IT security is a top priority

Table of Contents

A Guide for Board Members and CEOs

Foreword: Why IT Security Has Become a Management Responsibility

Imagine receiving a call at 6 a.m. on Monday morning: Your entire IT infrastructure has been encrypted. Customer data is no longer accessible. Operations have come to a standstill. Extortionists are demanding a ransom. Your employees are left helpless, staring at black screens.

This scenario is not dystopian fiction—it is a harsh reality for hundreds of German companies every year. And the question that prosecutors, insurers, and regulatory authorities then ask is not: “Did your IT department have the right tools?” It is: “Did you, as management, fulfill your duty of care?”

IT security has evolved from a technical niche issue into a core governance responsibility. Today, cyberattacks pose the greatest threat to business continuity, reputation, and management liability. Yet many board members still treat the issue as a technical detail that “IT will take care of.”

This booklet is designed to help you understand IT security for what it really is: a strategic management responsibility that directly impacts your business success, your legal standing, and your customers’ trust.

Chapter 1: A False Sense of Security

The most dangerous sentence in the executive office

“Nothing has happened here in 20 years. Why should we invest now?”

This statement is based on a fundamental fallacy: yesterday’s security situation bears no resemblance to today’s.

The reality in numbers:

  • 86% of German companies have been the target of cyberattacks in the past two years (Bitkom 2023)
  • The average loss for small and medium-sized enterprises is 1.3 million euros
  • For 60% of affected SMEs, a serious cyberattack leads to bankruptcy within six months

The invisible is often overlooked

Cybercriminals remain undetected in networks for an average of 287 days. A medium-sized automotive supplier lost access to 15 years’ worth of design data in a single night—resulting in a direct loss of 8 million euros, a production shutdown lasting over three weeks, and the loss of two major customers.

The questions leaders need to ask

  • What data is essential to our business model?
  • How long can we go without IT?
  • Who is liable if sensitive customer data is leaked?
  • Are our backup systems really secure?

Chapter 2: Liability, Reputation, and Economic Consequences

Personal Liability: The Board in the Crosshairs

Legal Basis:

  • Section 93 of the German Stock Corporation Act (AktG) / Section 43 of the German Limited Liability Companies Act (GmbHG): Members of the executive board and managing directors are liable for breaches of duty
  • GDPR: Fines of up to 20 million euros or 4% of annual turnover
  • NIS 2 Directive (effective October 2024): Expanded personal liability for executives

The burden of proof is on you. “I didn’t know about that” is not an excuse.

Economic Consequences: The True Costs

  • Production downtime: Every hour of downtime costs revenue and customer loyalty
  • Emergency IT Services: Six-figure sums for forensic analysis and data recovery
  • Legal disputes, insurance premiums, damage to reputation

Average total cost: 4 to 7 times the amount of direct damage.

Chapter 3: Facts and Myths

Myth 1: “We’re too small to be targeted by hackers”

Wrong. Modern attacks are automated. 80% of successful ransomware attacks target companies with fewer than 1,000 employees.

Myth 2: “A firewall and antivirus software are enough”

Modern attacks use social engineering, zero-day exploits, and encrypted channels. Standard tools are of no help here.

Myth 3: “That’s what our IT department is for”

IT security is a distinct field that requires specialized knowledge and 24/7 monitoring.

Myth 4: “The cloud solves the problem”

Cloud providers secure their infrastructure, not your data. The responsibility and liability remain with you.

Myth 5: “IT security is too expensive”

A professional security architecture costs 3–8% of the IT budget. A ransomware attack costs 20–50 times that amount.

The 3 biggest entry points:

  • Human error (82% of incidents)
  • Unpatched systems (67%)
  • Lack of network segmentation (54%)

Chapter 4: The 7 Responsibilities of Management

1. Conduct a risk analysis – Commission a systematic assessment of critical assets.

2. Define a security strategy – Have the strategy approved by the board of directors, not by the IT department.

3. Allocate resources – Dedicated security budget: 3–8% of the IT budget as a guideline.

4. Clarify responsibilities – Appoint a CISO or engage external expertise.

5. Establish a reporting system – Require quarterly security reports to be presented at board meetings.

6. Raise employee awareness – Regular security training for everyone, including management.

7. Develop and test an emergency plan – Conduct emergency drills at least once a year with management participation.

Business Case: Sample Calculation

  • Annual investment in security: 150,000 euros
  • Risk of a serious attack without protective measures: 15% per year
  • Average loss: 1.8 million euros → Expected value: 270,000 euros/year

As expected, the €150,000 investment will save significantly more than it costs.

Chapter 5: Axsos as a Strategic Partner

Axsos sees itself as a strategic partner for medium-sized and large companies that want to implement IT security in a professional and business-oriented manner.

The Axsos Security Concept: 4 Pillars

Pillar 1: Analysis & Strategy – A thorough assessment of the current situation and a customized security strategy, presented in a clear and understandable way for management.

Pillar 2: Technical Security Measures – Defense in Depth, Network Segmentation, Identity and Access Management, Encryption, Secure Backup Strategies.

Pillar 3: Monitoring & Incident Response – SOC with 24/7 monitoring, automated threat detection, and penetration testing.

Pillar 4: Compliance & Training – GDPR compliance check, NIS 2 readiness, security awareness training, management workshops.

Flexible entry-level models

  • Quick Security Check (1–2 weeks): A quick assessment
  • Security Roadmap (4–6 weeks): Multi-year security strategy
  • Managed Security Services: Axsos as an Extended Security Team
  • CISO as a Service: Experienced CISO on a part-time basis

Chapter 6: Take Action Now

Free Security Quick Check

In a 90-minute workshop, Axsos analyzes the key risk areas of your business—with no obligation and no fine print.

Schedule an appointment now: security@axsos.de | www.axsos.de

Checklist: Is Your Business Secure?

Strategy & Organization:

  • A documented IT security strategy is in place
  • IT security on the agenda at regular board meetings
  • CISO or Security Officer Appointed
  • Dedicated security budget established

Technical measures:

  • Multi-layered firewall implemented
  • Backups are created daily and tested regularly
  • Systematic Patch Management
  • Multi-factor authentication as the default

Monitoring & Compliance:

  • 24/7 network monitoring enabled
  • Incident Response Plan Tested
  • GDPR requirements met
  • Employees receive regular training

Results: 12–16 points: Good foundation | 8–11: Action needed | Below 8: Critical gaps – take immediate action

Share:

Scroll up

Jamil Isayyed

Jamil is an experienced digital process professional, has a rich international background in the information technology and services industry spanning Germany, Greece and Palestine. He holds a Bachelor's degree in Computer Science and a Scrum Master certification from the Scrum Alliance with a focus on Computer Software Engineering. Jamil is passionate about leading and building high-performance teams that deliver exceptional experiences and create valuable opportunities for clients. In addition to his main role, he is the Director of Axsos Academy GmbH. In this role, he leads a dynamic German-Palestinian bootcamp designed to help young people enter the IT market and build a successful career.

Bernd Length

Bernd Länge has been working in the IT industry for over 20 years and advises clients and interested parties on cyber security issues as well as on the development and implementation of information security management and data protection. In this role, he acts as an external data protection and information security officer for clients. It is important to him to take a pragmatic approach and work closely with clients, partners and vendors to ensure that clients' enterprise security is up to date.

Martin Müller

As a technology enthusiast and committed leader, he has been helping companies in the IT sector to shape the future of work for over 20 years. Thanks to his quick thinking and ability to develop effective solutions, he is able to formulate a clear vision of what our future way of working will look like. Step by step, he overcomes challenges and drives us forward into the future. However, he does not accomplish these tasks alone. He has a competent team that he trusts completely and can rely on. Together they overcome every hurdle! Through positive, critical thinking, the second-best solution often leads to incremental success - after all, even an empire wasn't built in a day. This approach makes him unique in his role and he looks forward to working with you on the path to the future.

Rolf Stephan

His enthusiasm for information technology led Rolf to study computer science and graduate from the University of Karlsruhe, now the KIT / Karlsruhe Institute of Technology. Rolf has been working in the IT sector ever since and knows the industry inside out - both nationally and internationally. For more than 25 years, he has focused on international cooperation between experts across all cultures. He also pursued this approach in the first company he founded, AD Solutions AG, which quickly developed into a renowned international IT service provider with several branches in Germany, Switzerland, Austria and the USA. Rolf Stephan has been General Manager since 2010 and CEO of AXON IVY AG, headquartered in Switzerland, since 2021. He has been an investor, shareholder and Chairman of the Supervisory Board of Axsos AG since 2009.

Frank Müller

Frank is a passionate IT expert and visionary entrepreneur. He loves and believes in peace and freedom. For him, these values are more than just words. They are the result of great awareness, responsibility and a solid foundation. His foundation is his faith in Jesus and his unconditional love for people. Frank builds his great visions on this foundation, such as his commitment to peace in the Holy Land. He is not afraid to realize creative and unconventional ideas, such as founding a medium-sized company that spans four countries and cultures and offers its employees a great deal of freedom. Founding a bootcamp academy in the midst of the coronavirus pandemic is certainly one of these ventures. Through these efforts, Frank creates new innovations and added value for his customers and the people who travel with him. With more than 32 years of IT experience and 15 years as an entrepreneur, Frank helps other entrepreneurs focus on their core business and translate their needs into technology opportunities and implementations. His team and he can translate these requirements into a customized IT strategy, processes and technologies. Frank always has a heart for the people he supports and wants to encourage them to break new ground and develop their potential. Frank is open to exchanging ideas with people who see values not as CSR or marketing chatter, but as the basis of their actions. He seeks contact with people who want to change the world for the better. He also welcomes those who are looking for support from him or his team on their journey into the cloud, digitalization or the use of AI.