<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Areko Consulting - Data Security, Data Privacy and Compliance on Data Security, Data Privacy and Compliance</title><link>https://areko.consulting/en/</link><description>Recent content in Areko Consulting - Data Security, Data Privacy and Compliance on Data Security, Data Privacy and Compliance</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://areko.consulting/en/index.xml" rel="self" type="application/rss+xml"/><item><title>Strategies against cyberattacks at the heart of your company</title><link>https://areko.consulting/en/events/2025-11-webinar-strategies-against-insider-threats/</link><pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/events/2025-11-webinar-strategies-against-insider-threats/</guid><description>We find it difficult to accept that threats often come from within our company. According to a Bitkom study, around 27% of IT attacks on German companies were deliberately carried out by (former) employees in 2024. Despite this, many companies are still focussing on the network perimeter.
However, working from home, multi-cloud setups, the use of SaaS and third-party APIs have removed the traditional boundaries. The network perimeter is no longer a reliable security boundary and we need new strategies.</description></item><item><title>With Data Masking reduce development costs and data privacy violations risks</title><link>https://areko.consulting/en/events/2025-10-webinar-data-masking-reduce-development-costs-data-privacy-risks/</link><pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/events/2025-10-webinar-data-masking-reduce-development-costs-data-privacy-risks/</guid><description>When it comes to troubleshooting IT projects, every hour counts - delays quickly drive up costs. To reproduce and fix bugs quickly, your development and QA teams can work more effectively with realistic test data. At the same time, you reduce your data protection and compliance risks by not requiring your developers to use or copy real personal and sensitive data in production.
The webinar is aimed at IT and software development managers, QA managers, data protection officers and IT security officers.</description></item><item><title>Discover data leaks in under 24 hours</title><link>https://areko.consulting/en/events/2025-09-webinar-compliance-discover-data-leaks-under-24-hours/</link><pubDate>Thu, 04 Sep 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/events/2025-09-webinar-compliance-discover-data-leaks-under-24-hours/</guid><description>Regulators in the EU are raising the bar for data privacy and security. Timely reporting of significant events under 24 hours and full details in 72 hours are expected from your organization to comply with NIS2.
In this webinar, you will learn how to discover leaks when they happen, prevent them altogether, and ensure compliance —without slowing down your systems. We will also share practical steps and real-world experiences that help organizations protect sensitive personal, financial and health data.</description></item><item><title>Outsourcing of Data Compliance Tasks</title><link>https://areko.consulting/en/services/outsourcing-data-compliance-tasks/</link><pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/services/outsourcing-data-compliance-tasks/</guid><description>External support for your data compliance processes I offer you data compliance services with a clear cost structure with my all-round service as an external IT security service provider. This reduces your unforeseeable compliance costs and risks.
If your administrators do not have time for data security and data compliance, I document where your sensitive data is located and prioritise its protection based on a risk and damage assessment. I carry out these tasks completely independently in collaboration with your IT department and, if necessary, your external software service providers.</description></item><item><title>Reduce data compliance costs for new IT projects</title><link>https://areko.consulting/en/services/new-systems-privacy-by-design/</link><pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/services/new-systems-privacy-by-design/</guid><description>Cost reduction through targeted data compliance management in new projects When developing new systems, I advise your IT management and your external IT service providers with the aim of reducing the costs of implementing data compliance and data security. In addition, I look for elegant solutions that fulfil the requirements of data protection and IT security officers as well as other stakeholders. In doing so, I take the budget, the available IT resources, and deadlines into account.</description></item><item><title>Database Auditing Tools: Installation and Configuration</title><link>https://areko.consulting/en/services/database-auditing-tools-installation/</link><pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/services/database-auditing-tools-installation/</guid><description>If you have an established team of database administrators I support you in identifying sensitive data in your systems, documenting current security measures and analysing which measures still need to be implemented to meet legal requirements. Together we define the criteria for selecting a database auditing solution, if one is necessary.
