Wichtige Information
zu Ihrer IT-Sicherheit
Wichtige Information
zu Ihrer IT-Sicherheit

Newsletter: DriveLock: Our New Partner for Endpoint Security

How We'll Work with DriveLock to Secure Devices, Data, and Interfaces in Businesses Going Forward

A large proportion of successful attacks begin in the workplace: via an email, a USB drive, or an application that was never approved. That’s exactly where our new partner DriveLock comes in. With the German vendor’s HYPERSECURE platform, we’re adding an endpoint security solution to our portfolio that protects endpoints, data, and user behavior all at once. The difference lies in the sequence: Instead of detecting an attack after it’s already well underway, DriveLock ensures that it never even starts on the endpoint.

What matters to us is what matters to our customers: reduced risk and a business that keeps running even after a security incident. DriveLock already protects companies in over 33 countries, including those in the critical infrastructure, healthcare, defense, government, and legal sectors.

Five Building Blocks, One Security Strategy

DriveLock has a modular design, and each module addresses a problem that IT managers encounter in their day-to-day work. You can start where the risk is greatest and expand step by step. Since all modules run from a single console and through a single agent, protection increases without increasing the administrative burden.

Application Control (AC)

Over time, many company computers end up running significantly more software than the IT department has ever approved: tools brought in by users, legacy installations, and scripts. Each of these is a potential entry point for ransomware. Application Control flips the principle of a virus scanner on its head: only approved software is allowed. This also blocks malware for which no signature yet exists. An initial scan records the approved software inventory, after which the device is locked down. New software is added via a learning mode and integration with existing client and patch management systems, ensuring that maintenance doesn’t fall solely on the help desk. This aligns with a zero-trust approach at the endpoint.

USB flash drives, external hard drives, and other interfaces are a classic entry point in both directions. Malware enters the network through them, and confidential data leaks out through them, often without malicious intent. A policy-based ban is virtually impossible to enforce. Device Control technically specifies which devices are allowed to connect—down to the serial number and user group—and logs every access. This prevents data leakage and, in the event of an audit, provides verifiable evidence of who accessed which interface and when.

If a laptop containing unencrypted data is lost, it often results in a reportable incident involving deadlines, contact with authorities, and external communication. DriveLock centrally manages hard drive encryption, handles key management, and automates recovery via challenge-response if a password is forgotten. Upstream pre-boot authentication protects the system even before Windows starts, and removable storage devices can be force-encrypted using BitLocker To Go. As a result, lost hardware remains merely property damage and does not constitute a data protection incident.

No IT team can address all the vulnerabilities that are reported every day. That’s why it’s crucial to address the most critical ones first. The module identifies open security vulnerabilities and misconfigurations in the system inventory, assesses their criticality, and helps ensure that the most important ones are addressed first. This provides a reliable picture of the organization’s risk profile and, at the same time, the transparency required for audits.

Technical measures have only limited effectiveness if employees fall for phishing attempts, and AI-powered attacks make such emails harder to detect. DriveLock trains employees in short sessions integrated into their daily work routine, supplemented by phishing simulations, and provides verifiable proof of training success. A Human Risk Assessment also identifies where the actual risk lies within the organization. This reduces human risk associated with phishing and social engineering while simultaneously fulfilling the training requirements under NIS2 and DORA.

Security and Compliance in a Single Approach

In many companies, security and compliance requirements are treated as separate projects, which results in duplicate effort. DriveLock combines both: The measures that protect against attacks also provide the logs and documentation needed for audits. The platform supports compliance with NIS2, DORA, ISO 27001, TISAX, GDPR, and BSI Basic Protection—from policy implementation to ongoing logging and audit preparation.

Added to this is an aspect that is becoming increasingly important to many customers: DriveLock is a German technology that meets high data protection standards, supplemented by solutions from European partners. In this way, DriveLock ensures data sovereignty and transparent processes.

Would you like to effectively secure your endpoints while conveniently meeting your compliance requirements? As certified DriveLock partners, our experts will assess your current situation, tailor the modules to your needs, show you specific ways to implement them in your company, and support you throughout the entire process.

Would you like to receive more information about IT security?

Then why not get in touch with our experts?

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert

Sign up for our
Cyber Security Newsletter

Our newsletter keeps you up to date on the most important topics in IT security.
The content is created and curated specifically for you by our cybersecurity experts.

You are currently viewing a placeholder content from Mailjet. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information