Device Code Phishing: What SMEs Need to Know

Device code phishing abuses real Microsoft logins and working MFA, leaving few warning signs. Here's what SMEs need to know in 2026.

Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…

Read More

Identity Theft in Germany: What SMEs Need to Know

Identity theft and stolen credentials drive most cybercrime in Germany

Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…

Read More

SME Squeeze: NIS2, AI Act, Ransomware Collide

Three regulatory and threat deadlines create an SME squeeze in Germany

On January 7, 2026, the ransomware group Akira hit Buhlmann Group, a Hamburg-based steel and metal trading company with roughly 2,000 employees and €428 million in annual revenue. The attackers made off with about 55GB of data — engineering drawings, HR files, financial records — before anyone at the company could respond. Buhlmann wasn’t an…

Read More

Cybersecurity Buyer’s Remorse: 5 Tips to Help SMEs Avoid It

Cybersecurity buyer’s remorse is a real risk for SMEs comparing endpoint protection, email security, vulnerability scanners, cloud security platforms, and managed detection services — there’s no shortage of solutions promising to reduce cyber risk. The challenge is deciding which ones are actually worth your money. Unlike large enterprises with dedicated security teams and sizeable technology…

Read More