{"id":1006164,"date":"2025-06-23T12:31:18","date_gmt":"2025-06-23T10:31:18","guid":{"rendered":"https:\/\/www.teal-consulting.de\/2025\/06\/23\/stand-der-technik-teletrust-teil-1\/"},"modified":"2025-07-02T16:10:48","modified_gmt":"2025-07-02T14:10:48","slug":"state-of-the-art-teletrust-part-1","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2025\/06\/23\/state-of-the-art-teletrust-part-1\/","title":{"rendered":"State of the art \u2013 Analysis of the TeleTrusT guide (Part 1\/2)"},"content":{"rendered":"<div class=\"wpb-content-wrapper\" id=\"wpb-content-root\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text][\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]In our two-part series, we would like to discuss the current guidelines issued by the TeleTrusT working group and present our perspective. Let&#8217;s get started \ud83d\ude0a.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>\u201cState of the art\u201d &#8211; PART 1<\/h2>\n<p>&nbsp;<\/p>\n<h3>What does \u201cstate of the art\u201d mean in IT security\u2014and why is it so important now?<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]The IT security situation remains tense and pressure on companies is mounting: new legal requirements such as NIS-2, DORA, the GDPR, and the upcoming NIS2UmsuCG not only demand more security measures, but also proof of compliance. At the heart of many regulations is a term that sounds clear but is anything but unambiguous: <em>state of the art.<\/em><\/p>\n<p><em><strong>But what does that mean in concrete terms? What measures are considered appropriate today? And how can companies prove that their protective measures comply with current standards?<\/strong><\/em><\/p>\n<p>Answers can be found in the <strong>recently published \u201cState of the Art\u201d report from the German Federal Association for IT Security (TeleTrusT) \ud83d\ude80<\/strong>. The annually revised guide has long been regarded by experts as a valuable guide not only for KRITIS operators, but for all organizations that want to set up their IT security in a legally compliant, effective, and future-proof manner.<\/p>\n<p>In the following, we will shed light on what exactly TeleTrusT understands by \u201cstate of the art,\u201d which legal requirements must be observed, which technical and organizational measures companies should really implement today, and where exactly we at Teal can provide targeted support.[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; css=&#8221;.vc_custom_1750675759138{padding-top: 20px !important;padding-right: 20px !important;padding-bottom: 20px !important;padding-left: 20px !important;background-color: #0156AE !important;}&#8221; z_index=&#8221;&#8221;][vc_column][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3><span style=\"color: #ffffff;\">Who is TeleTrusT?<\/span><\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]<span style=\"color: #ffffff;\">The German Federal Association for IT Security (Bundesverband IT-Sicherheit e.V.), better known as <strong>TeleTrusT<\/strong>, is one of the most important competence networks for IT security in Germany and Europe. The association brings together experts from business, science, government, and law and promotes exchange on current security issues. With initiatives such as the \u201cIT Security made in Germany\u201d quality mark, numerous working groups, and publications, TeleTrusT plays a key role in shaping the discussion on practical security standards.<\/span><\/p>\n<p><span style=\"color: #ffffff;\">One central working group is the \u201cState of the Art\u201d working group. Its goal is to provide guidance, particularly on the question of what the state of the art means in terms of laws and regulations. The result is a regularly updated guide that systematically evaluates technical and organizational measures and supports companies in classification and implementation.<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>What is the current state of the art?<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]The term \u201cstate of the art\u201d sounds objective, but in practice it is often difficult to grasp. According to TeleTrusT, it refers to the best performance available on the market for a measure that is suitable for effectively achieving legal IT protection goals such as availability, confidentiality, and integrity. It is therefore not necessarily about the latest or most innovative solution, but rather about what has proven itself in a professional environment and actually provides protection.<\/p>\n<p>In comparison:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The state of science and research encompasses highly innovative solutions \u2013 often not yet ready for the market.<\/li>\n<li>The generally accepted rules of technology are proven methods \u2013 but may be outdated or easily vulnerable.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]What does this mean for companies? The state of the art is not a single measure, but always depends on the protection requirements, the threat situation, and the specific application. It can be achieved through a bundle of measures and must be regularly reviewed and adapted to remain effective.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>Which regulations require state-of-the-art technology?