Cybersecurity Requires Community— Why?

By GTIA

Jan 15, 2026

Share this post

image of hands holding a lock

Cybersecurity is no longer purely a technical issue—it is business-critical. System houses and MSPs are under increasing pressure not only to understand security issues, but also to actively address them. With the entry into force of NIS 2, MSPs and companies are under increasing pressure to invest in IT security.

Hena Kless (Wire) and Jürgen Ebner (ICTE) have launched the GTIA Cybersecurity Interest Group. The first online meeting will take place on January 20. We asked Hena and Jürgen what motivated them to take this step, which topics are particularly close to their hearts, and how interested parties can get involved. Participation is free of charge. Click here to register.

>> Read this article in German.

Why a separate SIG for system houses and MSPs? What is currently missing in the exchange?

Jürgen:

For me, exchanging ideas with colleagues has always been a key factor for success—whether regionally, nationally or internationally. The challenges in IT security are similar everywhere, because cyberattacks know no national borders. For years, I have maintained contacts in various networks: Regionally and nationally, for example, in the IT Security Expert Group and as a spokesperson in the IT Security Working Group of the Styrian Chamber of Commerce, and internationally with colleagues from the United States, UK and Benelux.

But what I have been missing in German-speaking countries so far is a structured, practical exchange specifically for system houses and MSPs. Precisely because we have comparable legal requirements and similar customer expectations here, the need is great. This also became clear at the World Café during our last GTIA community meeting: The community wants formats in which real cases, mistakes and best practices are discussed openly—on an equal footing. We are all interested in learning from each other and jointly developing pragmatic solutions that work in everyday life.

What typical security risks do you encounter in your daily work with MSPs and system houses—and how should the SIG help to deal with them better?

Jürgen:

In everyday life, we repeatedly encounter the same challenges: Phishing, social engineering, identity theft, cloud security and the implementation of new regulatory requirements such as NIS2 or DORA. Prioritization is often a real challenge, especially in small and medium-sized enterprises with limited resources. Awareness is important, but many are oversaturated with traditional training courses—“awareness fatigue” is real.

What helps is an open exchange about real cases and concrete solutions. That's exactly what this group aims to offer: Practical tips, best practices, tool recommendations and an honest exchange of experiences—including mistakes and lessons learned. The World Café showed that this is exactly what many people want: formats where they can easily ask questions and benefit from the experiences of others. SIG is intended to be a platform where we can work together on pragmatic solutions that really work in everyday operations.

How do you intend to ensure that the content of the interest group does not remain purely theoretical, but delivers real added value for everyday operations?

Hena:

We consistently adhere to the principle of “from practice for practice.” This means no purely theoretical lectures, but rather the exchange of concrete instructions, checklists and blueprints that our members can implement directly the next day. We also create space for honest exchange—including about things that have gone wrong (lessons learned). When we talk about frameworks, we don't talk about them in abstract terms, but with a view to how they can be implemented in an SME with limited resources.

Jürgen:

It's also important to me that everyone takes away something from an interest group meeting that they can try out directly in their own company. Questions are expressly welcome. The group should be a place for genuine exchange and practical solutions. What would make me particularly happy is if the participants in the group also dared to talk openly about their  mistakes. Because it is often from mistakes and failed projects that the community learns the most.

What topics do you want to put on the agenda at the beginning?

Hena:

We're starting with a triad of law, people and technology: Practical implementation aids for NIS2, modern concepts against phishing and social engineering, and a deep dive into securing cloud environments.

Jürgen:

As Hena said, we are focusing on the triad of law, people and technology—exactly as the participants wanted. The topics mentioned in the World Café are very diverse: From NIS2 and other regulations to awareness and social engineering to cloud security and recovery strategies. We will work together to see how we can incorporate these topics in a meaningful way—and ensure that there is always enough space for open exchange. After all, the added value comes primarily from discussion and practical experience.

What is your ideal vision for the interest group in a year's time? What specific improvements do you want to see for members – in terms of expertise, strategy or networking?

Hena:

In a year's time, the group will be a hub for honest exchange, where we talk straight instead of exchanging marketing platitudes. Our goal: To take cybersecurity out of the expert niche and establish it as a relevant skill for everyone—supported by a strong, trusting community that backs each other up.

Jürgen:

I hope that, as a community, we can find a way to show our customers that cybersecurity is not just a cost factor, but a success factor for every company. Through open exchange within the group, we gather arguments, share experiences, and jointly develop convincing counterarguments. In this way, we position IT security as a real added value and a strategic investment—and not as a tiresome obligation.

Be a part of the conversation!

Get involved in the GTIA DACH Cybersecurity Interest Group. Contact Katrin Giza.

Related Posts:

Hände, die ein Schloss halten
By GTIA / Jan 15, 2026

Cybersecurity braucht Gemeinschaft – warum?

Cybersecurity ist längst kein rein technisches Thema mehr – sie ist geschäftskritisch. Systemhäuser und Managed Service Provider (MSPs) stehen unter wachsendem Druck, Sicherheitsfragen nicht nur zu verstehen, sondern aktiv anzugehen. Mit dem Inkrafttreten von NIS 2 steigt der Zwang für MSPs und Unternehmen, in IT-Sicherheit zu investieren.
IT workers discussing green initiatives
By Scott Campbell / Nov 5, 2025

Von Anwendungen bis zum Rechenzentrum: Nachhaltigkeit in der IT – Chancen und Herausforderungen

Mit mehr als 500 Rechenzentren und einem steigenden Bedarf an künstlicher Intelligenz und Speicherplatz wird die IT-Branche in Deutschland mehr Infrastruktur benötigen. Das bedeutet: höherer Energieverbrauch und steigende Kosten.