Device Code Phishing: What SMEs Need to Know

Device code phishing abuses real Microsoft logins and working MFA, leaving few warning signs. Here's what SMEs need to know in 2026.

Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…

Read More

Identity Theft in Germany: What SMEs Need to Know

Identity theft and stolen credentials drive most cybercrime in Germany

Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…

Read More

Cybersecurity Buyer’s Remorse: 5 Tips to Help SMEs Avoid It

Cybersecurity buyer’s remorse is a real risk for SMEs comparing endpoint protection, email security, vulnerability scanners, cloud security platforms, and managed detection services — there’s no shortage of solutions promising to reduce cyber risk. The challenge is deciding which ones are actually worth your money. Unlike large enterprises with dedicated security teams and sizeable technology…

Read More

Ransomware in Germany: From IT Incident to Insolvency Risk

Ransomware in Germany — idle production line symbolising a cyberattack-related operational shutdown

Ransomware in Germany is no longer an abstract IT concern — in 2026, it is one of the more concrete threats to whether a company survives at all. Two recent cases illustrate how differently this threat can play out. ZEGO Textilveredelungszentrum filed for insolvency following a cyberattack, without the attack type ever being publicly confirmed.…

Read More

Why Endpoint Protection Isn’t Enough for Modern Small Businesses

Why endpoint protection isn't enough for modern SMEs

Endpoint protection is where most small businesses start their cybersecurity journey — install antivirus or EDR software on every employee laptop, and assume the job is done. After all, if every device is covered, what else is there to protect? The problem is that much of today’s business activity no longer happens solely on those…

Read More