<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]The term \u201cstate of the art\u201d now appears in almost all relevant security and data protection regulations, even though it is never clearly defined there. As a result, companies must decide for themselves what exactly is \u2018appropriate\u2019 or \u201cnecessary,\u201d and this can quickly become a legal gray area.<\/p>\n<p>Some important examples:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>NIS 2 Directive:<\/strong> Far-reaching EU regulation with reporting obligations and requirements for security and risk management \u2013 including explicit consideration of the state of the art.<\/li>\n<li><strong>DORA:<\/strong> Mandatory for the financial sector and requires robust ICT risk management measures that must be \u201cappropriate\u201d and \u201cproper.\u201d<\/li>\n<li><strong>GDPR (Art. 32):<\/strong> Data protection by design (privacy by design) requires technical and organizational measures, taking into account risk, costs, and the state of the art.<\/li>\n<li><strong>BSI Act &amp; IT Security Act 2.0:<\/strong> Obliges KRITIS operators, but also companies of particular public interest (UBI), to implement technical and organizational measures, including verification.<\/li>\n<li><strong>TISAX, ISO 27001, BSI Basic Protection:<\/strong> Norms and standards that operationalize the state of the art in the form of concrete requirements or best practices.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Compliance with the state of the art is therefore not a \u201cnice to have,\u201d but a legally established minimum standard. And: Anyone who disregards it risks fines, liability issues, and loss of reputation.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Relevant building blocks for IT security<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]<strong>Teal specializes in identity protection.<\/strong> That is why we focus primarily on the topics described in the TeleTrusT guide, with which we have gained a wealth of experience over the past few years. In our view, the measures outlined in the following modules are essential for operating a modern and secure infrastructure.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>Password management<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]At first glance, password management seems relatively \u201ceasy\u201d to master. However, upon closer inspection, several questions arise for which there may be multiple solutions. At the same time, end users must be able to cope with the required specifications and, ideally, not be adversely affected by them. The same applies to password management for \u201cnon-human identities\u201d (service accounts) and administrative users, who are often a much more attractive target for attackers and are usually poorly secured.<\/p>\n<p>In the TeleTrusT guide, the chapters \u201c3.2.1 Authentication,\u201d \u201c3.2.2 Evaluation and enforcement of strong passwords,\u201d and \u201c3.2.3 Multi-factor authentication\u201d describe the secure handling of passwords.<\/p>\n<p>The assessment in the TeleTrusT report shows in the following two graphs that, compared to the 2023 assessment, the topics of \u201cevaluation and enforcement of strong passwords\u201d and \u201cmulti-factor authentication\u201d have become significantly more important.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_empty_space height=&#8221;20&#8243;][vc_empty_space height=&#8221;20&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner width=&#8221;1\/2&#8243;][vc_column_text css=&#8221;&#8221;]<strong><span style=\"color: #008081;\"><em>1: Evaluation and enforcement of strong passwords<\/em><\/span><\/strong><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1006138 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild1.png\" alt=\"\" width=\"471\" height=\"325\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild1.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild1-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild1-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild1-700x483.png 700w\" data-sizes=\"(max-width: 471px) 100vw, 471px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 471px; --smush-placeholder-aspect-ratio: 471\/325;\" \/>[\/vc_column_text][\/vc_column_inner][vc_column_inner width=&#8221;1\/2&#8243;][vc_column_text css=&#8221;&#8221;]<strong><span style=\"color: #008081;\"><em>2: Multifaktor-Authentifizierung<\/em><\/span><\/strong><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1006140 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild2.png\" alt=\"\" width=\"471\" height=\"325\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild2.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild2-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild2-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild2-700x483.png 700w\" data-sizes=\"(max-width: 471px) 100vw, 471px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 471px; --smush-placeholder-aspect-ratio: 471\/325;\" \/>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_empty_space height=&#8221;20&#8243;][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]The measures are primarily intended to prevent<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>other people from guessing weak passwords,<\/li>\n<li>stolen or known passwords from being used by others,<\/li>\n<li>and someone from stealing, misusing, or fraudulently using another person&#8217;s identity.