• Latest
  • Trending
Information security as a success factor: Why it pays off!

Information security as a success factor: Why it pays off!

3. January 2023
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026

AI guideline for agencies and external service providers

14. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Information security as a success factor: Why it pays off!

3. January 2023
in Other
Reading Time: 4 mins read
0 0
A A
0

What does information security mean?

Content Hide
1. What does information security mean?
2. Why is information security essential?
2.1. Protection against economic damage
2.2. Ensuring business continuity
2.3. Legal conformity and contractual compliance
2.4. Confidence building and market positioning
3. Advantages of a practiced information security policy
4. How can information security be improved in the company?
4.1. Establishment of a safety culture
4.2. Development of a company-wide security strategy
4.3. Technical measures
4.4. Organizational measures
5. Legal requirements: When is information security mandatory?
6. TISAX: Industry standard for information security in the automotive industry
6.1. Objectives of the TISAX certification:
7. Conclusion: Information security is not an IT issue – it is corporate management
7.1. Author: Marian Härtel

Information security refers to the entirety of technical and organizational measures that serve to protect information and data from loss, unauthorized access, manipulation or other compromises. The aim is to permanently guarantee the confidentiality, integrity and availability of information – also known as the “CIA triad” (Confidentiality, Integrity, Availability).

Key Facts
  • Information security protects data from unauthorized access and manipulation.
  • Secure handling of sensitive data is essential for companies.
  • A high level of protection against cybercrime minimizes the risk of financial losses.
  • A good information security policy increases customer confidence.
  • Legal requirements demand compliance with safety standards.
  • TISAX certification promotes the protection of sensitive information in the automotive industry.
  • Investments in information security can offer decisive competitive advantages.

Unlike pure IT security, information security refers not only to digital systems, but to all forms of information, including printed documents, conversations, prototypes and organizational knowledge.

It is not just a technical issue, but also encompasses business, legal and organizational aspects. Especially in an environment of increasing digitalization, international business activities and stricter regulation, information security is a key competitive factor – and is also legally binding.

Why is information security essential?

Protection against economic damage

  • Loss of sensitive customer data or intellectual property can lead to considerable reputational and financial damage.
  • Data protection violations under Art. 32 GDPR can result in fines of up to €20 million or 4% of annual global turnover.

Ensuring business continuity

  • Information security reduces downtimes, protects against business interruptions and increases reliability – e.g. through backups and emergency plans (business continuity management).

Legal conformity and contractual compliance

  • Companies are legally obliged to implement suitable technical and organizational measures to protect personal data (see Art. 32 GDPR).
  • Increased requirements apply to the processing of particularly sensitive data (e.g. health data, trade secrets).
  • Proof of an appropriate level of information security is also increasingly becoming a prerequisite in contractual business relationships (e.g. with corporations, authorities or automotive OEMs).

Confidence building and market positioning

  • Information security creates trust among customers, partners and investors – especially in data-driven business models.
  • It is increasingly a component of ESG ratings and corporate compliance.

Advantages of a practiced information security policy

  • Reduction of the liability risk
  • Strengthening customer loyalty through trustworthy data processing
  • Compliance with legal requirements (e.g. GDPR, TKG, BDSG, Supply Chain Duty of Care Act)
  • Reputation protection in crisis situations
  • Compliance with industry-specific standards (e.g. TISAX, ISO/IEC 27001, BAIT, VAIT)

How can information security be improved in the company?

Establishment of a safety culture

  • Information security does not start with the firewall, but with the attitude of the employees.
  • Training, guidelines, regular awareness campaigns and clear responsibilities are essential.

Development of a company-wide security strategy

  • Definition of protection goals and risk analysis (e.g. through BSI basic protection, ISO 27001, VDA ISA)
  • Establishment of an ISMS (information security management system)

Technical measures

  • End-to-end encryption
  • Access restrictions and rights concepts
  • Two-factor authentication (2FA)
  • Monitoring and intrusion detection systems (IDS)

Organizational measures

  • Emergency and recovery plans (disaster recovery)
  • Employee training (regular and mandatory)
  • Audit-proof documentation of access rights, incidents and measures

Legal requirements: When is information security mandatory?

