Backups are no protection: How ransomware attacks really work and why recovery alone is not enough 

In many medium-sized businesses, there is a supposedly reassuring assumption: should a ransomware incident occur, you simply restore from backups and business carries on as normal. For a long time, this notion was not entirely unfounded. Until around 2022, ransomware was, at its core, essentially an encryption problem. Attackers would lock files, demand a ransom, and anyone with clean, up-to-date backups could weather the incident relatively unscathed. 

But those days are over. Modern ransomware attacks are multi-stage operations in which encryption is often merely the final, visible step in a much longer process. Anyone who continues to base their security strategy solely on recovery is defending against a threat that hardly exists in this form anymore. A look at the individual phases reveals how an attack actually unfolds today and why backup has become one of several building blocks rather than the sole lifeline. 

This is how a modern ransomware attack really unfolds 

A ransomware attack rarely begins with a loud bang. The initial entry is usually inconspicuous, for example via exploited software vulnerabilities, compromised login credentials or a well-crafted phishing email. According to the Verizon Data Breach Investigations Report 2026, the exploitation of vulnerabilities has now become the leading entry vector, accounting for 31 per cent of all security breaches – a significant increase from 20 per cent the previous year. By comparison, the misuse of stolen login credentials has declined slightly. This shift points to an approach that prioritises speed and scalability rather than conspicuous malware campaigns. 

Initial access is not usually followed by immediate encryption. Instead, attackers move inconspicuously through the network for weeks, expanding their privileges and gaining an overview of the infrastructure. Various expert analyses estimate the average time between initial access and actual encryption at around five to eleven days, though in many documented cases it is significantly longer. This is the phase where the crucial steps take place: 

  • Lateral movement: Attackers explore the network and identify valuable systems. 
  • Targeted search for backups: Network drives, NAS systems and even cloud synchronisations are tracked down so that they can be specifically encrypted or deleted at a later stage. 
  • Data exfiltration: Before any encryption even begins, sensitive data is copied and transferred to the attackers’ own infrastructure. 
  • Preparation for encryption: Only once backups have been compromised and data secured is the actual ransomware deployed. 

It is only at the end of this chain that victims perceive what they recognise as ‘the attack’: encrypted systems and a ransom demand. For your defences, this means one thing above all: there is a window of opportunity lasting days, or in some cases weeks, during which an attack could be detected and stopped before anything is encrypted at all. It is precisely this window that is scarcely utilised by traditional security approaches designed purely for recovery. 

Double Extortion: Why recovery does not solve the real problem 

The reason why a functioning backup is no longer sufficient today lies in what is known as ‘double extortion’. In this now dominant tactic, attackers not only encrypt your systems, but also specifically steal data beforehand and threaten to publish it. According to the BSI Situation Report 2025, around 72 per cent of all ransomware attacks now follow this pattern. 

The consequences for those affected are severe: even if you have flawless, up-to-date backups and can restore operations within hours, you have not escaped the actual extortion. Your stolen customer, staff or contract data remains in the attackers’ possession, and no recovery strategy can prevent its publication on the dark web. Added to this are potential reporting obligations to regulatory authorities and those affected, as well as the reputational damage, which often weighs more heavily than the actual operational downtime. 

Even paying the demanded ransom is not a reliable solution. A study by HYCU and ActualTech Media shows that, whilst around 60 per cent of companies that comply with the initial ransom demand do initially regain access to their data, almost a third have to make a further payment before recovery is even possible, and 8 per cent remain unable to access their data even after payment. And even if a decryption key is provided, the technical restoration of the systems often takes several weeks in practice. 

Why backups are still systematically targeted 

The fact that backups are a key target for attackers is no coincidence, but rather an integral part of modern ransomware campaigns. As described, professionally organised groups often spend weeks undetected within the network. During this time, they specifically search for accessible backups and destroy or encrypt them before the actual attack begins. In such a scenario, a backup that is accessible via the normal network no longer offers reliable protection. 

Another, frequently underestimated problem is a lack of testing. Whilst many companies formally have a backup strategy in place, they have never actually carried out a full recovery under real-world conditions. In an emergency, it then becomes apparent that backups are incomplete, out of date or simply non-functional. A backup that has never been restored is, in the worst case, merely a hope, not a safeguard. 

The Federal Office for Information Security (BSI) therefore takes a nuanced view of backups: they remain one of the most important preventive measures for restoring data availability in an emergency, but they explicitly do not protect against the theft and publication of data. According to the BSI, the following are particularly important: 

  • separate storage, isolated from the production network (offline or air-gap backups) 
  • regular, documented recovery tests 
  • clear responsibilities and a well-rehearsed contingency plan 

The real key: detecting attacks before encryption takes place 

In light of this development, the most effective lever in defence is shifting noticeably: away from a purely reactive approach after encryption has taken place, towards early detection during the preparatory phase, which often lasts for days. If an attacker is detected whilst they are still moving laterally within the network or exfiltrating data, the actual damage can often be prevented before it even occurs. 

This is precisely where approaches such as Extended Detection and Response (XDR) and Managed Detection and Response (MDR) come into play. XDR collects and correlates telemetry data from endpoints, firewalls, cloud services, email and identity systems, thereby revealing suspicious patterns that individual security tools would overlook. MDR supplements this data set with a Security Operations Centre (SOC) staffed around the clock, which not only analyses incidents but also intervenes actively where necessary. For companies without their own SOC – that is, the majority of small and medium-sized enterprises – this approach is often the most practical way to stop attacks at an early stage, before data is exfiltrated or systems are encrypted. 

This shift is now no longer merely a recommendation but is enshrined in regulation for a growing proportion of German SMEs. With the NIS-2 Implementation Act, documented protective measures – including provisions to maintain operations in accordance with Section 30 of the Federal Information Security Act (BSIG) – have become mandatory for around 29,500 German companies. 

What an effective security strategy actually requires 

The key insight can be summarised simply: a backup is a necessary but not a sufficient measure. It ensures the availability of data, but it prevents neither the initial breach nor the theft of sensitive information, nor the resulting reputational damage. A robust security strategy therefore covers the entire lifecycle of an attack, from prevention through early detection to recovery, and is based on several interlinked layers, including: 

  • consistent patch and vulnerability management 
  • multi-factor authentication for all access points 
  • network segmentation to contain lateral movement 
  • end-to-end detection of suspicious activity (EDR, XDR, MDR) 
  • isolated, regularly tested backups 
  • a documented and practised contingency plan 

The threat landscape in Germany alone demonstrates the necessity of this combination: the BSI Situation Report 2025 recorded 950 registered ransomware attacks, 80 per cent of which targeted small and medium-sized enterprises. Trend Micro’s Cyber Risk Report 2026 counted 433 confirmed ransomware incidents in Germany in 2025, placing the country among the three most severely affected nations worldwide, behind the US and Canada. 

Anyone who continues to rely solely on their backup in this environment is defending against yesterday’s attack. The more effective approach begins much earlier, with the detection of an attacker, long before the first file is encrypted. 

Early detection with NovaMDR™ 

This is precisely where NovaMDR™ comes in. Rather than relying on recovery after a successful attack, the service continuously monitors the IT environment and highlights suspicious activity whilst an attacker is still moving within the network, expanding their privileges or gathering initial data – in other words, during the critical window of days or weeks that determines the outcome of an attack. 

What NovaMDR™ offers SMEs 

  • 24/7 monitoring by a Security Operations Centre, without you having to set up your own internal SOC team 
  • Detection of suspicious patterns across endpoints, the network and other systems, rather than isolated individual alerts 
  • Active intervention in the event of an incident to stop lateral movement and data exfiltration at an early stage 
  • An approach specifically tailored to the resources and structures of SMEs in the DACH region 

Backup and MDR as a complement, not an alternative 

NovaMDR™ does not replace a backup strategy, but fills the gap left by recovery strategies alone. Whilst well-tested, isolated backups ensure the availability of data, early detection ensures that, in the best-case scenario, data theft and encryption do not occur in the first place. For companies that are already obliged to implement documented protective measures under NIS-2 and Section 30 of the BSIG, this approach can also be directly integrated into the required audit trail. 

Conclusion 

Ransomware is therefore no longer a one-off encryption incident, but a multi-stage operation that often begins days or weeks before the actual attack and specifically targets backups as well. Double extortion further ensures that even a complete recovery does not eliminate the risk of extortion as long as stolen data remains in circulation. 

A backup therefore remains indispensable, but is no longer sufficient as a stand-alone strategy. It is crucial to detect attackers during the preparation phase, before data is stolen and systems are encrypted. It is precisely this shift from mere recovery to early detection that medium-sized enterprises should be making now. 

Phishing 2.0: Why staff training is no longer enough to combat AI-powered attacks 

One click, one incorrect bank transfer, one compromised account: phishing has been one of the biggest risks to your business for years. What is new, however, is the speed and sophistication with which attackers operate today. Artificial intelligence has turned a familiar problem into a threat that renders many of your established protective measures ineffective. If, as a security manager, you are still relying on annual awareness training covering traditional warning signs, you are protecting your business against a threat landscape that is a thing of the past. 

The figures speak for themselves 

Recent analyses by Dashlane show just how significant this leap really is: AI-generated phishing emails now have a success rate of 54 per cent, compared with just 12 per cent for traditional, manually created campaigns. Since the launch of ChatGPT at the end of 2022, global phishing volumes have risen by 4,151 per cent, and business email compromise now accounts for 73 per cent of all reported cyber incidents.  

Attackers are no longer limiting themselves to traditional email: smishing, vishing and deepfake attacks via video are also becoming noticeably more prevalent. This is particularly problematic for your existing awareness programme: AI-generated messages are increasingly free of typos and stylistic inconsistencies – precisely the characteristics on which traditional training courses base their detection guidelines.

Social Engineering 2.0: How AI is changing attackers 

According to estimates, social engineering is behind up to 98 per cent of all cyberattacks. The actual vulnerability is therefore rarely the technology, but rather the people with whom you and your colleagues work on a daily basis. Generative AI is now changing the way in which this vulnerability can be exploited – both more precisely and more convincingly. Attackers analyse publicly available information about their targets and adapt their messages in real time to the victims’ behaviour, for example if they initially hesitate.  

Among the established forms of attack that are taking on a new dimension thanks to AI are, in particular, classic mass phishing, personalised spear-phishing, the compromise of business email accounts by exploiting real-world power dynamics, and pretexting, in which attackers invent convincing pretexts to gain targeted access to sensitive information. According to estimates, AI-assisted attackers can work around 40 per cent faster whilst simultaneously generating significantly more convincing content – a gain in efficiency that benefits criminals alone.  

Deepfakes and voice cloning take attacks to a new level 

The threat becomes even more serious when AI no longer just forges text, but also voices and images. Just a few seconds of audio material is enough to convincingly clone an executive’s voice and persuade your staff to make bank transfers over the phone. A case from Hong Kong illustrates just how real this threat already is: an employee took part in a video conference in which supposedly familiar colleagues were present. 

In fact, they were all AI-generated deepfakes, which persuaded him to make a bank transfer of around 25 million US dollars. 

This development is not an isolated incident, but part of an industry-wide trend: identity-based attacks are set to be the dominant form of threat by 2026, as generative AI enables hyper-personalised phishing, automated attacks on login credentials on an industrial scale, and deepfake attacks that are virtually impossible for humans to recognise as fakes. At the same time, the barrier to entry for attackers is continuing to fall: AI now allows even less technically savvy criminals to carry out operations that were previously the preserve of state-sponsored actors. So do ask yourself: would you be able to recognise a video call from your senior management as genuine beyond any doubt today?  

A record-breaking wave of attacks MEs – in most cases

Recent real-world incidents show that this trend is not slowing down but accelerating. In March 2026, the coffee chain Starbucks reported a serious data breach. Attackers had gained unnoticed access to the internal human resources management system via fake login portals, without using any traditional malware. At the same time, the Bergisch Chamber of Industry and Commerce warned of mass mailings of fake emails in which fraudsters posed as Chamber staff and, under the pretext of a data check, requested updates to bank details – complete with forged logos, portrait photos and signatures to maximise credibility. 

For the remainder of 2026, you should expect a further increase and refinement of such attacks, as AI automation reduces preparation time whilst the personalisation of messages increases at the same time.

Why traditional awareness training is reaching its limits

This highlights why many existing training programmes in your organisation may be falling on deaf ears. Three technical developments make modern attacks particularly dangerous: AI analyses publicly available profiles, LinkedIn data and previous data breaches, and uses this to compose messages that are precisely tailored to the target’s role, tone of voice and current projects. A few seconds of audio material are used to create a deceptively real voice, turning a purported call from senior management into a tool for CEO fraud. And fake video calls featuring deceptively realistic-looking line managers put your staff under pressure in real time, for example to authorise urgent bank transfers.  

The result: typos, awkward forms of address or inappropriate corporate wording – in other words, precisely those warning signs on which traditional training programmes are based – simply no longer exist in this form. Whilst awareness remains an important component of your security strategy, it can no longer be the sole line of defence. 

A culture of caution rather than isolated identifying features

One detail that may come as a surprise at first glance: a total of 197 different ERP systems were identified in the sample. This is If attacks can no longer be reliably identified by external characteristics, you must also shift the focus of your prevention measures. Instead of concentrating exclusively on obvious signs of phishing, it is advisable to establish a fundamental culture of caution throughout the organisation.  

It is crucial that every incoming communication is scrutinised critically:  

  • Why would this message come from this particular person?  
  • Did you actually sign up for this webinar?  
  • Doesn’t this offer sound too good to be true?  

Encourage your teams to make a habit of asking precisely these kinds of questions. The focus should be more on the contextual content of a message than on its outward form. To ensure that such a culture really takes hold in your day-to-day working life, you need regular and compulsory training sessions. One-off compulsory sessions are not enough.

The technical foundation: authentication and simulation

However, awareness and culture alone are not enough if the technical infrastructure in your organisation is not up to scratch. As the task of detecting fake messages can no longer be left solely to humans, a key lever lies in the technical protection of your own domains: correctly implemented SPF, DKIM and, above all, a consistently enforced DMARC make it considerably more difficult for attackers to misuse your brand for phishing. Combined with clear approval processes for payments and a modernised awareness programme, this creates a significantly more robust level of protection.  

In addition, regular phishing simulations have become an integral part of modern security strategies. If you use Microsoft 365, you can, for example, utilise the integrated attack simulation training provided by Microsoft 365 Defender. In addition, specialised solutions such as SoSafe’s phishing demo or KnowBe4’s free Phishing Security Test have become established on the market. Such simulations show you, under realistic conditions, how your staff actually react to suspicious messages, thereby providing the data needed to refine your training content in a targeted manner, rather than adopting a one-size-fits-all approach. 

How Managed Detection and Response provides additional protection 

However, even the best combination of awareness, organisational culture and technical prevention cannot prevent every attack, precisely because AI-powered attacks have become so targeted and varied that a single successful click within your organisation remains a possibility at any time.  

This is where Managed Detection and Response (MDR) comes in: through continuous monitoring of the network, endpoints and access patterns, it can detect suspicious activities following a successful phishing or social engineering attack – such as unusual login attempts, conspicuous data access or suspicious account activity – before any significant damage occurs. MDR thus complements your preventative measures with an effective second line of defence that kicks in precisely when prevention alone has not been sufficient. 

Conclusion

AI has transformed phishing from a mass phenomenon with recognisable vulnerabilities into a highly personalised threat that is now almost impossible to detect. If you want to protect your business effectively, a fundamental rethink is essential: practical, recurring training sessions rather than one-off compulsory events; a company-wide culture of vigilance; consistently implemented technical safeguards such as DMARC and phishing-resistant authentication; and continuous monitoring that responds as soon as something does slip through. Only by combining these elements can the growing threat posed by AI-powered social engineering be effectively contained. 

SMEs choose SMEs: What a new study on the German IT market reveals

A recent study by the University of Potsdam shows that almost half of all small and medium-sized enterprises (SMEs) in Germany rely on solutions from the SME IT sector for their ERP software. What lies behind this, what does it mean for you as a decision-maker, and why is this topic more relevant than ever?

Who actually supports whom?

German SMEs are regarded as the backbone of the economy. That may sound like a cliché, but if you take a closer look at the figures, it quickly becomes clear that this is simply the reality. And within this backbone, there is a relationship that hardly anyone speaks about openly: that between SME users and the SME IT sector.

The Bundesverband IT-Mittelstand e.V. (BITMi) raised precisely this question and commissioned the Chair of Business Informatics at the University of Potsdam to provide an empirical answer. The results have been available since May 2026, and it is worth taking a closer look.

What the study examined

The research team led by Prof. Dr.-Ing. Norbert Gronau analysed a sample of around 2,500 companies. The methodological approach: using ERP systems as a proxy. The reasoning behind this is as simple as it is compelling.

ERP (Enterprise Resource Planning) software is the most widely used standard business software of all. It integrates accounting, stock management, CRM, production and more into a central platform. And because ERP providers typically offer a whole ecosystem of complementary solutions, the choice of ERP system provides a reliable indication of whether a company tends to rely on solutions designed for large corporations or on software tailored for SMEs.

For the study, two groups were clearly defined: the SME user base comprises companies with fewer than 1,000 employees. The SME IT sector on the supplier side consists of software companies with fewer than 500 employees, characterised by close customer relationships and specialisation.

The sample covered a total of over 4.6 million jobs, 72.5% of which were in SMEs. This provides a solid basis for reliable conclusions.

The key finding: almost one in two chooses SME IT providers

Among the 1,662 SME ERP user companies in the sample, 44.3% rely on solutions from SME IT providers, whilst 55.7% use corporate ERP systems such as SAP or Microsoft Dynamics. At first glance, this may appear to be a clear majority in favour of the large providers. But when you consider the marketing budgets, sales organisations and brand awareness that these large corporations bring to bear, holding on to almost half the market is a truly extraordinary achievement.

Particularly noteworthy is the reach of these SME solutions: they are used across all company sizes, and even among large enterprises, the share remains at over 20%. SME software is therefore no longer a niche topic for small businesses.

SMEs buy from SMEs – in most cases

An interesting finding from the study concerns selection behaviour by company size. There is a clear trend: users prefer IT providers from their own size category. Micro-enterprises are more likely than average to opt for software from smaller providers, whilst large enterprises tend to favour products from major corporations.

Looking at the percentages, the shift is clearly visible:

  • Micro-enterprises (< 10 employees): 48.8% use SME ERP
  • Small enterprises (< 50 employees): 52.9%
  • Lower-tier SMEs (< 250 employees): 46.6%
  • SMEs (< 500 employees): 37.8%
  • Upper-tier SMEs (< 1,000 employees): 28.9%
  • Large enterprises: 22.5%

What is striking is that even among upper-tier SMEs and large enterprises, SME ERP solutions are by no means insignificant. This speaks to the quality and performance of these providers.

Relevant across all sectors, not just in mechanical engineering for your IT team

Another key finding of the study: SME IT providers are by no means insignificant in any major sector. Whether in chemicals, electrical engineering, food, retail, property or IT services themselves, they hold significant market shares across the board.

As expected, they are particularly well represented in traditional SME sectors such as the service sector, metalworking and retail in general. Only in the automotive industry, where corporate group structures dominate, is their share somewhat lower. But even there, they are present.

This shows that SME IT companies do not have a specific home sector; they are generalists with deep specialisation.

Diversity as a strength: 197 different ERP systems in use in the supply chain

One detail that may come as a surprise at first glance: a total of 197 different ERP systems were identified in the sample. This is not a sign of fragmentation or chaos. It is a sign of diversity and competition.

On the supplier side, most of these systems come from small and medium-sized enterprises:

  • Small enterprises (< 50 employees): 56 different systems (28.4% of all suppliers)
  • Lower mid-market (< 250 employees): 63 systems (32.0%)

Together, these two size categories already account for 60% of all ERP providers on the market. Large corporations with more than 1,000 employees, on the other hand, make up only 13.2% of providers, but naturally account for a significant proportion of installations due to their widespread use.

What this means for you as a decision-maker

If you are currently considering a new software infrastructure for your company, or if your ERP system is getting on in years, this study sends a clear message: the market for medium-sized IT providers is capable, diverse and trustworthy. Opting for a large corporation’s solution is not automatically the safest choice, and choosing a medium-sized provider is not a compromise.

At the same time, you should bear in mind a question that the study does not explicitly answer, but which is directly related to it.

And then there is the issue of security

Software decisions are IT decisions. And today, IT decisions are always security decisions as well.

So whether you opt for a corporate-level solution or a medium-sized ERP platform: any system integrated into your business processes is also a potential point of attack. Ransomware, data breaches, compromised supply chains – these are no longer abstract scenarios. They affect companies of all sizes, across all sectors, on a daily basis.

Medium-sized companies in particular face a specific challenge here:

IT resources are limited, yet the threat landscape is complex. For most, operating their own Security Operations Centre (SOC) is simply not cost-effective.

This is precisely where Managed Detection and Response (MDR) comes in. Instead of building up in-house capacity – which is rarely cost-effective to operate in the long term – a specialist provider takes over the continuous monitoring, detection and response to threats. With NovaMDR™, we offer exactly that: an MDR solution consistently tailored to the needs of SMEs, without the complexity of large corporations, but with full SOC support. SMEs protecting SMEs, if you like. The same logic demonstrated by the BITMi study for ERP software therefore also applies to cybersecurity.

Conclusion: SME IT is not a stopgap solution; it is a conscious choice

The University of Potsdam study highlights what many in the field have long known: SME IT is structurally deeply embedded in the fabric of the German economy. Almost one in two SMEs relies on its solutions, across all sectors and company sizes, with a tendency towards loyalty.

This is no coincidence. It is the result of customer focus, specialisation and an understanding of what really drives SMEs. IT providers who think in terms of SMEs – rather than corporate structures – are able to connect with their customers’ language, requirements and pace.

For you and your business, this means: when making your next software decision, be sure to consider SME providers as well. Not out of solidarity, but because the figures show that it pays off.


Gronau, N. (2026). Wie stark trägt der IT-Mittelstand den deutschen Mittelstand? Untersuchung für den Bundesverband IT-Mittelstand e.V. (BITMi). Universität Potsdam, Lehrstuhl für Wirtschaftsinformatik. 

The WhatsApp Spyware Crisis: Why a fake update is the cleverest hack of 2026

In early April 2026, WhatsApp officially alerted approximately 200 high-value individuals – including corporate executives, journalists, and government officials—that they had been targeted by a highly sophisticated spyware campaign. The method was deceptively simple: attackers used counterfeit versions of the app to trick targets into installing a “critical security update” outside of official stores. For Small and Medium-sized Enterprises (SME), this isn’t just a tech headline; it’s a direct warning that the most responsible behavior of your staff—maintaining device security—is now being weaponized by hackers to bypass enterprise defenses.

The irony of security: A trap for the conscientious

Imagine this scenario: An employee wants to ensure their work mobile is protected and sees a professional-looking notification for a WhatsApp update. Nothing unusual at first glance. Out of habit and a sense of duty, they click ‘Install’ to keep the device up to date. In that single second, your corporate perimeter is breached. The irony in 2026 is brutal: it’s precisely the attempt to ensure security that opens the door to the spy. A compromised phone no longer just means the loss of private data; it’s basically a cloned master key to your financial systems and customer databases.

Shadow IT: The invisible crack in your defences

In Germany, business flexibility and success are based on hybrid working and BYOD (Bring Your Own Device). But when employees use the same device for private chats and sensitive company emails, this security boundary disappears. Such incidents reveal the hallmark of modern attacks: hackers no longer try to ‘break through’ your firewall; they simply ask your employees for the ‘key’ through psychological manipulation. For many German SMEs, this invisible breach turns into an irreversible act of industrial espionage through an unconscious tap.

Why your current security is just an alarm, not a security guard

Many company managers believe that basic antivirus software is sufficient. But there is a crucial difference: traditional software is like an alarm system. It makes a noise, but if no one reacts at 3:00 am, the thief gets away anyway. Furthermore, if your employee manually clicks ‘Allow access’, the software assumes it’s a legitimate human decision and remains silent. In a typical SME, IT resources are limited. Without continuous monitoring, an attack at the weekend gives hackers a 48-hour head start to steal your data.

Why you should choose NovaMDR™

Professional response as your competitive advantage

As purely technical defences have reached their limits, you need a dynamic solution that combines technology with human intelligence. This is where Managed Detection and Response (MDR) comes into play. Our MDR service creates an intelligent shield through bespoke behavioral modeling. We do not believe in ‘one-size-fits-all’ solutions. Instead, our platform learns your company’s unique ‘digital DNA.’ If an employee’s device shows atypical data flows (even if the software has a ‘legitimate signature’), our system raises the alarm immediately.

The final line of defence with local experts

Important: Cyberattacks don’t stick to office hours, and your team needs breaks. If an employee triggers a high-risk alert outside working hours, you shouldn’t have to wade through English manuals or wait for a response from an overseas call center. Our local German-speaking experts intervene in real time. We don’t just send you a simple message; we act as your 24/7 security service, blocking the threat before it spreads. The service integrates seamlessly into your existing architecture and guarantees security without slowing down productivity.

Your Legal Shield and the Executive Bottom Line

As an entrepreneur or executive, you face not only technical risks but also personal liability. Under the GDPR and the stricter NIS2 guidelines of 2026, directors can be held personally accountable for security failures. The audit logs provided by MDR are more than just a defence: they offer you legal proof of your duty of care. This compliance-compliant approach demonstrates to regulatory authorities that you have implemented ‘state-of-the-art’ measures to fulfill your management responsibilities.

Leave security to the professionals so you can focus on your business

Last week’s WhatsApp attacks show that hackers have mastered the art of human manipulation. For German SMEs, future security is not about “preventing every click”, but about “responding professionally as soon as a click occurs.” With MDR, you take the burden of 24/7 vigilance off your employees’ shoulders. In an era of increasing digital uncertainty, professional real-time protection is not an expense. It’s your most stable business investment.

Next-Gen AI Agents: Why DACH SMEs are underestimating the new cyber risks

For small and medium-sized enterprises (SMEs), this creates significant efficiency gains. However, it also introduces new security dependencies that are not adequately addressed by traditional cybersecurity models.

What is OpenClaw

OpenClaw is an emerging AI agent framework designed to integrate LLMs with enterprise applications, APIs, and user interfaces.

Unlike traditional automation scripts, AI agents are not limited to predefined sequences. They operate in a goal-oriented manner:

  • They interpret tasks contextually
  • They dynamically determine execution steps
  • They interact directly with enterprise systems (ERP, CRM, databases)

This represents a shift toward software systems that act as autonomous decision-making entities within defined permission boundaries.

From a security perspective, these agents must be treated as high-privilege, continuously active system actors.

New risk dimensions for SMEs in the DACH region

SMEs in the DACH region face increasing pressure from both operational constraints and regulatory requirements, including GDPR compliance obligations.

AI agents amplify risk in three key areas:

1. Expanded attack surface through system integration

AI agents require broad access to internal systems, increasing the potential impact of credential misuse or indirect manipulation.

2. Data processing beyond traditional control boundaries

Many AI workflows rely on external LLM services, raising compliance questions under GDPR regarding personal and sensitive data handling.

3. Reduced auditability

The autonomous nature of AI agents makes it difficult to fully reconstruct decision paths across extended execution chains.

Why traditional security architectures are insufficient

Conventional cybersecurity models rely on perimeter-based controls such as:

  • network segmentation
  • access control mechanisms
  • signature-based detection
  • rule-based SIEM alerts

These models are primarily designed to detect external threats.

AI agents, however, operate within trusted environments using legitimate permissions, making them significantly harder to detect using traditional approaches.

Managed Detection and Response (MDR) as an adaptive control layer

Managed Detection and Response (MDR) is a security operations model combining continuous monitoring, behavioral analytics, and active incident response.

In AI-agent-driven environments, MDR provides critical capabilities:

1. Behavioral anomaly detection

Continuous profiling of identities, endpoints, and AI agent execution patterns enables detection of deviations from expected behavior.

2. Cross-domain correlation

MDR systems correlate:

  • user identities
  • API interactions
  • AI agent execution logs

to reconstruct complete execution chains.

3. Real-time containment

Upon detection of anomalies, affected agents can be isolated, API tokens revoked, or execution halted to prevent systemic impact.

Regulatory context

In the DACH region, GDPR compliance introduces strict requirements for:

  • data minimization
  • purpose limitation
  • auditability of automated decisions
  • technical and organizational measures (TOMs)

In highly automated environments, continuous monitoring becomes essential for maintaining compliance.

Conclusion

AI agents such as OpenClaw represent a structural shift in enterprise IT: from rule-based automation to autonomous decision-making systems.

For SMEs, this introduces not only efficiency gains but also systemic security and compliance challenges.

What is SEO poisoning and why should SMEs care?

In daily work, employees of SMEs often search online for software, templates, or business information. However, some seemingly legitimate search results may hide serious risks, this is SEO poisoning. Attackers manipulate search engine rankings to place malicious websites at the top of search results, tricking users into clicking and potentially stealing credentials or spreading malware.

For example, a finance employee in a small company searching for “latest financial report template” might click the first result, which looks legitimate but contains malware, compromising sensitive company data. Similarly, downloading a VPN client or commonly used software from a poisoned search result could also expose the business to serious security risks.

How SEO Poisoning Works

SEO poisoning exploits the trust users place in search engine rankings. Key characteristics include:

  • Keyword manipulation: Attackers target trending keywords to boost malicious page visibility.
  • Fake downloads: Pages disguise malware as common software or business templates.
  • Credential theft: Fake pages collect usernames, passwords, or other sensitive company information.
  • Malicious redirects can lead users to harmful pages when they attempt to visit legitimate websites.

Because this method is subtle, employees often fail to recognize the threat, and a single click can compromise the entire organization.

Why This Matters for SMEs

For SMEs (KMU) in the DACH region, SEO poisoning is a significant and growing threat. According to the German Federal Office for Information Security (BSI), these attacks can lead to credential theft, malware infections, and even business disruption. Studies show that black-hat SEO networks involve hundreds of thousands of fake websites and millions of malicious promotion items across search engines, meaning even routine online searches can expose companies to risk.

A single accidental click could trigger DSGVO compliance reporting obligations, and failure to act properly could result in regulatory penalties and financial losses. Many SMEs do not have dedicated IT security teams, making them especially vulnerable.

Compliance Risks

DSGVO compliance imposes strict data protection requirements. SEO poisoning creates several risks for SMEs:

  • Unauthorized data collection: Malicious websites may capture customer or employee information.
  • Data breaches: Stolen credentials or files must be reported promptly.
  • Reporting obligations: Failing to comply can result in fines or penalties.

Understanding SEO poisoning and implementing preventive measures is both a security and a legal necessity.

How MDR Services Mitigate Risk

Managed Detection and Response (MDR) services offer proactive protection for SMEs (KMU):

  • Continuous monitoring: Detects unusual traffic and suspicious website activity.
  • Threat intelligence integration: Keeps pace with emerging SEO poisoning tactics.
  • Automated response: Blocks malicious downloads or redirects.
  • Compliance support: Helps document security events and maintain DSGVO compliance.

MDR services allow IT managers in SMEs to minimize risk while keeping business operations running smoothly.

Best Practices to Prevent SEO Poisoning

SMEs can reduce risk by adopting the following measures:

  1. Employee training: Teach staff to recognize suspicious search results and download links.
  2. Device and browser security: Regularly update systems and software.
  3. Web filtering and monitoring: Block access to known malicious websites.
  4. Deploy MDR services: Enable round-the-clock threat monitoring and rapid response.
  5. Verify downloads: Ensure files come from trusted sources and check SSL certificates.
  6. Regular audits: Monitor traffic and downloads for unusual activity.

Why Acting Now Matters

SEO poisoning attacks are evolving rapidly. Waiting until an incident occurs is risky because:

  • Attacks are subtle and hard to detect with traditional monitoring.
  • Data breaches can cause significant financial losses and operational downtime.
  • Exposure to data inevitably leads to regulatory risks under DSGVO.

Implementing MDR services, raising employee awareness, and strengthening everyday cybersecurity measures are the most reliable ways to protect SMEs from SEO poisoning.

Final Thoughts

SEO poisoning is a real and growing threat to SMEs, capable of compromising data security and DSGVO compliance even during routine searches. Supported by BSI guidance and real-world examples, IT managers in SMEs (KMU) should prioritize proactive monitoring, MDR services, and employee education. Taking these steps not only protects sensitive data but also ensures business continuity and compliance.

Immer up to date!

Abonnieren Sie unseren Newsletter und erhalten Sie wertvolle Branchen-Insights, Produkt-Updates und aktuelle Analysen von ForeNova direkt in Ihr Postfach.

Wir verwenden Brevo als unsere Marketing-Plattform. Indem Sie das Formular absenden, erklären Sie sich einverstanden, dass die von Ihnen angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden, gemäß den Datenschutzrichtlinien von Brevo.