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Authentication generally distinguishes between knowledge (e.g., a password), possession (e.g., a FIDO stick), and biometric characteristics (e.g., a fingerprint). The combination of these principles ensures authentication, but the following additional factors should also be taken into account:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>User accounts, and especially administrative users, must be secured with an additional authentication factor. Windows Hello for Business, Azure MFA, or SCAMA can help here.<\/li>\n<li>Using complex passwords is essential. Passwords should also be secured according to your individual protection needs. In a domain environment, Fine Grained Password Policies (FGPP) can be used here, for example.<\/li>\n<li>In addition, it is imperative to regularly check whether compromised passwords are in use. If this is the case, users must be informed and asked to change their passwords. Administrators can use commercial offerings such as Azure Password Protect or free offerings such as DSInternals.<\/li>\n<li>Regularly changing passwords for service accounts and functional users is an often neglected but essential security measure. Where possible, the use of Group Managed Service Accounts should be considered to automate this process. If this is not feasible, alternative automation solutions can significantly reduce the administrative effort. If this is also not feasible, the password change should at least be documented and specifically delegated to third parties, such as a service provider or trainee. In this way, the burden on administrators, who are already under considerable strain, can be specifically reduced.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>(3.2.5) Encryption of data carriers<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Encrypting data carriers is a tried-and-tested method for effectively protecting \u201cdata at rest.\u201d This measure is already widely used, particularly in the client sector, and prevents data loss if, for example, a laptop is stolen from a hotel room during a conference or similar event. The assessment of the TeleTrusT working group was already clear in 2023. Encrypting data carriers is an indispensable component of IT security. In the 2025 report, this measure has been rated even higher, which once again highlights its urgency.[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]<img decoding=\"async\" class=\"aligncenter wp-image-1006142 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild3.png\" alt=\"\" width=\"845\" height=\"583\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild3.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild3-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild3-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild3-700x483.png 700w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/583;\" \/>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Hard disk encryption has not yet been established across the board in the server sector. In our view, this is mainly due to the fact that for many years, it was only possible to encrypt guest systems on VMware hypervisors with additional software. However, this can now also be implemented with on-board tools \u2013 and should be implemented as standard as a matter of urgency.<\/p>\n<p>Companies using Hyper-V had advantages here from the outset: similar to the client sector, encryption with BitLocker could be used and combined effectively with pre-boot authentication. This requires a PIN to be entered before the system starts up, before the user can access it.<\/p>\n<p>Regardless of the technology used, it is essential to store the associated decryption keys securely and protect them reliably against unauthorized access. In the case of BitLocker, for example, backup in Active Directory is a good option. This enables help desk staff to provide effective support when needed, for example, if a PIN is forgotten or technical problems arise.<\/p>\n<p>In summary, this is a long-established security measure whose implementation should now be a matter of course in every company.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>(3.2.8) Protection of electronic data traffic with PKI<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]When information is exchanged,<strong> two things are of central importance<\/strong>. First, the recipient must be sure that the sender is actually the sender. Second, both parties must be sure that the message arrives at the recipient unchanged. To ensure both of these things, many companies <strong>operate a public key infrastructure<\/strong>, also known as a certificate authority. It is also possible to purchase trusted certificates from external providers. The TeleTrusT guide recommends this measure to protect against the following threats in particular:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Identity theft \/ falsification of identity<\/li>\n<li>Manipulation of the content of electronic messages or files<\/li>\n<li>Manipulation of the timing of messages or files<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]The measure has long been classified as state of the art and has been slightly upgraded again in the 2025 report:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1006144 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild4.png\" alt=\"\" width=\"845\" height=\"583\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild4.