WOODLANDS ADVISORY
Insights

Perspectives on security and compliance.

Analysis and viewpoints from Woodlands Advisory – for decision-makers who understand security as business strategy.

17 of 17 articles

Strategy· 4 min

In conversation with ADAC — the four topics that truly occupy large security organizations in 2026

23 million members. 37 companies. One CISO. Woodlands Advisory spoke with Ümit Kuşdoğan, CISO of ADAC, about the topics that actually move enterprise security in 2026 — AI in security operations, third-party risk with regulated suppliers, regulation arriving in the audit, and AI sovereignty. The common thread: security has arrived in the business. The scarce resource is no longer budget. It is judgment.

Lesen
Strategy· 7 min

At the table with 1&1 — why the cyber market is tipping now, not in five years

On 30 June, Woodlands Advisory sat down with Robert Henninger, Head of Information Security at 1&1 — a group with roughly 16 million customer contracts and responsibility for meaningful parts of Germany's critical telecommunications infrastructure. Why the conversation was less a meeting than a confirmation. And what the IBM 2025 figures, NIS2, the EU AI Act, the CRA and DORA mean for the next few quarters.

Lesen
Journal· 3 min

Welcome to the Firm, Bjonda

Nine months ago, she tried to place me into a job. Today, she took one at Woodlands instead.

Lesen
Compliance· 11 min

Cyber Resilience Act: Why the 11 September 2026 Reporting Deadline Is the Real Inflection Point for Manufacturers and Buyers

On 11 September 2026, the CRA's reporting obligation goes live — 24-hour early warning, 72-hour full notification, 14-day final report. Germany's BSI becomes the market surveillance authority. What that means for manufacturers, software vendors and M&A buyers in the DACH mid-market — and where the traps sit.

Lesen
M&A Security· 12 min

The €4 million question — how cyber due diligence moves the purchase price

On a €120M target, a properly run cyber due diligence moves €2.4–9.6M of purchase price in expectation. Verizon–Yahoo cost 7.25% of EV. Marriott–Starwood showed what the missing DD costs. An analytical framing with the primary sources behind the claim.

Lesen
Strategy· 8 min

72 Percent. $3.4 Million. What Two International PE Reports Mean for DACH.

In November 2025, Russell Reynolds reported that 72 percent of all PE firms in the US and Europe had a serious cyber incident inside a portfolio company within three years — averaging $3.4 million per incident. RSM, working from the consultant side, points to the underlying cause: a lack of visibility across the portfolio. For DACH operating partners, these are not US stories — they are an instruction for the next 24 months.

Lesen
M&A Security· 8 min

M&A Is Back. Cyber Diligence Has to Catch Up.

McKinsey's 2026 M&A Trends report puts global deal value at $4.7 trillion, up 43 percent year-on-year. Megadeals are at multi-year highs, hold periods have lengthened to 6.2 years, and TMT alone accounted for nearly a quarter of all activity. Each of these shifts changes what cyber due diligence has to look like — and how long it has to stay in place.

Lesen
Partnership· 5 min

Woodlands Advisory and Aikido: Application Security on a Single Platform — From Repository to Runtime

Woodlands Advisory is now an official Aikido partner. What this means for organisations that no longer want to spread code, supply chain and cloud security across five disconnected tools.

Lesen
Partnership· 5 min

Woodlands Advisory and Kertos: Data Protection Compliance That Stays in Germany

Woodlands Advisory is now an official Kertos partner. What that means for organisations that refuse to leave GDPR, data protection, and EU compliance to chance.

Lesen
Threat Landscape· 8 min

The Supply Chain as Entry Point: Why the Attack on SAP Packages Is Not a Niche Problem

SAP development packages with nearly ten million monthly downloads were compromised in early May 2026. Simultaneously, supply chain attacks against Ruby Gems, Go modules and PyPI are multiplying. What is driving this – and why DACH companies need to audit their CI/CD pipelines now.

Lesen
Threat Landscape· 9 min

"AI Has Made It Worse": Jamie Dimon, JPMorgan and What It Means for European Companies

In JPMorgan Chase's Q1 2026 earnings call, CEO Jamie Dimon named cyber risk as the firm's single greatest threat – and AI as its primary amplifier. Reports of short-notice meetings between US regulators and America's largest banks add weight to that assessment. What DACH companies need to take from this.

Lesen
Partnership· 4 min

Woodlands Advisory and Vanta: Compliance Automation Meets Strategic Advisory

Woodlands Advisory is now an official Vanta partner. What that means in practice for companies on the path to ISO 27001, NIS2, or SOC 2.

Lesen
Threat Intelligence· 6 min

Threat Landscape DACH: What the Threat Dashboard Shows — and How to Read It

DACH companies are targeted by sophisticated attacks daily. The Woodlands Threat Dashboard distils current threat data into actionable assessments — for management and boards, not security teams.

Lesen
Strategy· 8 min

Trade Wars and Cyber Threats: What Macroeconomic Instability Means for DACH Cybersecurity

Rising tariffs, recession fears and geopolitical tensions are fundamentally reshaping the threat landscape for DACH companies. State-sponsored actors are deliberately exploiting economic uncertainty – while security budgets face mounting pressure.

Lesen
M&A Security· 7 min

M&A Cyber Due Diligence: The Checklist for Target Companies

Many companies discover their security gaps only during the sale process — when it's too late to close them without a price reduction. Twelve areas that buyers systematically examine, and how to prepare.

Lesen
NIS2· 6 min

NIS2: What Executives Are Now Personally Liable For

The NIS2 Directive makes cybersecurity a board-level matter – with personal liability of up to €10 million. What this means in practice and how to protect yourself.

Lesen
M&A Security· 7 min

Cyber Due Diligence: The 7 Questions Investors Are Asking Now

PE investors are systematically integrating cybersecurity into their M&A processes. Target companies that arrive unprepared risk price reductions – or the collapse of the deal entirely.

Lesen
Newsletter

New articles delivered to your inbox.

No spam. No sales pitches. Only relevant content when there is something worth saying.