Information security is not only good practice, but also a legal requirement in many areas:

  • Art. 32 GDPR requires the implementation of appropriate technical and organizational measures to protect personal data.
  • The IT Security Act 2.0 (Germany) places special requirements on companies in the KRITIS sector.
  • Companies with processing operations in third countries must also provide special guarantees (Art. 44 et seq. GDPR).
  • Increased regulatory requirements apply in the financial sector, healthcare, transport and telecommunications (e.g. Section 8a BSIG, BAIT/VAIT, Section 75b SGB V).

TISAX: Industry standard for information security in the automotive industry

TISAX (Trusted Information Security Assessment Exchange) is a standard developed by the German automotive industry for the assessment and recognition of information security. It is based on the ISA catalog developed by the VDA, which is based on ISO/IEC 27001, among others.

TISAX is mandatory for all companies that work with sensitive information from automotive manufacturers (OEMs) – e.g. design data, production documents, personal data or prototype information.

Objectives of the TISAX certification:

  • Standardization of security requirements within the supply chain
  • Avoidance of multiple security checks by third parties
  • Proof of safe processing for OEMs

Companies from outside the industry are also increasingly using TISAX or ISO standards to document their security architecture to business partners.

Conclusion: Information security is not an IT issue – it is corporate management

Today, information security is an integral part of governance, risk and compliance. It affects not only the IT department, but all processes, systems and people in the company. Its implementation is not only legally required, but also makes strategic sense – and is ultimately a prerequisite for long-term competitiveness and trustworthiness.

The requirements may seem complex – but they are feasible. It is crucial to act early, to involve competent support and to see information security not as a project, but as a permanent management system.

Note: I support companies in the implementation of information security concepts, including TISAX preparations, training concepts and legal support in accordance with the GDPR. Feel free to contact me if you need support – both legally and organizationally.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AuthenticationCompetitive advantageComplianceData protection LawDevelopmentdigitalInformationinternetInvestmentLawsPrivacySicherheit

Weitere spannende Blogposts

The Darknet is not illegal!

Abusive warnings are punishable by law
7. November 2022

I don't have much to do with criminal law, except at the time of the state exam. That's why I...

Read moreDetails

Vision of contract execution: how smart contracts could shape the future of payments and legal processes

Vision of contract execution: how smart contracts could shape the future of payments and legal processes
19. October 2023

Introduction Technology is rapidly evolving and opening doors to new opportunities in the legal field, a development that always fascinates...

Read moreDetails

Article series: Legal problems around esport as a club

Article series: Legal problems around esport as a club
26. November 2018

In a report from the Hamburger Sportbund last Friday Should an e-sports department be located in a sports club in...

Read moreDetails

Ban on distribution? Online retailers and packaging law!

Ban on distribution? Online retailers and packaging law!
29. December 2018

Attention! As of Tuesday, there will be a new legal hurdle, for example for online retailers, namely the new packaging...

Read moreDetails

Why startups should be careful with high investments: 5 reasons pro and contra

Why startups should be careful with high investments: 5 reasons pro and contra
10. May 2023

Five reasons against rash, high investments As a lawyer and consultant, I would first like to point out to young...

Read moreDetails

Data protection when using cloud services

Data protection when using cloud services: what startups need to know
10. October 2024

Cloud services offer start-ups numerous advantages such as flexibility, scalability and cost efficiency. However, the use of cloud services also...

Read moreDetails

19th Open Stage Games in Stuttgart – typical mistakes in publishing contracts

19th Open Stage Games in Stuttgart – typical mistakes in publishing contracts
7. November 2022

Open Stage, what is it? Whether independent development studios or large publishers, fresh graduates or recruiters looking for graphic designers...

Read moreDetails

I wish you a happy year 2020

I wish you a happy year 2020
30. December 2019

I wish all readers of the blog and all clients a happy New Year 2020. Especially in the field of...

Read moreDetails

Google delisting due to data privacy?

BGH considers Uber Black to be anti-competitive
7. November 2022

On June 16, 2020, at 9:30 a.m., the German Federal Court of Justice will rule in two cases on whether...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024

Welcome to the third episode of our podcast "IT Media Law"! In this episode, we delve into the fascinating world...

Read moreDetails

On the dark side? A lawyer in the field of tension of innovative start-ups

26. September 2024

Influencers and gaming: legal challenges in the digital entertainment world

26. September 2024
Legal challenges in the gaming universe: A guide for developers, esports professionals and gamers

What will 2025 bring for start-ups in legal terms? Opportunities? Risks?

24. January 2025

Web3, blockchain and law – a critical review

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung