30% of your cloud costs are probably wasted. Here are 7 strategies to save immediately without sacrificing performance. Read blog
Digital Sovereignty for Swiss Companies - Between EU Regulation and Local Requirements
As a Swiss company, do you think GDPR doesn't affect you? That's incorrect. Here you will learn what digital sovereignty means—and why it protects your business. Read blog
In times of identity-based security – is the network still necessary?
Identity-based security or network security? Discover why you don't have to choose between them and how modern IT architectures combine both approaches to provide genuine protection. Read blog
Is it cheaper to recover after a ransomware attack or to rebuild?
Is it cheaper to recover from a ransomware attack or to rebuild? We explain the true costs, risks, and decision-making criteria—and why the seemingly cheaper option often turns out to be the most expensive. Read blog
Why Your Network Security Model Is Broken
Learn about the 7 strategic changes for modern network security that treat every access request as untrusted. Discover why traditional perimeter security fails and how to build resilience in cloud-first environments. Read blog
Zero Trust Transformation: Where do I actually start?
Approaching Zero Trust Migration Strategically: A Practical Guide for a Step-by-Step Transition. Learn how to integrate legacy systems and avoid common mistakes – from practice for practice. Read blog
Zero Trust Demystified: What the Security Concept Can Truly Deliver and What It Cannot
Demystifying Zero Trust Architecture: What really lies behind the security concept? We'll dispel the myths and show you how to practically implement Zero Trust without replacing your entire network. Read blog
Why Most Risk Analyses Fail
Learn how to conduct effective cybersecurity risk analyses according to NIST 800-30. A practical guide to identifying threats, vulnerabilities, and protecting corporate assets. Read blog
Crown Jewel Analysis - Focus on What Really Matters
Many companies allocate their security budget using a scattergun approach. A bit of firewall here, some antivirus there... and then the attack hits exactly the system that keeps the business running. ... Read blog
CISO-as-a-Service – Leadership in cybersecurity when it matters
3.5 million security experts are missing worldwide. CISO-as-a-Service provides SMEs access to top expertise without a full-time position. Flexible, scalable, immediately effective. Read blog
Jaguar Land Rover Cyber Attack – A Wake-Up Call for Business Risk Management
Jaguar Land Rover lost hundreds of millions due to a cyber attack. What companies need to learn from this – and how they can truly protect themselves. Read blog
Why IT Excellence should be part of your IT strategy
IT excellence transforms IT from a cost center into an innovation engine. Learn how strategic IT transformation enhances business value and secures competitive advantages. Read blog
Digital Transformation Beyond Buzzwords: The 5 Dimensions of Successful Digitalization
60-75% of all digitization projects fail. Not due to the technology – but due to five other factors. Here you will learn what they are. Read blog
How companies can actually use AI sensibly (without all the hype)
Forget the AI hype. Gain practical insights into how artificial intelligence can truly enhance your business operations – no overnight miracles, just real results. Read blog
The Real Cost of Being Unprepared for Ransomware
Ransomware recovery costs an average of 5.13 million dollars and 24 days of downtime. Discover how prepared companies can recover faster and more cost-effectively. Read blog
Future-proof thanks to perimeterless cybersecurity
Cloud, remote work, and mobile-first approaches are making traditional security models obsolete. Discover perimeter-less cybersecurity strategies with Zero Trust. Read blogNo articles found. Adjust your search or reset the filter.
Join us on the journey
Effortlessly schedule a conversation and discover how we bring success in the digital world to your company.