I will help you to select a vendor and negotiate features and licences prior to purchase.
Finally, I install the software on your servers, train your administrators and support you in investigating incidents and identifying the reasons for abnormal database behaviour.</description></item><item><title>Our privacy policy</title><link>https://areko.consulting/en/our-privacy-policy/</link><pubDate>Wed, 10 Apr 2024 10:12:42 +0300</pubDate><guid>https://areko.consulting/en/our-privacy-policy/</guid><description>Privacy policy of Areko Consulting Ltd.</description></item><item><title>Imprint</title><link>https://areko.consulting/en/imprint/</link><pubDate>Wed, 10 Apr 2024 10:05:25 +0300</pubDate><guid>https://areko.consulting/en/imprint/</guid><description>Imprint of Areko Consulting Ltd.</description></item><item><title>Terms and Conditions</title><link>https://areko.consulting/en/terms-and-conditions/</link><pubDate>Wed, 10 Apr 2024 10:05:25 +0300</pubDate><guid>https://areko.consulting/en/terms-and-conditions/</guid><description>Terms and Conditions of Areko Consulting Ltd.</description></item><item><title>Compliance: Logging all database activity is already possible today</title><link>https://areko.consulting/en/blog/2026/09/compliance-logging-all-database-activity-is-already-possible-today/</link><pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/09/compliance-logging-all-database-activity-is-already-possible-today/</guid><description>As a former developer, new IT security products show me that I was wrong. It is possible to store all DB activities for security and compliance reasons. What I considered impossible is being sold nowadays and has been running in production at financial institutions for 15 years.
&amp;ldquo;All database activities are stored with a granularity of five minutes,&amp;rdquo; claims the founder of a company I work with. He is talking about Core Audit from the company Blue Core Research.</description></item><item><title>My Vision for IT Security: From Reaction to Prevention</title><link>https://areko.consulting/en/blog/2026/08/my-vision-for-it-security-from-reaction-to-prevention/</link><pubDate>Thu, 27 Aug 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/08/my-vision-for-it-security-from-reaction-to-prevention/</guid><description>&amp;ldquo;What do I want to achieve with my work in IT security?&amp;rdquo; I was recently asked. When you drive a car, ride a bike, or walk on the street, you make a risk assessment and decide how to behave to arrive safely and avoid causing damage. I wish an implicit risk assessment in the development, purchase, and maintenance of IT systems and infrastructures to protect companies&amp;rsquo; value creation and jobs.</description></item><item><title>After a ransomware attack, GDPR auditing helps</title><link>https://areko.consulting/en/blog/2026/08/after-a-ransomware-attack-gdpr-auditing-helps/</link><pubDate>Tue, 25 Aug 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/08/after-a-ransomware-attack-gdpr-auditing-helps/</guid><description>Following a ransomware attack, the logging required by the GDPR plays a key role in assessing the resulting damage. “In a large number of typical ransomware attacks, it must now be assumed that personal data has been stolen by attackers in the context of the ransomware and is being misused. (&amp;hellip;) Consequently, this means that in such cases, the data subjects – e.g. employees, suppliers, customers, clients or patients – must usually also be notified of the incident in accordance with Article 34 of the GDPR,” states the Bavarian State Office for Data Protection Supervision1, adding: “In particular, the question of whether there is a reasonable likelihood that no data flows to the attackers have taken place must be adequately addressed (e.</description></item><item><title>Access to Personal Data by Administrators Can Be Blocked</title><link>https://areko.consulting/en/blog/2026/08/access-to-personal-data-by-administrators-can-be-blocked/</link><pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/08/access-to-personal-data-by-administrators-can-be-blocked/</guid><description>As a developer, I assumed that database administrators had access to all data of an application, including confidential data, and that nothing could be done about it. But this claim has not been true for 15 years. Nowadays, reading, editing, or deleting personal, financial, or health data can also be blocked for administrative accounts. This allows database administration to be outsourced while simultaneously avoiding the risks of data exfiltration or unintentional changes.</description></item><item><title>Benefits of Designing Systems Without Personal Data</title><link>https://areko.consulting/en/blog/2026/08/benefits-of-designing-systems-without-personal-data/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/08/benefits-of-designing-systems-without-personal-data/</guid><description>That we more frequently design systems without personal data is a positive effect of the GDPR. These solutions are generally easier and cheaper to develop and maintain. As an IT architect, I recall two projects where the final design pleasantly surprised me.
