Knowledge base

Field notes for better IT decisions.

Practical, independently authored guidance on secure operations, resilience, cloud choices and digital sovereignty for SMEs.

Named authorBenjamin RaulfReview datevisible on every articleClear boundariesno disguised legal adviceUseful next stepsevidence before products
36 practical articles

Security, operations, cloud and modernisation

Every German field note now has a maintained English counterpart and a direct language switch.

Field note

A backup without a restore test is only an assumption

Successful backup jobs do not prove that systems, permissions and business data can be restored within the required time.

Read article
Field note

A practical route into BSI IT-Grundschutz for SMEs

IT-Grundschutz becomes useful when its controls are scaled to the organisation instead of copied into an oversized documentation project.

Read article
Field note

What SMEs can learn from a global endpoint outage

A security product can reduce risk and still become a shared dependency. Resilience therefore needs recovery paths as well as prevention.

Read article
Field note

Digital sovereignty is an operating model, not a product label

Open source can improve control and portability, but only when skills, updates, backups and exit paths are actively managed.

Read article
Field note

Modernising an SME without disrupting daily work

The safest digitalisation programme starts with one measurable workflow and grows through controlled, documented iterations.

Read article
Field note

DIN SPEC 27076: a focused cyber-risk check for smaller organisations

The specification provides a structured entry point when an SME needs priorities and evidence without beginning with a full certification programme.

Read article
Field note

EU AI Act: what SMEs should organise first

Even organisations that only use AI services need an inventory, usage rules and a clear view of data, providers and human oversight.

Read article
Field note

A firewall is a maintained control, not a one-time purchase

Useful protection depends on current firmware, understandable rules, secure administration and a response process for alerts.

Read article
Field note

Home-office security that remains workable

Remote work is safest when identity, managed devices, encrypted access and clear support paths are designed as one operating model.

Read article
Field note

A hybrid-cloud strategy needs explicit boundaries

Hybrid architectures work when workload placement follows business requirements rather than habit or vendor pressure.

Read article
Field note

Information security without an internal IT department

A small organisation still needs named responsibility, an asset view and dependable external escalation—even if technical work is outsourced.

Read article
Field note

Why useful IT documentation pays back quickly

Documentation reduces dependency and recovery time when it records decisions, access paths and operating reality—not screenshots that immediately become stale.

Read article
Field note

Prepare for the first hour of an IT emergency

The first decisions in an incident determine evidence quality, downtime and communication risk. A short, rehearsed plan is more valuable than a long unread manual.

Read article
Field note

What an IT service provider should actually be accountable for

A professional provider makes scope, ownership, response times, documentation and exclusions visible before an incident tests the relationship.

Read article
Field note

From paper to cloud without losing control

Moving a process to the cloud should improve traceability and access without creating unclear retention, permissions or supplier dependence.

Read article
Field note

Deepfake calls: verification beats voice recognition

Synthetic audio makes urgency and authority easier to imitate. Payment and access processes must not rely on a familiar voice alone.

Read article
Field note

Microsoft 365 availability is not your complete backup

Service resilience, retention and customer-controlled recovery solve different problems. Deleted, encrypted or maliciously removed data needs an independent recovery path.

Read article
Field note

A defensible Microsoft 365 security baseline

The strongest early improvements usually come from identity protection, administrative separation, logging and controlled external sharing.

Read article
Field note

Microsoft 365 licensing starts with requirements, not plan names

The right licence mix depends on identity, device management, security, compliance and telephony—not only Office applications.

Read article
Field note

Introducing Microsoft Copilot without exposing information

AI assistance can surface existing oversharing faster. Permissions, data hygiene and user guidance should therefore precede broad enablement.

Read article
Field note

Nextcloud instead of OneDrive: compare operating models

Sovereignty, integration and responsibility differ more than the visible file-sync features. The decision must include identity, updates, backup and support.

Read article
Field note

NIS2 for SMEs: direct duties and supply-chain pressure

Company size and sector influence direct applicability, while customer contracts can transmit security expectations far beyond formally regulated entities.

Read article
Field note

Approach NIS2 without panic—or false certainty

A calm programme starts with applicability, current evidence and the highest business risks, then assigns realistic owners and dates.

Read article
Field note

Passkeys reduce phishing risk, but rollout still needs governance

Passkeys remove reusable secrets from many login flows. Recovery, device change and legacy access still require planned processes.

Read article
Field note

Recognising phishing is a process, not a memory test

Attackers exploit urgency, trusted brands and real conversation context. Staff need a safe verification and reporting route.

Read article
Field note

Private cloud for SMEs around Hannover: when control is worth it

A private platform can improve data control and workload flexibility when the organisation accepts clear operating responsibility.

Read article
Field note

Proxmox instead of VMware: treat it as a migration, not a licence swap

Platform change affects networking, storage, backup, monitoring, support and operational skills. A workload inventory is the starting point.

Read article
Field note

Ransomware: the first actions should preserve options

Uncoordinated shutdowns, wiping and communication can destroy evidence or spread impact. Use an authorised incident path.

Read article
Field note

Refurbished hardware can be a professional business choice

Used enterprise equipment can reduce cost and waste when provenance, condition, support life and secure preparation are controlled.

Read article
Field note

RMM and patch management: visibility must lead to action

Monitoring creates value only when alerts, maintenance windows, exceptions and reporting have clear owners.

Read article
Field note

Securepoint Cert+ as a structured security starting point

A structured review is useful when it produces a transparent baseline, prioritised actions and evidence that management can understand.

Read article
Field note

VMware licensing pressure: decide from workload facts

Commercial change can justify a platform review, but urgency should not replace dependency analysis and tested migration planning.

Read article
Field note

What belongs in an IT maintenance agreement

A useful agreement makes service boundaries, response expectations, security duties and customer dependencies unambiguous.

Read article
Field note

Windows 10 after end of support: choose a controlled path

Unsupported endpoints increase security and compatibility risk. Replacement, upgrade and temporary extended support should be assessed per device and workload.

Read article
Field note

Zero Trust in plain language: verify each important access

Zero Trust is not one appliance. It combines identity, device state, least privilege, segmentation and continuous evidence.

Read article
Field note

Physical and digital access security belong together

Doors, alarm systems, identities and administrator access protect the same business processes and need coordinated ownership.

Read article

What should your IT do better next?

A short conversation is enough to establish the sensible next step.