Blog
Stopping IT sprawl: strategies against shadow IT and redundant software, and how companies stay in control
8 min read
ReadBlog
Since December 2025, Germany's NIS2 implementation act makes IT transparency a legal duty for roughly 29,500 companies — with personal liability for management. What this means in practice and how to get started.
Cyberattacks on German companies have reached a record level. According to the Bitkom study "Wirtschaftsschutz 2025," 87 percent of companies in Germany were affected by data theft, espionage, or sabotage within twelve months, with total economic damage of €289.2 billion. According to IBM, it takes an average of 241 days to identify and contain a security incident.
Since December 6, 2025, a second dimension has been added: Germany's NIS2 implementation act (NIS2UmsuCG) makes IT transparency a legal duty for roughly 29,500 companies — those with 50 or more employees or €10 million or more in annual revenue in one of 18 covered sectors. With no transition period.
A company that doesn't know which IT systems are running can neither protect nor defend them. That is exactly the situation in practice: legacy systems, decentralized procurement, and the constant switching between spreadsheets, ticketing systems, and the knowledge held by individual employees mean that no one in the organization can reliably answer which applications, services, and interfaces are actually in use.
The law does not mandate a standalone "application inventory" as an isolated obligation. But the required measures are practically impossible to fulfill without one:
If you don't know which systems exist in your company, you cannot run a risk analysis on them, and you cannot report within 24 hours exactly what was affected.
Without a current application overview, the same chain reaction typically unfolds: reporting deadlines are missed because nobody can quickly identify which systems and data are affected. Containing an attack is delayed because interfaces and data flows aren't documented. And afterward, there's no evidence of the security measures that were in place — with fine risk and personal liability for management under Section 38.
Read the full analysis
The complete analysis — with full source references, the complete NIS2 obligations checklist, and detailed recommendations — is available as a free white paper: Download "Blind in a Crisis?" as a PDF
knooing is an AI-native IT management platform that automates exactly this kind of transparency — instead of spreadsheets and tribal knowledge. A central, AI-supported registry of all applications, services, contracts, and licenses delivers, in minutes rather than days, the answer to "which systems, data, and contracts are affected?" — the basis for timely reporting, effective containment, and evidence for BSI, customers, and insurers.
This article provides a general overview and does not constitute individual legal advice.
More articles
Blog
8 min read
ReadBlog
4 min read
ReadBlog
8 min read
ReadSchedule a free, no-obligation demo