The department responsible for 70% of an online shop&amp;rsquo;s revenue had new competition and wanted a completely new online shop with live pricing and new additional services that our seven-year-old online platform could not support.</description></item><item><title>DORA: The Reported Costs of Major IT Incidents in 2025 Are Questionable</title><link>https://areko.consulting/en/blog/2026/08/dora-the-reported-costs-of-major-it-incidents-in-2025-are-questionable/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/08/dora-the-reported-costs-of-major-it-incidents-in-2025-are-questionable/</guid><description>Thanks to DORA, we now have the first public statistics on major IT incidents in the EU. However, the reported costs raise several questions.
&amp;ldquo;Based on the available information, it seems that major incidents had a very limited monetary impact: half of them did not report any direct or indirect costs (almost 40 %) or indicated to have suffered a negligible monetary impact, with direct and indirect costs amounting to less than EUR 1,000 (around 10 %)&amp;rdquo;, states the &amp;ldquo;Joint ESA Report pursuant to Article 22 DORA for the year 2025&amp;rdquo;1.</description></item><item><title>NIS2 Compliance: A Cost Factor or a Shield for Your Business?</title><link>https://areko.consulting/en/blog/2026/05/nis2-compliance-cost-factor-or-company-shield/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/05/nis2-compliance-cost-factor-or-company-shield/</guid><description>The NIS2 Directive is intended to safeguard prosperity in Germany through economic, proportionate, and effective security measures. Already 70% of the total damage to the economy was caused by cyberattacks. However, only half of the affected companies had signed up by the Federal Office for Information Security (BSI) by March. We will discuss the reasons for this reluctance, as well as whether investing in compliance with the new legal obligations is worthwhile and which NIS2 implementation strategy is most suitable for your company.</description></item><item><title>Contact Form</title><link>https://areko.consulting/en/contact/error/</link><pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/contact/error/</guid><description>Enquiry failed Unfortunately, your inquiry could not be sent to our CRM. Please email us to contact_us at go.areko.consulting and we will reply in less than two working days.</description></item><item><title>Contact Form</title><link>https://areko.consulting/en/contact/success/</link><pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/contact/success/</guid><description>Enquiry sent Thanks for your inquiry! We will contact you in less than two working days.</description></item><item><title>Risk Assessment for IT Projects: Template and Tips for Collaborating with Development Teams</title><link>https://areko.consulting/en/blog/2026/03/risk-assessment-for-it-projects-template-and-tips-for-collaborating-with-development-teams/</link><pubDate>Wed, 04 Mar 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/03/risk-assessment-for-it-projects-template-and-tips-for-collaborating-with-development-teams/</guid><description>Note: Please turn on the subtitles in English.
To ensure that your security and data compliance requirements are considered by development teams from the beginning of IT projects, you need a risk assessment that fits the language of IT. In this post, I share a template to be filled out by IT leads or project managers, serving as a basis for joint risk analysis.
I also give you practical tips on how to raise security awareness among the development team so that they consider the requirements of the information security officer and data protection officer from the kick‑off meeting onward.</description></item><item><title>Template for Risk Assessment of IT Projects</title><link>https://areko.consulting/en/blog/2026/03/template-for-risk-assessment-of-it-projects/</link><pubDate>Wed, 04 Mar 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/03/template-for-risk-assessment-of-it-projects/</guid><description>Note: For security reasons, I don&amp;rsquo;t provide a Word, LibreOffice, or RTF document. You can simply copy and format the questions as text.
