Important Information from
Regarding Your IT Security
Important Information from
Regarding Your IT Security

Newsletter: New Partners. New Solutions. Greater Security.

We were at it-sa in Nuremberg and picked out the most exciting security topics for you!

There was plenty to discover at this year’s it-sa, and to help you take full advantage of it right away, we’re not only highlighting these topics in our latest newsletter but have also already established partnerships with the vendors. This ensures that you have access to solutions that will take your IT security to the next level.
Here are the new topics we’d like to share with you:

DriveLock

DriveLock is a comprehensive European IT security solution that helps businesses protect their endpoints, data, and applications from cyberattacks and data loss—either on-premises or via the cloud.

🛡️ What is DriveLock?

DriveLock is a German IT security product that operates on the Zero Trust principle (“never trust, always verify”). It offers protection against cyber threats through a modular platform called HYPERSECURE, which is available both on-premises and as a cloud service. DriveLock DriveLock.

🔧 Overview of Key Features

  • Device Control
  • Monitors data flow through USB ports and other interfaces to prevent unauthorized data transfers.
  • Application Control
  • Prevents unknown or malicious programs from running by using whitelisting.
  • BitLocker Management
  • Centralizes the management of Windows Drive Encryption and securely stores keys.
  • Encryption Solutions
  • Encrypts files, hard drives, and portable storage devices to protect sensitive information.
  • Defender Management
  • Optimizes and manages the security settings for Microsoft Defender and other Windows security features.
  • Security Awareness
  • Integrates training and safety tips directly into the work environment to enhance employee safety awareness.
  • Vulnerability Management
  • Identifies vulnerabilities on endpoints and helps resolve them.
  • Risk and Compliance Monitoring
  • Monitors activity on end devices and helps ensure compliance with legal requirements.
  • DriveLock 365 Access Control
  • Controls file sharing in Microsoft 365 and prevents unintended data sharing DriveLock ProSoft GmbH.

☁️ Deployment options

  • On-premises
  • The software is installed and managed on-premises.
  • Managed Security Services (Cloud)
  • DriveLock hosts the solution in the cloud—ideal for scalability, lower costs, and easy management. DriveLock.

✅ Benefits for businesses

  • Flexible and modular – adapts to individual needs.
  • Made in Germany – ISO 27001 certified and recipient of multiple awards.
  • Zero Trust architecture – proactively protects against threats.
  • Centralized management – reduces effort and increases transparency.

Enclaive, LLC

Enclaive GmbH is a security platform for confidential data processing in multi-cloud environments that helps companies protect sensitive information even in insecure cloud infrastructures—without requiring changes to code or existing processes.

🧩 Key Components and Products

  • Vault
  • Centralized secret management for multi-cloud environments. Keys are managed outside the cloud to enhance security and control. enclaive.io.
  • Nitrides
  • Identity management for workloads. Only verified applications are granted access to sensitive data on enclaive.io.
  • Buckypaper
  • Secure virtual machines for on-premises hosting. Migrations are possible without modifying the code. enclaive.io.
  • Dyneemes
  • Kubernetes clusters with a hardware-based security boundary for confidential applications: enclaive.io.
  • Confidential Nextcloud & GitLab
  • Host popular applications with zero-trust security and full data sovereignty at enclaive.io.
  • Confidential Databases
  • Databases with 3D encryption – protection at rest, in transit, and in use enclaive.io.

☁️ Provision and Use

  • Multi-cloud capable
    • Enclaive works across clouds and provides a universal platform for processing confidential data.
  • Zero Trust Architecture
    • Applications are protected from unauthorized access by infrastructure or cloud providers.
  • Flexible use
    • Available as a license, OEM product, or managed service through the Enclaive Confidential Multi Cloud Marketplace (EMCP) from Utimaco.

✅ Benefits for businesses

  • Data sovereignty – not even the cloud provider has access to the content.
  • No code changes are necessary—existing applications can be protected immediately.
  • Compliance with NIS2, DORA, and CRA – supports EU regulatory requirements for security insiders.
  • Ideal for sensitive industries—such as healthcare, finance, and public administration.

Valuze, LLC

Valuze GmbH is an IT service provider based in Fürth that supports companies in their digital transformation—with a focus on Microsoft cloud solutions, cybersecurity, and AI-powered services.

💼 Core Services

  • Protect your Microsoft 365 cloud environment and position it for the future
  • Conducting an in-depth analysis of settings and services
  • All results are evaluated and presented according to A-B-C criteria.
  • Based on this, corresponding recommendations for action are derived, which can be implemented at one’s discretion.