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild4-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild4-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild4-700x483.png 700w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/583;\" \/>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]However, anyone who operates their own certification authority should be aware that these systems are also targeted by attacks. Since domain controllers, among other things, also have certificates for encrypted communication, the certification authority is often the starting point for compromising the entire environment. Active Directory Domain Services (ADDS), for example, is Microsoft&#8217;s solution, which is often not operated securely. Historically grown systems, poor documentation, and high complexity make the system vulnerable to cyberattacks. We have addressed the various attack techniques on certification authorities and Active Directory in detail in a separate blog post: <a href=\"https:\/\/www.teal-consulting.de\/en\/2022\/04\/19\/pspki-audit\/\" target=\"_blank\" rel=\"noopener\">PSPKI Audit \u2013 Why you should analyze your PKI<\/a><\/p>\n<p>Even a relatively simple attack vector illustrates how essential it is to secure a PKI system. Attackers repeatedly exploit the possibility of issuing certificates with a so-called Subject Alternative Name (SAN). Many certificate templates allow the use of such alternative names, for example to secure web servers or similar services.<\/p>\n<p>Problems arise when authorized users can independently issue certificates with arbitrary SANs \u2013 such as administrator@domainname \u2013 and use them for authentication. In such cases, the PKI system quickly becomes a gateway for attacks.<br \/>\nTherefore, the resilience of the public key infrastructure should be checked regularly and with the highest priority.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>(3.2.21) System hardening<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]By default, many operating systems\u2014whether Windows, Linux, or appliances\u2014are anything but securely configured. Unused services, open interfaces, and weak default settings provide an unnecessarily large attack surface. This is exactly where system hardening comes in: <strong>it ensures targeted protection of systems by disabling unnecessary functions, restricting interfaces, and enforcing secure configurations<\/strong>.<\/p>\n<p><strong>The principle: only what is really needed remains active<\/strong> \u2013 everything else is deactivated. This applies to physical servers as well as virtual machines, cloud instances, or special management clients such as Privileged Access Workstations (PAW).<\/p>\n<p>Once properly implemented, system hardening not only protects against the infiltration of malware or ransomware, but also against identity theft, data leakage, sabotage, and the misuse of your infrastructure \u2013 for example, for crypto mining or sending spam. It also makes it more difficult for attackers to carry out lateral movement, i.e., the undetected migration from compromised systems to other targets in the network.<\/p>\n<p><strong>In practice, system hardening is increasingly becoming an indispensable part of any IT security strategy<\/strong>. This is also evident from the latest TeleTrusT report: Compared to 2023, the topic is now rated much higher \u2013 with growing relevance in the catalog of measures and in the technical assessment by expert committees.[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]<img decoding=\"async\" class=\"aligncenter wp-image-1006146 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild5.png\" alt=\"\" width=\"845\" height=\"583\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild5.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild5-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild5-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild5-700x483.png 700w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/583;\" \/>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Those responsible for information security must implement a variety of technical and organizational measures. First, they must decide which settings to apply to the existing systems. It is strongly advised not to create each configuration completely independently. Instead, common recommendations from industry-proven bodies such as the Center for Internet Security (CSI), the Federal Office for Information Security (BSI), or manufacturer recommendations such as Microsoft&#8217;s Security Baseline should be used. These standards comprise hundreds of settings. They offer very good protection and can be adapted to individual needs.<\/p>\n<p>Once the target configuration has been defined, the question arises as to how the settings can be implemented in the field. We have already presented our approaches (layered, rapid, and lifecycle hardening) in another blog post on the topic of \u201c<a href=\"https:\/\/www.teal-consulting.de\/en\/2023\/11\/15\/three-effective-methods-for-introducing-system-hardening\/\" target=\"_blank\" rel=\"noopener\">Three effective methods for introducing system hardening.<\/a>\u201d<\/p>\n<p>A system hardening project always involves eliminating legacy issues, and auditors increasingly require reasonable reports as proof. That is why we work closely with our partner FB Pro GmbH on this topic. The Enforce Administrator solution makes it easy to combine industry standards and secure Windows, Linux, domain, and non-domain systems with a uniform technology. This allows state-of-the-art hardening configurations to be defined, rolled out to IT systems, and centrally managed throughout the entire lifecycle \u2013 transparently, traceably, and auditably.<\/p>\n<p>If you want to check how a system is secured today, you can do so with the<a href=\"https:\/\/github.com\/fbprogmbh\/Audit-Test-Automation\" target=\"_blank\" rel=\"noopener\"> free Audit-Tap tool on GitHub from FB Pro<\/a>. This allows you to generate compliance reports for your systems. The resulting HTML reports provide a transparent overview of the security configuration of your devices in comparison to international security standards and hardening guides.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h3>(3.2.28) Securing administrative IT systems<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Many administrators still manage their systems from the same machine that is used for writing emails and surfing the web \u2013 the \u201cnormal office PC\u201d. Office computers are not adequately protected and are vulnerable to phishing and other attacks. Once an office device has been compromised, attackers can exploit this to steal administrative login credentials and gain further access. That is why office work must be separated from administrative work.<\/p>\n<p>The administrative IT systems used for this purpose \u2013 i.e., clients or servers that control and manage other systems \u2013 are at the heart of many IT infrastructures. This also makes them a particularly lucrative target for attackers: if they succeed in gaining access here, entire networks or production environments are often compromised. This makes it all the more important to secure these systems with particular care \u2013<strong> technically, organizationally, and operationally.<\/strong><\/p>\n<p>What needs to be considered?<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>Use only for administration:<\/strong> Administrative systems belong in isolated network segments and may only be used for administrative tasks \u2013 not for email, Office, or web access.<\/li>\n<li><strong>System hardening &amp; secure authentication:<\/strong> These systems must also be consistently hardened. Access should ideally be via multi-factor authentication (MFA) over encrypted channels \u2013 always via personal, traceable accounts.<\/li>\n<li><strong>Logging &amp; rights assignment:<\/strong> All activities must be centrally logged and regularly evaluated. Important: Admins should not have access to their own logs \u2013 the dual control principle is the gold standard here.<\/li>\n<li><strong>Software control:<\/strong> Only approved software may be run on administrative endpoints. Untested tools, browsers, or test scripts have no place there.<\/li>\n<li><strong>Securing sensitive zones:<\/strong> Access to highly sensitive network areas should ideally be via dedicated jump servers or admin terminals \u2013 logically separated from the rest of the network.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]In practice, so-called <strong>privileged access workstations (PAW)<\/strong> are used. We have described our view on this topic in a detailed blog article: <a href=\"https:\/\/www.teal-consulting.de\/en\/2022\/08\/16\/privileged-access-workstation-deep-dive-and-practical-implementation\/\" target=\"_blank\" rel=\"noopener\">PAW \u2013 Deep Dive and Practical Implementation<\/a><\/p>\n<p>However, many companies find it difficult to provide each administrator with an additional, dedicated device. In our view, this is particularly necessary for the administration of domain controllers or other critical systems (T0 systems). However, taking risk assessment into account, different mechanisms are also conceivable for \u201cnormal\u201d server systems. For example, more and more companies are successfully using privileged access management (PAM) systems. Solutions such as CyberArk quickly become very expensive and can be replaced by software such as Devolutions or Passwordstate. Among other things, these systems can control the temporary assignment of admin rights, document them automatically, and ensure traceability at all times. This keeps your admin systems lean, secure, and under control.<\/p>\n<p>PAWs and\/or PAM systems are no longer an optional extra. The current TeleTrusT Report 2025 clearly shows that securing administrative IT systems is now one of the <strong>central, fundamental building blocks of modern IT security architectures. Compared to the 2023 report, the measure has developed significantly in terms of both its proven effectiveness in practice and its recognition by experts in the field.<\/strong><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1006148 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild6.png\" alt=\"\" width=\"845\" height=\"583\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild6.png 845w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild6-300x207.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild6-768x530.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/TeleTrusT_Schaubild6-700x483.png 700w\" data-sizes=\"(max-width: 845px) 100vw, 845px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 845px; --smush-placeholder-aspect-ratio: 845\/583;\" \/>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Conclusion<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]<strong><img decoding=\"async\" class=\"wp-image-1006158 alignleft lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI.png\" alt=\"\" width=\"288\" height=\"288\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI.png 1600w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-300x300.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-1024x1024.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-150x150.png 150w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-768x768.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-1536x1536.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-570x570.png 570w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-500x500.png 500w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-1000x1000.png 1000w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/06\/Schluesselanhaenger-TAVI-700x700.png 700w\" data-sizes=\"(max-width: 288px) 100vw, 288px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 288px; --smush-placeholder-aspect-ratio: 288\/288;\" \/>Now is the right time to make a move<br \/>\n<\/strong><\/p>\n<p>The new \u201cState of the Art\u201d report clearly shows that IT security is not a one-time project, but rather a continuous process. Companies must not only comply with legal requirements\u2014they must actively protect their systems against current threats. And this is precisely where we at <strong>Teal<\/strong> come in.<\/p>\n<p>We help you identify the right measures, implement them professionally, and continuously improve them\u2014whether it&#8217;s monitoring and protecting directory services, system hardening, cloud security, business continuity, or secure authentication. Together, we bring your IT to a modern, regulatory-compliant, and, above all, secure level.<\/p>\n<p><strong>Get in touch with us!<\/strong>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Whether you are just starting out or want to update your existing security concept, we support you with sound advice, proven tools, and many years of practical experience. <strong>Teal is your point of contact for identity protection.<\/strong><\/p>\n<p>In the second part of the series <span style=\"color: #008081;\">(to be published in early July)<\/span>, we will discuss other important components from the state-of-the-art guide:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>2.29 \u00dcberwachung von Verzeichnisdiensten und identit\u00e4tsbasierte Segmentierung<\/li>\n<li>2.31 Cloud-Sicherheitsplattform<\/li>\n<li>3.9 Absicherung privilegierter Benutzerkonten<\/li>\n<li>3.17 Gesch\u00e4ftskontinuit\u00e4ts-Management (BCM)<\/li>\n<li>3.18 Notfall- und Krisenmanagement<\/li>\n<li>3.20 Technische Sicherheits\u00fcberpr\u00fcfung<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;100&#8243;][vc_raw_html css=&#8221;&#8221;]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;50&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h4>LATEST POSTS<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\">Microsoft is backtracking: Tiering isn&#8217;t dead\u2014it&#8217;s essential for survival<\/a><\/h4>\n                            <p class=\"excerpt\">Microsoft releases an Active Directory Tier Model on GitHub. To many, this sounds like just another tool. For us, it\u2019s official proof of something we\u2019ve been saying for years: if you don\u2019t strictly isolate ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">02 September, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\">Microsoft pulls the plug: why SMS MFA is now finally obsolete<\/a><\/h4>\n                            <p class=\"excerpt\">Starting September 1, 2026, passkeys will gradually become the default authentication method in Microsoft Entra ID. At the same time, Microsoft has announced that it will discontinue native support for SMS and voice MFA....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">06 August, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\">One-Click Disaster in Microsoft 365 Copilot: When AI becomes a hacker&#8217;s best friend<\/a><\/h4>\n                            <p class=\"excerpt\">AI agents like Microsoft 365 Copilot are revolutionizing our daily work and promise unprecedented productivity. But what happens if this very smart assistant system quietly turns into the ultimate spy? ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 July, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>PART 1: In our two-part series, we would like to discuss the current guidelines on the topic of \u201cState of the Art in IT Security\u201d from the TeleTrusT working group and present our perspective. Let&#8217;s get started!<\/p>\n","protected":false},"author":14,"featured_media":1006132,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1006164","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1006164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=1006164"}],"version-history":[{"count":5,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1006164\/revisions"}],"predecessor-version":[{"id":1006210,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1006164\/revisions\/1006210"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/1006132"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=1006164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=1006164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=1006164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}