Project Details Identification Number: Project&amp;rsquo;s Name: Client/Requester: Product Owner/Project Manager: Architecture Description Purpose of the System: Production Server Diagram Code and Function of Involved Systems and Microservices: Security Measures How are these systems secured/protected? Which network protocols are used? Which authentication methods are applied? How is user management handled and who&amp;rsquo;s responsible for it?</description></item><item><title>Preventing Burnout as a CISO and CIO: Practical Tips for Greater Resilience</title><link>https://areko.consulting/en/blog/2026/02/preventing-burnout-as-a-ciso-and-cio-practical-tips-for-greater-resilience/</link><pubDate>Fri, 06 Feb 2026 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2026/02/preventing-burnout-as-a-ciso-and-cio-practical-tips-for-greater-resilience/</guid><description>Note: Please turn on the subtitles in English.
Without health, we can’t protect our companies from cyberthreats. The roles of an CISO or a CIO are very demanding, and it&amp;rsquo;s difficult to avoid negative stress that can lead to burnout. This includes constant communication with stakeholders from different departments, the general underestimation of investments in IT security and IT infrastructure in companies, as well as the broad scope of responsibilities that covers all processes in the company.</description></item><item><title>Books and online courses on B2B sales &amp; marketing</title><link>https://areko.consulting/en/blog/2025/11/books-and-online-courses-on-b2b-sales-marketing/</link><pubDate>Sat, 15 Nov 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2025/11/books-and-online-courses-on-b2b-sales-marketing/</guid><description>You can find online too many resources to learn about B2B sales and marketing. But after one course and two books, I realized that the core concepts and daily activities are always the same. Here are my recommendations in the order I would have read/watched them:
Compact Introduction to B2B Sales: The Udemy Course The Ultimate Sales Development Rep Training Programme It teaches you what the daily tasks of a Sales Representative (SDR) look like.</description></item><item><title>About me</title><link>https://areko.consulting/en/about-me/</link><pubDate>Wed, 03 Sep 2025 15:15:34 +1000</pubDate><guid>https://areko.consulting/en/about-me/</guid><description>I call myself an engineer: someone who solves problems. These days, my job is to find organisations struggling with data security, data privacy and compliance issues and solve these problems using off-the-shelf software. Life has always surprised me with unexpected opportunities, so my plans are constantly changing.
Vision A Europe where businesses operate with confidence, knowing their critical business processes and data are resilient against internal and external threats, as well as software and hardware failures.</description></item><item><title>Cost-Effective Security for Your Data</title><link>https://areko.consulting/en/blog/2025/06/cost-effective-security-for-your-data/</link><pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2025/06/cost-effective-security-for-your-data/</guid><description>Why is the security of your data important? How long could your company operate without up-to-date data? Imagine turning on your laptop and finding it unable to display information from the last seven days. Or noticing that incorrect information is being displayed across all programs. Naturally, your company&amp;rsquo;s data also requires a certain level of confidentiality. Just imagine a former employee taking a list of all your customers and suppliers on their last day of work.</description></item><item><title>Code Generator and IA Assistant for Unpopular Frameworks</title><link>https://areko.consulting/en/blog/2024/08/code-generator-and-ia-assistant-for-unpopular-frameworks/</link><pubDate>Fri, 23 Aug 2024 00:00:00 +0000</pubDate><guid>https://areko.consulting/en/blog/2024/08/code-generator-and-ia-assistant-for-unpopular-frameworks/</guid><description>If you are a developer using hardly known frameworks, you must be struggling to find a code generator which really ease your daily work. The general-purpose statistical LLMs only work well, if they get enough training data with code and that code can only include the most popular tools and frameworks. All of us working on the unpopular side, are left in the dark.
Cheap but precise code generator and assistant for proprietary frameworks Now I am holding a lamp at my work and it is called Aider.</description></item></channel></rss>