✅ Benefits for businesses

  • Protection of sensitive data.
  • High security through vulnerability remediation.
  • Sensitive data is essential and must be protected in every company. It is important to identify it and map its flow.
  • Determine who, when, where, why, and how this data is accessed, and how it can be processed

✅ Zero Trust.

  • Don't trust anyone.
  • The fewer rights, permissions, and access privileges users and applications have, the more secure your company data will be.
  • This data-centric approach is based on permissions and access rights tailored to roles, resources, and applications.
  • This greatly improves the security of your Microsoft environment.
  • Third-party services are traditional entry points and are also being reviewed.

Your prize:

  • Lean Management & Continuous Improvement.
  • Streamlined processes and continuous improvement.
  • Preventing and eliminating waste of resources, thereby reducing costs within the company.
  • Improving environmental performance and minimizing lifecycle costs.
  • Constantly changing conditions make regular adjustments and reviews necessary. This ensures that processes always run as smoothly and efficiently as possible

EXCERPT FROM THE SCOPE OF THE ANALYSIS

Global Tenant Settings & Security Management

  • A general review of compliance-critical settings, current user permissions, and global user and group policies, based on a best-practice approach.
  • Other areas include mobile devices, Defender Services (if licensed), and monitoring for current security incidents. If necessary, we also assess hybrid infrastructures.

Exchange Online/Server

  • General analysis of Exchange settings, the mail server, and, if necessary, the hybrid configuration.
  • Review of patches and security policies, as well as global mailbox settings such as mailbox auditing

Teams, SharePoint, and OneDrive

  • The policies governing sharing functions and policies for collaborating with external staff will be reviewed
  • Files shared externally
  • Activity Analysis of Current SharePoint Sites
  • Activity Analytics for Microsoft Teams

Azure Active Directory

  • Review of password and authentication policies (such as multi-factor authentication), service principals
  • Analysis of enterprise applications. Guest permissions and access by external users are also reviewed

Search for Compliance Management Tools

We have reviewed the following for our customers:

SECJUR

Secjur is a German legal tech solution that, through its Digital Compliance Office, helps companies meet data protection, information security, and other regulatory requirements—without complex Excel spreadsheets or expensive consultants.

🔧 Main Features

  • Automated compliance workflows and step-by-step wizards guide users through certification processes such as ISO 27001 or GDPR.
  • Custom Frameworks Companies can define their own compliance standards or combine existing ones.
  • Cross-mapping: Linking different standards to simplify audits and documentation.
  • AI-powered document analysis automates the review and structuring of legal content.
  • Central Platform for Legal & Compliance All tasks, deadlines, and documents are available digitally and can be accessed from anywhere.
  • Secjur is particularly well-suited for startups, SMEs, and organizations that want to achieve compliance quickly and systematically—even without their own legal department or CIS

Dataguard

DataGuard is a German company that offers a combination of Software-as-a-Service (SaaS) and personalized consulting. Its goal is to make data protection and IT security accessible and actionable for businesses of all sizes—without complex processes or prior legal knowledge.

🔧 Key Solutions

  • Privacy-as-a-Service: Support for GDPR implementation, including data protection documentation, training, and an external data protection officer.
  • Information Security-as-a-Service: Support for the implementation of an ISMS (Information Security Management System), e.g., in accordance with ISO 27001 or TISAX.
  • Compliance-as-a-Service: Support with regulatory requirements such as NIS2, the Supply Chain Act, or the Whistleblower Directive.
  • Compliance Management Platform: A digital interface for managing all tasks, deadlines, documents, and actions—including audit preparation

Formalize

Formalize is a RegTech provider based in Denmark that specializes in the digitization and automation of compliance processes. The platform is designed for companies of all sizes and offers solutions for information security, data protection, and whistleblower protection.

🔧 Main Features

  • Compliance Operations Platform: Management and implementation of standards such as NIS2, DORA, ISO 27001, and GDPR—including risk and incident management.
  • Audit and Form Builder: Creation of customized audit processes and forms for documentation and tracking.
  • Supplier Audits & Risk Management Automated assessment and monitoring of third-party suppliers and internal risks.
  • Custom Frameworks & Cross-Mapping: Create your own compliance frameworks and link them across systems.
  • Dashboards & Reporting: Real-time overview of risks, incidents, and actions—ideal for management and stakeholders

Would you like to receive more information about IT security?

Then why not get in touch with our experts?

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert