• Contact
  • Customer Portal
  • Partner Portal
  • Jobportal
  • Search
  • DE
LogoGenua Logo
  • Solutions
    IT Security Solutions

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Firewalls & Gateways

      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN

      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance

      • Remote Service Solution genubox
    • Mobile Working

      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes

      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security

      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter

      • Central Management Station genucenter

    Comprehensive Security Solution genusecure Suite

    Comprehensive solution for workplaces complient with the classification level German VS-NfD
    [Translate to English:]
  • Fields of Use
    Fields of Use

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Public Sector

      IT Security Solutions for Authorities and Public Institutions

    • Critical Infrastructure

      Protection of Critical Infrastructures and Sensitive Systems

    • Defense

      IT Security for Military Networks and Data Communications

    • Classified Industry

      IT Protection for Projects with Confidentiality Requirements

    • IT Security for Mechanical and Plant Engineering

      IT Security for Networked Machines and Systems

    Fotocollage zur High Resistance Firewall genugate (Verwendung nur für die Presse)

    Our sales team will be happy to answer your enquiries. Let us advise you!

    Get in Touch

  • Service & Support
    Service & Support

    Contact

    + 49 89 991950-0info@genua.deContact us
    • IT Security Services

      On-site Support, 24/7 Hotline and Regular Update Services

    • Trainings

      Product and Solution Trainings for Your Team - Practical and Up-to-date

    • Hacking Bootcamp

      Improve the Defence of Your Systems and Get to Know the Techniques of Real Hackers

  • Topics & Trends
    Topics & Trends

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Topics

      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base

      Case Studies, White Papers, Specialist Articles, Interviews and Insights from the IT Industry

    • Research Projects

      Whether it's Post-Quantum Cryptography or a Secure Cloud - Here You Will Find an Overview of our Current Research Projects

  • Partners
    Partners

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Sales Partner

      Benefit from the expertise of our qualified Sales Partners

    • Partnerlocator

      Find your genua Sales Partner in our overview

    Three employees in a sales dialogue

    In our Partner Portal we provide services to support you in your sales activities.

    To the Partner Portal

  • Career
    Career

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Working at genua

      Start Your Career with the Leading IT Security Specialist

    • Vacancies

      Our current vacancies at all locations

    • Speculative Application

      Send us your application now.
We look forward to hearing from you.

    Two genua employees engrossed in a cheerful conversation

    Start Your Career now at the Leading IT Security Specialist genua

     Career site

  • About Us
    About Us

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Facts & Figures

      Milestones in genua's Success Story: a Look at the Figures

    • News

      The Latest News on Products and Company Updates

    • Trade Fairs & Events

      Meet us and Our Experts at the Most Important IT Security Events

    • Press & Media

      Press Releases and Media Downloads

    • Trainee Firm genufix

      Fast & Free Help for Charitable and Social Organisations in and Around Kirchheim near Munich

    • genukids

      In-house Childcare for Employees and Residents of Kirchheim

  • DE
  • Solutions
    • Firewalls & Gateways
      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN
      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance
      • Remote Service Solution genubox
    • Mobile Working
      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes
      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security
      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter
      • Central Management Station genucenter
  • Fields of Use
    • Public Sector
    • Critical Infrastructure
    • Defense
    • Classified Industry
    • IT Security for Mechanical and Plant Engineering
  • Service & Support
    • IT Security Services
    • Trainings
    • Hacking Bootcamp
  • Topics & Trends
    • Topics
      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base
    • Research Projects
  • Partners
    • Sales Partner
    • Partnerlocator
  • Career
    • Working at genua
    • Vacancies
    • Speculative Application
  • About Us
    • Facts & Figures
    • News
    • Trade Fairs & Events
    • Press & Media
    • Trainee Firm genufix
    • genukids
  • Contact
  • Customer Portal
  • Partner Portal
Displaying results 97 to 112 of 210.
Results per page:
pages 93
press 48
knowledgebase 37
news 16
product 16

EUROGATE Puts its Trust in genugate

Case Study 14.04.2008 EUROGATE Puts its Trust in genugate Europe’s Largest Container Terminal Operator Safeguards IT and Data Communication with a Firewall Cluster that Guarantees High Availability. Global trading today utilizes a universal form of packaging – the container. Regardless of whether textiles, television sets, raw steel, refrigerated fruit, or gasoline, there is room for everything in these standardized steel crates. Most of them will travel around the globe on container ships, and the number is steadily growing. Container transport is currently expanding at the rate of ten percent each year, matched by a similar increase in the number and size of the ships used. The latest container ships can stack up to 15,500 TEUs (twenty-foot equivalent units, or standard containers). Stacked containers in the port of Hamburg The advantages of the container become most apparent when it reaches its destination port. Instead of the goods having to be transferred individually, which would be a most laborious process, the entire container can simply be moved onto a train or truck for onward shipment. Careful coordination is required at this stage. Computers calculate the optimum procedure, to ensure that all the containers end up promptly in the right place, while customers are kept constantly updated on the status of their delivery. Data exchange must always be able to function in this environment, since breakdowns can mean longer wharf and shipment times, and thus higher costs as well. EUROGATE, the largest container terminal operator in Europe, uses a cluster with two-tier firewall systems to safeguard and ensure the high availability of its data connections at the LAN-Internet interface. EUROGATE operates a total of nine container terminals in Europe, and has a total workforce of 6,600. The largest terminal is Bremerhaven, while Hamburg has the most dynamic growth. As soon as a ship docks here, the huge container cranes start their work: They move busily back and forth, loading and unloading the huge ships at high speed. This speed is possible only thanks to perfect coordination. Software programs calculate all the processes and generate the optimum stowage plan. This ensures that no container is suddenly in the wrong place, or has to be moved several times. Continuous Exchange of Data is Needed for Efficient Coordination Bremerhaven is EUROGATE’s largest container terminal Data needs to be exchanged constantly in order to coordinate procedures: Ship owners e-mail information on their cargoes, container deliveries, and onward transport. In turn, the terminal operator uses the “Infogate,” to provide detailed information on the status of the unloading of ships, so that customers are at all times aware of where each of their containers is. EUROGATE is also in constant contact by data line with many business partners who provide additional logistics services, or who carry out maintenance work. If this flow of information were ever to break down, work on the long quays would quickly come to a standstill – and EUROGATE would incur substantial additional costs. Stephan Krause, IT Administrator at EUROGATE in Hamburg explains: "To ensure, for example, that a container from Beijing gets to the right consignee in Berlin on the agreed date, a lot of different processes need to mesh together perfectly. Reliable data exchange between all the parties involved is absolutely crucial to maintain this complex logistics exercise, so we place the highest priority on IT security and reliability." In its efforts to ensure that these standards are met, the terminal operator is assisted by the Hamburg-based IT consulting and services company secion GmbH. Critical Ioint: The interface to the Internet Must be Secured To ensure reliable data communication, it is essential to secure the gateway between the local EUROGATE network and the Internet. In this instance, the secion IT specialists recommended the use of two genugate firewalls that are combined to form a cluster. secion Managing Director Hellmuth Michaelis is convinced that the genugate firewall is the right solution for requirements such as these: "In a cluster, the system can be used with a high degree of availability, and, thanks to the two-tier system, it provides a high level of security that has been tested by the German Federal Office for Information Security (BSI), and certified to an extremely high level." genugate is a security solution developed by German firewall company genua, which is based in Kirchheim, near Munich. The option of combining genugates in clusters is an important feature: the systems in the clusters share tasks and monitor one another. If one system breaks down, the other can take over the entire load at short notice. As a result, the firewalls act as an efficient protective wall, ensuring high availability between the Internet and the company network. Secure: Demilitarized Zone for Online Services The firewalls also divide the internal area of EUROGATE into two separate networks: the demilitarized zone (DMZ), and the actual Local Area Network (LAN). The DMZ contains the systems that can be accessed from both the Internet and the LAN, e.g. the Infogate information system. The LAN itself, with the clients, is even more securely sealed off. No external access is possible here, except for expressly authorized connections. The two internal security zones can be set up very easily, since genugate provides two firewall systems in one solution: an Application Level Gateway and a packet filter. Both systems are different types of firewall, and run on physically separated computers. The DMZ is protected from the Internet by the Application Level Gateway, while the LAN enjoys twofold protection thanks to the additionally installed packet filter. Secure Protection: Two Firewall Systems in One Solution Gantry cranes are busy around-the-clock Data from the Internet therefore has to get through two firewall systems before it reaches the EUROGATE LAN. However, its journey comes to an abrupt end at the first control point: The Application Level Gateway blocks the data packets, and a direct connection is never permitted. The system checks the packets, analyzes the contents, and blocks out harmful data, such as viruses or active web content. Once its content has been carefully examined by the Application Level Gateway, the data passes on to the second firewall system, the packet filter, immediately upstream of the LAN. The packet filter is designed to be even more restrictive. It generally allows through only data packets that have previously been requested by the LAN. Data packets are checked at network and transport level using the header information. Individual ports need to be expressly activated for other external connections. Greylisting Helps Defeat Spammers High Resistance Firewall genugate genugate also has an efficient method of dealing with annoying spam. Greylisting is based on a simple technique. Three pieces of information are queried for all incoming mail: the IP address of the dispatching mail server, the address of the sender, and that of the recipient. If this three-part data combination occurs for the first time, the e-mail is rejected, but the new set of information is stored. In these cases, professional mail servers will make a second attempt to deliver after a short period of time. Since the three-part set of information is already known, the mail is then allowed through to the recipient. Spammers, on the other hand, focus on sending volume in the shortest possible period, and do not waste time on repeat deliveries. For that reason, they are foiled by greylisting. "We receive around 30,000 e-mails per day, but, thanks to greylisting, only 5,000 are accepted. This method successfully mitigates the annoying problem of spam," explains Stephan Krause. EUROGATE is using two genugates in a cluster that is regularly updated with new software from the manufacturer genua to combat any new risks. Stephan Krause summarizes the advantages of the system as follows: "genugate has two coordinated firewalls whose control mechanisms complement one another at different levels, providing reliable protection for our network. With the continuing success of EUROGATE, we are experiencing an increasing number of attempted attacks, but with this solution no security issues have ever arisen." genugate Firewall is Certified to the Highest Level This appraisal has also been confirmed by the German Federal Office for Information Security (BSI). It has certified the two-tier solution in accordance with the international Common Criteria (CC) standard at the EAL 4+ security level. This is the highest level that can reasonably be applied to a complex security system such as a firewall. However, genugate can meet even higher standards when it comes to the important security criterion of "Self-protection against direct attacks." Here, it meets the criteria for EAL 6. This is a significant point: A firewall must be equipped to deal with all kinds of attacks or attempts to manipulate data if it is to provide reliable security for the network it is guarding. Because of this function, the firewall is also classified as “highly resistant" – the only firewall in the world to achieve this rating. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Industry Firewalls & Gateways Share Article Related Links High Resistance Firewall genugate Complete data analysis for maximum network security Back to Overview

EU roadmap for the transition to post-quantum cryptography

Interviews 15.07.2025 Expert Interview with Stefan-Lukas Gazdag EU Calls for Transition to Post-Quantum Cryptography – are We Prepared? With the support of the Commission, the EU member states have published a roadmap and timeline for moving toward a more complex form of cybersecurity : According to this roadmap, all member states have to begin the transition to post-quantum cryptography by the end of 2026. At the same time, the protection of critical infrastructures is to be migrated to post-quantum cryptography as quickly as possible, but no later than the end of 2030. We asked Stefan-Lukas Gazdag, IT security researcher and PQC expert at genua, how this requirement can be implemented by affected organizations. EU roadmap: All member states are encouraged to begin the transition to post-quantum cryptography by the end of 2026. At the same time, the protection of critical infrastructures should be transitioned to PQC as soon as possible, but no later than the end of 2030. In June 2025, the EU Commission published a press release outlining a concrete roadmap for the transition to post-quantum cryptography. Is there a specific reason for this, such as new findings about an increasing real threat to encryption methods posed by productive quantum computers? Stefan-Lukas Gazdag: The current state of development is sometimes difficult to determine, as many reports from manufacturers and early adopters contain a lot of marketing. The German Federal Office for Information Security (BSI) regularly publishes and updates an excellent study on the state of development of quantum computers . At the end of 2023, the authors stated that a realistic estimate for the construction of a cryptanalytically relevant quantum computer would be approximately 20 years. By the beginning of 2025, this time horizon had already been reduced to a maximum of 16 years, as many insights were gained within that one year faster than even experts had expected. Since further acceleration and disruption cannot be ruled out, the BSI and other authorities assume that risk management must anticipate a significant probability that the first attacks using quantum computers could become possible in the early to mid-2030s. Some guidelines and recommendations therefore advise protection against so-called "store now, decrypt later" attacks – i.e., an attacker who collects data and later breaks it using a quantum computer – by 2030 at the latest. However, Internet traffic can already be intercepted and stored today, so the sooner the better. genua has been working on post-quantum cryptography (PQC) for years as part of research collaborations, building up relevant expertise, and achieving success. What is the current status of research and development? Stefan-Lukas Gazdag: genua has been working on this topic for about 15 years. Our first publicly funded research project, squareUP , began in 2014 with a single researcher. Further projects followed. Currently, a team of experts is working exclusively on PQC, collaborating with a variety of academic institutions, industry partners, and government agencies. This currently includes three funded research projects focusing on post-quantum migration ( AmiQuaSy ), quantum-resistant solutions for safety-critical digital infrastructure ( QUDIS ), and issues related to confidential computing ( SUSTAINET guarDian ), as well as various contract projects. Our findings continuously flow into our product development. Back in 2017, we received approval for quantum-resistant software updates for our VPN appliance genuscreen using the algorithm XMSS , which we also contributed to. Since the major rollout in 2018, other appliances have followed. Last year, we received approval for a post-quantum VPN with quantum-resistant key exchange . By actively advancing the topic, coordinating with the relevant authorities, and developing initial migration steps, we are one of the leading providers for post-quantum migration. With our post-quantum VPN, you can already take the first step toward security against the aforementioned "store now, decrypt later" approach. Further migration steps for our products are already planned, while we are researching solutions for the future. Stefan-Lukas Gazdag , IT Security Researcher and PQC Expert, genua GmbH How should organizations that need to convert their VPN infrastructures act now? What should be considered when public authorities and companies process classified information in the course of public procurement? Stefan-Lukas Gazdag: The most important first step seems banal, but unfortunately, it is far from trivial: creating a crypto inventory. For a post-quantum migration in general, an organization needs to know where and in which products and applications cryptographic methods are used. Traditional inventory lists can be just as helpful, as can system administrators' knowledge of the specific structure of corporate networks or an analysis of network traffic. However, the ultimate documentation and prioritization of all systems and applications can quickly become complex. Organizations can also find out what the migration of their systems might look like. This means contacting vendors and learning about their strategy and plans for post-quantum migration, which hopefully go beyond "we'll be able to update this somehow at some point." It's also important to find out, for example, whether certain open source solutions can be updated in a timely manner. With all this information, a migration plan tailored to the organization can be created. Of course, it's especially important for government agencies to stay informed about the progress of approved and certified products, as well as the regularly updated BSI specifications. For example, it was important to us to incorporate a quantum-resistant update mechanism into our appliances as early as possible. This means that even in the case of a quantum attack, software updates can be securely installed at any time. With our post-quantum VPN, you can take the first step toward protection against the aforementioned "store now, decrypt later" approach. Further migration steps for our products are already planned, while we are working on solutions for the day after tomorrow in research. For many areas of our product portfolio, we have already ensured that products being rolled out today are fit for future threats and requirements. VPN infrastructures in particular benefit from the fact that our VPN solutions not only already incorporate the first post-quantum mechanisms, but also that they can be used to protect vulnerable communication applications that cannot or are difficult to secure with quantum-resistant security. How can organizations obtain further information? Stefan-Lukas Gazdag: In addition to the recommendations of the European Commission , various guidance documents exist. The BSI, in particular, provides information on the topic through various publications and regularly updates specifications and recommendations, such as TR-02102-1 on cryptographic procedures. Other useful guides are also available, such as the " PQC Migration Handbook ." And we as a manufacturer are also available at any time to advise organizations on an upcoming post-quantum migration and to implement it successfully. Stefan-Lukas Gazdag is an IT security researcher and PQC expert in the Research and Innovation department of genua GmbH. He has been working on future-proof infrastructures and applied cryptography since 2013. His goal is to transform academic research into secure and practical applications and implementations. He holds a Master in Computer Science. More Information Event: European Conference on PQC Migration Press Release: Firewall & VPN Appliance genuscreen 8.4 Provides Protection Today Against The Cyber Attacks of Tomorrow Research of the Bundesdruckerei Group: Technologies for the Era of Quantum Computers Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Research VPN Encryption Share Article Related Links Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks VPN Software Client genuconnect Secure connection of Windows devices to internal networks up to classification level German VS-NfD Back to Overview

"Thinking 'Who's Going to Bother Attacking Us?' Isn't Good Enough"

Interviews 27.10.2023 IT Security Trends "Thinking 'Who's Going to Bother Attacking Us?' Isn't Good Enough" For the November issue of the Industrial Communication Journal , Editor Bastian Fitz spoke to genua Managing Director Matthias Ochs about current technology trends in cyber security and geopolitical threats in 2024. You can read the whole interview here. Matthias Ochs: "People often focus on the possible technological developments, but big threats can also come from geopolitical developments. Just think about how the Western world's relationship with China has changed." In your opinion, how big is the threat of geopolitically motivated cyber attacks in the coming year? What precautions should companies take? Matthias Ochs: All analyses and findings show a clear trend: The number and severity of cyber attacks is constantly growing. For companies it is ultimately of secondary importance whether the attacks are politically motivated or committed for the purpose of extortion. It is also important to recognize that thinking "who's going to bother attacking us?" isn't good enough. Attacks are often automated. So companies can quickly be affected as collateral damage. As of May 1, the German IT Security Act 2.0 makes it obligatory for operators of critical infrastructure to implement extended security measures, especially regarding attack detection. What solutions do you offer in this regard? Mattias Ochs: With cognitix Threat Defender, we offer a particularly advanced solution for this. It enables our customers to meet the applicable attack detection requirements and also perform important analyses of their network more or less live. Also, irrespective of the legal requirements, I consider having this kind of analysis capability in your own network to be an essential part of cyber security. 2023 is set to be a defining year for the metaverse trend. What is your perspective on this in terms of IT security? Matthias Ochs: From my perspective, the IT security challenges of a metaverse are not fundamentally different than those of social networks or familiar services such as online shopping. The security of your own identity is the top priority, closely followed by critically checking which content and information about yourself you should reasonably be making available to all users online. In terms of identity, you at least make it more difficult for attackers if you use secure passwords and two-factor authentication. In relation to this, the German Federal Office for Information Security (BSI) provides citizens and companies with important recommendations and explanations that people should consider. The convergence of IT and OT has been one of the key topics of the last years in the industry. Which developments do you expect in this field in the next year? Matthias Ochs: I think the trend of IT and OT progressively converging will continue. The digitization in the industry is enabling new competitive advantages and will become more and more of a distinguishing feature. New technologies such as the currently massive progress in artificial intelligence will accelerate this trend. For security, this essentially means that in the same way in which we deal with IT developments, we must master the ever more complex networks and framework conditions in OT. This also means that those responsible for security in the industry must raise their processes, methods and tools in OT to a corresponding level. Our customers benefit from our extensive experience in the IT world, where we have been dealing with security topics for decades already. In your opinion, how big is the threat of a democratization of cyber criminality, for example through business models such as "ransomware as a service"? Matthias Ochs: Since there are still states where such criminal business models are not combatted effectively or are even interwoven with state actors, I predict that we will continue to see attacks become more frequent and more professional. Like everyone else, attackers use the latest technologies, such as AI, to further improve their chances of success. Companies must counteract these developments by continuing to invest in cyber security. Another important aspect is close collaboration with public authorities, especially the police. In your opinion, how necessary is green security given the rising energy prices and raw material shortage? Matthias Ochs: Sustainability will become more important for all products. Naturally, that applies to IT and IT security as well. Trends such as the virtualization of security components and the use of modern CPU platforms can drive progress in this area. Here too, companies must be prepared to invest to get rid of old, less energy-efficient systems. In the coming year, mobile edge computing via 5G is to become a bigger part of productive operations. In your opinion, which security concepts are necessary here? Matthias Ochs: To ensure that networks are used securely, it is first necessary to create a trustworthy network infrastructure. Above all, this can be achieved using products from trustworthy, certified manufacturers. This premise is also fully applicable to mobile networks. Furthermore, all proven security concepts can be used in principle. Zero trust is particularly well suited for enabling infrastructure to be largely independent. However, integration into an overall architecture is crucial. Looking to the future, which security topics do you think will be relevant in the short to medium term? And for which of these threats can companies prepare now? Matthias Ochs: Artificial intelligence will lead to considerable changes in cyber security. This technology holds new challenges and opportunities for both attackers and defenders. For many years already, our research department has been addressing the use of artificial intelligence in cyber security. For example, we are working on intelligent firewalls and network solutions that enable administrators to understand and control data traffic despite networks being highly complex and dynamic. Quantum computers call into question many cryptographic techniques and thus the confidentiality and security of all digital data. In this regard, it is necessary to take action today by implementing solutions involving new crypto algorithms that provide sufficient protection against quantum computers. We have also been working on this topic for over ten years, together with the global research community. The findings are already being implemented the development of our products. People often focus on the possible technological developments, but big threats can also come from geopolitical developments. Just think about how the Western world's relationship with China has changed. This interview originally appeared in: Industrial Communication Journal 4 (TeDo Verlag) dated Oktober 16, 2023. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Threat Detection Industry 4.0 Cyber Resilience Share Article Related Links IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

Terms of use

Terms of Use This user agreement ("Agreement") regulates the use of the online platforms of genua GmbH ("Portals") by customers/partners/members/subscribers ("Users"). By accessing the platform and using its functions, the Users declare their consent to being bound to the terms of this Agreement. 1. Access to the Platform Use of this platform shall be enabled by genua GmbH and intended only for the acquisition of information and material as well as for contacting employees of genua GmbH. The platform may be accessed only for purposes in the context of deployment of genua products (Customer Portal) or cooperation within the framework of a sales partnership (Partner Portal). Use of the platforms shall require registration of the User and approval of the User. The user account is not transferable. genua GmbH shall reserve the right to verify the identity of the User. To register on the platform, Users must enter their business contact data. All data requested during registration must be entered completely and correctly. genua GmbH shall reserve the right to check the registration data and to refuse or restrict access rights without stating reasons. Use of our online services shall be permitted only if the User uses a business, person-related email address which clearly indicates the company for which they work. The User shall be responsible for keeping their access data confidential. Disclosure to third parties is not permitted. 2. Use of the Platform Use of the platform shall be exclusively reserved for business partners of genua GmbH. Use of the platform by private users is not permitted. Use of the platform is free of charge. Use of the platform requires one-off registration and approval of the User; there is no right to approval; genua GmbH is entitled to refuse approval without stating reasons. Provided that there is no objection to the registration, genua GmbH notifies the User by e-mail. This e-mail shall be deemed as acceptance of the User's request for approval to use the platform. From this point onward, the User shall be authorized to use the platform in accordance with the specifications given in these Terms of Use. 3. Rights and Obligations of the Users The User shall ensure that the applicable statutory provisions are observed. In particular, it is prohibited to disseminate illegal or immoral contents, or to send or disseminate harassing, defamatory or threatening contents. The User may not at any time do anything that could jeopardize or threaten the security of the platform. In particular, it is prohibited to penetrate the data network or attempt to do this (hacking), to send unsolicited mass e-mails (spamming), to use equipment or run applications that lead to or can lead to disruption/changes to the physical or logical structure of the servers or networks. The User shall keep their login data and, where applicable, security features confidential and safeguard them against access by third parties. The User shall be responsible for all activities performed via their user account, even if the activities concerned were not authorized or intended by the User. The User shall be liable for damage resulting from their own use of their user account or from use of their user account by third parties. For access to the Portal, the User must keep the operating system and browser of the terminal equipment up to date and take precautions to protect against malware. If the contact data of the User, especially e-mail, is changed, the User shall undertake to inform genua GmbH of this. 4. Intellectual Property All contents, material and resources that are available on the platform, including texts, graphics, videos and software, are protected by copyright and remain the property of genua GmbH or the respective copyright holders. Users may download, copy, distribute or otherwise use contents of the platform only for the purpose of the business relationship within the framework of existing (where applicable: support) contracts, or where applicable legislation permits this. The unauthorized use of protected contents can result in civil and criminal penalties. genua GmbH and/or third parties authorized by it and/or third parties who have suffered damage are, in the case of infringements as well as the assertion of claims for damages, also entitled to judicial enforcement and restitution of the legal status. 5. Data Protection and Security genua GmbH shall undertake to protect the privacy and security of the user data in accordance with the applicable data protection legislation and in accordance with the applicable general data protection regulation. Detailed information can be found in the respective Privacy Policy . 6. Exclusion of Liability The contents on the platform are compiled with utmost diligence. However, genua GmbH as publisher shall not accept liability for the correctness, completeness and up-to-dateness of the contents provided. Liability of genua GmbH – irrespective of the legal grounds – shall be given only if the damage is attributable to culpable violation of an essential obligation or to gross negligence or intent, or in the case of injury to life and limb. genua GmbH shall not be liable for ordinary negligence, unless it is the simple negligent violation of essential contractual obligations. In this case, genua GmbH shall be liable only for foreseeable damage typical of the contract concerned. Essential contractual obligations are those obligations, the fulfillment of which is necessary for the execution of this contract and upon fulfillment of which the customer may normally rely. Unavailability of the platform or data losses cannot be attributed to genua GmbH. In no event shall the company or a third party that is involved in the development, creation or distribution of the platform, be liable for damage of any kind resulting from the use or inability to use the platform, including – but not limited to – errors, omissions, interruptions, the deletion of files, errors, defects, viruses, delays in operation or transmission or any failure of performance, irrespective of whether these were caused by force majeure, transmission errors, theft, destruction or unauthorized access to the platform/website. 7. Amendment and Termination The user agreement shall be valid for an indefinite period of time. genua GmbH shall reserve the right to check use of the services at regular intervals and, in the case of non-use or unauthorized use, to withdraw or restrict the access rights. Amendments to the Terms of Use are possible at any time and become legally effective on the day after initial publication. Users shall undertake to inform themselves of significant amendments by calling up or using the updated user agreement. genua GmbH can suspend or terminate use of the platform by a User at any time for good cause, particularly in the case of violation of this agreement. The User can at any time inform us in writing that they no longer want to use the services. When termination takes effect, genua GmbH shall block the login data of the User and delete the user account including all data and documents, etc. stored there. 8. Other Should individual provisions of these Terms of Use be invalid, this shall not affect the validity of the remaining provisions. The regulation that comes closest to the intended purpose shall apply in place of the invalid provision. These Terms of Use shall be subject exclusively to German law. The place of jurisdiction for all disputes arising from these Terms of Use shall be Munich (Germany). Contact data of genua GmbH: E-Mail: info@genua.de 9. Export Control During use of the Portals, software and/or technology is also provided electronically which may be subject to export control restrictions and prohibitions. The User acknowledges that the transfer of software and/or technology to other member states of the EU and the export of goods to third countries outside of the EU customs area may be subject to approval. Access to the software and/or technology from a country outside of the EU customs area is not permitted without the explicit consent of genua GmbH. The User shall undertake to ensure this. genua GmbH and the User shall agree that compliance with the applicable national and/or international export control and/or sanctions legislation (referred to below as "applicable export control legislation") is an essential prerequisite for use of the Portals. genua GmbH and the User shall therefore undertake to comply with and not to circumvent the applicable export control legislation. The Portals may be used only if there is no applicable export control legislation to the contrary. The User shall undertake to ensure that no natural nor legal persons, organizations or institutions (referred to below as "involved party") that are listed in the sanctions lists of the European Union and/or of the USA or any other sanctions list are involved either directly or indirectly in the use of the Portals. Should the User or an involved party be added to one of the above-mentioned sanctions lists during the period of use, the User shall undertake to notify genua GmbH of this immediately. As at: October 2025

Produktvarianten genuline | genua GmbH

Highlights High-Speed VPN Appliance genuline Hardware variants Information material Request Hardware Variants for the VPN Appliance genuline Compare hardware Reset < > Model genuline genuline Hardware ▴ ▾ Revision 4.0 CPU Intel Xeon E-2386G (6 Cores, 3.5 - 5.1 GHz) Memory 32 GB ECC Network interfaces default 4 x 1 Gbit/s RJ45, 2 x 100 Gbit/s QSFP28 Optional network cards - Available network cards - Flash Drive 1 x 500 GB SSD DVD-ROM Drive - Graphics Connector 1 x VGA Serial Ports 2 x RS-232 USB Port 2 x USB 2.0 Type-A (1 needed for smartcard reader), 2 x USB 5Gbit/s Type-A Smartcard Slot Format ID-000 Performance ▴ ▾ IPSec UDP 198.58 Gbit/s 1 [1] Chassis ▴ ▾ Power Supply 2 x 800 W Power consumption load 435 W BTU/h load 1485 Fixture 19" rackmount Width 430 mm (19") Height 44 mm (1 U) Depth 399 mm Weight 8.1 kg Weight (incl. Packaging) 10.0 kg Environment Operation ▴ ▾ Voltage 100 - 240 V AC, 60 - 50 Hz, 5.5 A, connector 2 x IEC-C14 Temperature 10 - 35 ℃ Humidity 8 - 90 % non condensing Shock 20 G: 2 ms Vibration 5 - 200 Hz: 0.25 G Norms CE Environment Storage ▴ ▾ Temperature -40 - 60 ℃ Humidity 5 - 95 % non condensing Shock 10 - 20 G: 10 ms Vibration 5 - 200 Hz: 0.5 G All information in this data sheet is provided for product description purposes only, does not constitute a guarantee, and is not intended to be exhaustive. Technical changes are reserved. Actual performance may vary depending on the operating environment and configuration. Reproduction and/or duplication – including in part and/or in modified form – is permitted only with the written consent of genua.

Quantum-safe cryptography - why and how?

Insights 30.05.2023 Post-Quantum Cryptography Watch Out, Crypto Hackers: The Gradual Progression to Quantum-Safe Cryptography With the quantum age fast approaching, the cryptographic encryption techniques used must meet higher and higher requirements. We must counter this threat today to ensure the integrity of online data in the future. The good news: The first quantum-safe solutions are in sight. Cryptography is a crucial foundation for IT security. To protect confidential communications, financial transactions and critical infrastructure even in the coming quantum age, quantum-safe encryption is needed as soon as possible. After all, quantum computers already pose a threat to the current encryption algorithms – and not only because massive amounts of sensitive data are already being stored so that they can be decrypted in the future using suitable tools. What is Quantum-Safe Encryption? A theoretically fully secure encryption is only possible using quantum cryptography, i.e. based on physical principles. However, in practice, implementing this kind of encryption is not yet possible because it would require specialized equipment that is not (yet) viable and will be rather expensive in the future. Moreover, quantum cryptography is suitable only for particular applications. Therefore, researchers are developing brand-new algorithms that can withstand attacks by quantum computers and be implemented on classic hardware – this is post-quantum cryptography. However, certain things need to be done before these algorithms can be used in protocols and IT solutions. RSA, AES, and More: Cryptographic Techniques and Keys We visit websites, shop and carry out banking activities online or work from home via a VPN connection to the work network. This is all made possible by encryption and signature methods operating in the background – they verify the authenticity of the sender and ensure that the data cannot be read, or even tampered with, as it is transmitted between the sender and the recipient. A cryptographic key can be used to turn plain text into an encrypted message for this purpose. Based on the type of key distribution, a distinction is made between symmetric and asymmetric techniques. In practice, the two techniques are often combined – usually, the key is exchanged via an asymmetric technique and the plain text is then encrypted via a symmetric technique. Asymmetric techniques include the common RSA algorithm (named after the developers: Rivest, Shamir and Adleman), which is used to secure online orders and debit card payments, among other things, and is based on the factorization of prime numbers. Another technique is the Diffie-Hellman key exchange, which is based on discrete logarithms. Both techniques involve trapdoor functions. These functions are easy to compute but time-consuming to invert. The Advanced Encryption Standard (AES) is a symmetric encryption technique and offers a high degree of security due to its long key length of 128, 192 or 256 bits. For this reason, AES-192 and AES-256 are approved for US state documents with the highest level of confidentiality. Quantum Computers: The New Crypto Hackers Stefan-Lukas Gazdag, crypto researcher What happens now if powerful quantum computers are used as code breakers? Grover's quantum algorithm is a search algorithm that can be used to search an unstructured database for one or more elements that meet a specific criterion. It speeds up the key search significantly and initially weakens symmetric techniques. Using correspondingly long keys neutralizes the threat for the time being. The situation is different with asymmetric techniques. Quantum mechanical effects – such as superposition and entanglement – enable parallelism, thereby speeding up some calculations. Shor's algorithm can be run on a quantum computer to perform the prime factorization in comparatively little time – and other asymmetric techniques (such as Diffie-Hellman) would also be broken quickly. Stored Today, Decrypted Tomorrow? But quantum computing is still at a developmental stage, so why worry about it now? There are several good reasons. With technology giants such as IBM, Amazon and Google investing heavily in work on quantum computers, it is only a matter of time until the latter find their way out of the research labs and into applications – experts predict that this will happen in the early 2030s. However, sensitive data is already in danger: Intelligence services worldwide are storing encrypted confidential data with the intention of using quantum computers to decrypt it at some point in the future. Governmental and military communications may be targeted at first, but as the technology becomes more advanced, many more targets will be affected. Therefore, appropriate preparations must be made today to ensure that sensitive data remains protected in the future. The good news: There are already viable options for gradually making the cryptographic infrastructure quantum safe. It is unclear when quantum computers will be available. Today's quantum computers have the character of laboratory experiments and do not yet play a role in practice. But what has already been achieved today was questioned just a few years ago. Accordingly, it seems realistic that a sufficiently large quantum computer relevant to cryptography could be created within the next ten years. The responsible authorities, such as the German BSI, are therefore using the working hypothesis that everything must be secured in a quantum-resistant manner by the early 2030s at the latest. Stefan-Lukas Gazdag , Kryptoforscher Post-Quantum Cryptography: Balancing Security and Efficiency Post-quantum cryptography (PQC) is based on mathematical problems that are theoretically impossible to solve in a reasonable amount of time even with quantum computers. A variety of approaches are being taken. For example, the techniques may rely on one of the following: The difficulty of efficiently deciphering general error correcting codes The difficulty of specific problems in mathematical grids The security features of the hash functions used Hash functions are considered sophisticated quantum-computer-resistant signature schemes. The signature scheme XMSS was developed during the research project squareUP . Since 2018, it has officially been the permissible Internet standard (cf. RFC 8391 ) and even authorities consider it fit for use (cf. PDF: BSI TR-02102-1 ). XMSS uses hash functions that create a type of verifiable digital fingerprint from the file or message to be sent – but it is only suitable for digital signatures. Code-based, grid-based and other techniques can be used for encryption but are not always good for signatures. So there will not be a single solution to all cryptography problems. These techniques also pose the following additional challenges: Key lengths are significantly longer than with classic techniques, therefore requiring more storage space In some cases, encryption and decryption would require a lot of computing power , which would massively decrease the efficiency of many current applications. Quantum Resistant Key Exchange Techniques Stefan-Lukas Gazdag (together with research partner Richard Zink, System Security Architect at Adva Network Security GmbH) The first step toward quantum-safe cryptography was the abovementioned hash-based signatures for software updates. These signatures are particularly relevant because they verify the authenticity of the sender or manufacturer while also ensuring that an update cannot be tampered with from outside the system. Quantum-resistant key exchange techniques are far more complex. One example application is secure communication via Virtual Private Networks (VPNs). VPNs were researched as part of the project QuaSiModO – Quantum-Safe VPN Modules and Operation Modes – which was funded by the German Federal Ministry of Education and Research (BMBF) and carried out in consultation with the BSI. Many VPN protocols differentiate between the actual communication channel, which is typically secured using symmetric techniques, and (other) key exchange or key agreement protocols. Particularly in the latter case, it depends on the currently used cryptographic techniques. The key exchange protocol used most frequently in the context of IPsec is Internet Key Exchange version 2 (IKEv2), which is based on a Diffie-Hellman key exchange. This protocol must be replaced with or supplemented by quantum-resistant techniques. Problems such as the limitation of the overall key size and other special features resulting from the fragmentation require the sophisticated integration and handling of new techniques. Therefore, the QuaSiModO research project tested initial drafts of Internet standards in practice and evaluated different cryptographic techniques from the NIST competition as a quantum-safe expansion of IKEv2. Specifically, the aim was to identify practical trustworthy and secure algorithms that can be used to operate quantum-safe VPNs in the near future. The common IPsec and MACsec key exchange and key agreement protocols, Internet Key Exchange Version 2 (IKEv2) and MKA/PACE, should be made quantum-safe for this purpose, including by using hybrid, cryptoagile, and multilayer encryption techniques. In addition, the first attempts at post-quantum authentication have been undertaken. genua's main research had been on IPsec protocols. The first pre-quantum solutions are already available on the market: For example, the update mechanism of the Firewall & VPN-Appliance genuscreen as both a digital signature and a quantum-resistant signature. Thus, increasingly effective quantum-resistant solutions are to be developed gradually in consultation with the BSI and the NIST, or rather the protocols are to be adapted based on the new standards. However, when fully quantum-resistant products will be available on the market also depends on the standardization process. Illustration of quantum-safe communication through IPsec and MACsec (QuaSiModO demonstrator). Two sites are connected via layer 2 (VLAN) and layer 3 (IP tunnel). The VLAN is secured by SecTAG. The IP tunnel, on the other hand, is secured by IPsec / ESP and additionally encapsulated in SecTag. The connection is established with IKEv2 for ESP and MKA / PACE for SecTAG. The New World of the Quantum-Safe Future – Complex but Agile What awaits us in the quantum-safe (IT) world? Will we be safe from attacks and security apocalypses? Unfortunately not, as there will always be dangerous attacks and crypto bugs. But with post-quantum cryptography, the incidents will not be so serious. The probability of fatal errors is low, since communication will be protected by techniques operated in parallel. In addition, agility will be greater: If the protocols are not designed too specifically for one technique, a system administrator can immediately switch to a different protocol with sufficient security if needed, until the defective protocol has been repaired. However, a lot of research is needed before the quantum-safe (IT) future arrives. With the quantum-resistant key exchange for IPsec and MACsec, the implementation of quantum-resistant solutions on Layer 2 and Layer 3 of the TCP/IP reference model and the development and testing of VPN-suitable hybrid and cryptoagile mechanisms, we have achieved all the goals of our QuaSiModO research project. Stefan-Lukas Gazdag , Kryptoforscher In addition to genua as project coordinator, the QuaSiModO research project, which ran from 2019 to the start of 2023 and was funded by the German Federal Ministry of Education and Research (BMBF), involved the following project partners: ADVA Optical Networking SE, the Fraunhofer Institute for Applied and Integrated Security (AISEC) and the Ludwig Maximilian University of Munich (LMU). The German Federal Office for Information Security (BSI) and the Hessen CyberCompetenceCenter (Hessen3C) were also associated partners. Sources and related links [1] squareUp research project [2] J. Buchmann, E. Dahmen, and A. Hülsing: XMSS – A Practical Forward Secure Signature Scheme based on Minimal Security Assumptions [3] BSI-Technische Richtlinie: Kryptographische Verfahren: Empfehlungen und Schlüssellängen (BSI Technical Guideline: Cryptographic Mechanisms: Recommendations and Key Lengths, German only) [4] NIST: Post-Quantum Cryptography Standardization ( https://csrc.nist.gov/Projects/post-quantum-cryptography/Post-Quantum-Cryptography-Standardization ) [5] Migration zu Post-Quanten-Kryptografie“ des Bundesamts für Sicherheit in der Informationstechnik (BSI), Handlungsempfehlung des BSI, Stand 2020 (German Federal Office for Information Security (BSI): Migration to Post Quantum Cryptography: Recommendations for action by the BSI, dated 2020, German only) [6] QuaSiModO research project [7] Firewall & VPN-Appliance genuscreen technical data Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption VPN Share Article Related Links Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks Back to Overview

Remote Access and OT Security in the Process Industry

Case Study 28.02.2025 Remote Access and OT Security Bayer – Secure Remote Access from a Single Source A mammoth project in the field of security: The life science company Bayer has standardized remote access to its many different plants and locations worldwide. With help from genua, an experienced cyber security partner, Bayer has been able to introduce important functionalities for its regulated production lines. The Solution: The introduction of genubox as a remote maintenance solution in combination with the genua logging system as well as secure file transfer as part of a comprehensive and tailored genubox security solution.(Copyright Bayer) The damage caused to the German economy by cyber attacks skyrocketed again in 2024 – by approximately 29 percent, reaching 266.6 billion euro. For comparison, that is significantly more than half the German national budget. In the meantime, almost every company in Germany has been affected. While theft of customer data or intellectual property, such as patents and research findings, can become very expensive, the digital sabotage of industrial plants or operating procedures has the potential to compromise the plants‘ integrity and thus put people‘s lives at risk. This level of potential damage is particularly relevant to the process industry. Challenge for the Process Industry: A Remote Access and OT Security Manufacturers of chemicals, pharmaceuticals and food are no longer only ensuring the functional safety of their plants – now, they must also protect the integrity of their networks. Commissioning equipment without being on site, performing diagnoses remotely and carrying out monitoring functions from home have gradually become standard for suppliers and service providers. This is because quick external access increases plant availability – but it also leads to a whole host of different access methods and security concepts. The applications employed to enable the use of appropriate, cost-effective devices and methods from the IT world in process plants have become an almost impenetrable jungle, especially at large locations. For an industry that demands the highest standards when it comes to the integrity and security of plants, this is a growing problem. The Search for a Standardized Solution An excellent example of how complexity can be reduced while also maximizing security for plant operation is the company Bayer. “The then CISO had the idea of drawing up an OT security program. The aim was for this to create transparency within the overall company regarding how the individual Bayer sites address this topic,” says Jani Alexander Krämer, Information Technology Security Analyst at Bayer. The combination of being hugely beneficial to the company while also posing a high risk of damage made remote access top priority. Therefore, the most important objective of the OT security program implemented at the time was initially to come up with a standardized technical solution for remote access to machines and plants at the different Bayer locations. At the start of a standardization project, there are thousands of reasons why things don’t work. With genua’s support, we always ultimately found solutions that all parties were satisfied with. Jani Alexander Krämer , Information Technology Security Analyst at Bayer The right partner for the job was soon found in IT/ OT security experts genua from Kirchheim near Munich. The company, which has since become part of the Bundesdruckerei Group, protects plants and communication processes in networked and automated production systems. The experts design a secure IT/OT infrastructure, work with the users to select the appropriate security products for ensuring network security, and implement these. If necessary, the on-site team also receives training and support. A Fixed Appointment Is Mandatory The rendezvous solution from genua prevents onesided access by the external remote maintenance service. Connections to the plant for analysis or maintenance must take place via a rendezvous server located in a noncritical “demilitarized zone” (DMZ) or with a virtual location in a cloud. The external maintenance service and the person responsible at the operating company each establish a connection to this meeting point at a fixed time. This active step carried out by the user creates the continuous connection required for the flow of information for maintenance purposes. This enables machine values and error messages to be read out and dealt with. Meanwhile, the access remains restricted to a specific time period and area. The external service can only move within the predefined target system and in the predefined role. genua implements this using an application-specific SSH rather than VPN access that covers the whole network. Almost 100 genuboxes have been installed for Bayer in Germany alone. To start with, it was mostly rack hardware or on-premises technology, but now, virtualized service boxes are increasingly being installed in the cloud – in roughly a quarter of all Bayer‘s applications. “When I arrived at Bayer, the genua solution had already been tested in the laboratory and rolled out to 70 locations worldwide. The big challenge we‘ve since overcome internally at Bayer was to create a service out of the technology and turn that into a successful roll-out project – not an easy task in a large company,” Krämer remembers. Almost 100 have been installed for Bayer in Germany alone. To start with, hardware versions of genubox were used in most cases. Since then, the company has increasingly opted for virtualized service boxes in the cloud. The background to this is that many Bayer companies and important suppliers were already using their own security solutions. In cases where the technical implementation of the remote access focused on functionality more than security, people were very willing to switch to the new system. “In many cases, however, it took some work to convince them to accept genua as the mandatory standard solution in the company. Especially where suppliers with their own good solutions were forced to change to genua,” says Krämer. One topic where assessments differed was the audit trail. “Many companies work in a GXP or GMP environment. In such cases, we have to meet high requirements regarding documentation. We must be able to prove, without a single omission, who was on which system when, and what changes were made,” adds Carsten Rocks, Global Program Lead “Manufacturing IT Security“. In Bayer‘s CISO organization, he develops special security controls for the OT world. In contrast, the access solutions of mechanical engineers, for example, worked with a pooled back office of third-party companies. As a result, in some cases, it was not possible to tell which operator was behind an account – an unacceptable situation from an auditing perspective. Access Always Registered and Recorded Krämer, who performs a kind of service manager role at Bayer, worked with service provider Atos to implement and deploy the necessary programs, adaptations and employee training worldwide. “genua were and continue to be on hand to help with their technical expertise. Their technical support steps in as level three if there are problems with the service that the provider cannot solve,” explains Krämer, who handles coordination and any classic issues that are escalated. Now, the genua logging system used at Bayer ensures that users can track all connections – meaning it is always transparent who has logged in, when, what work was carried out and who oversaw it. The recording function that has also been integrated was even developed at the express request of Bayer‘s then management team. For genua, it has become a unique selling point to record not only logs but also the actual maintenance process in detail. Once the work is complete, the session recording can be archived similarly to a video. Secure Updates Performed Externally An additional implementation that has also been carried out recently in close collaboration with the Bayer team concerns the secure file transfer part. Receiving files from outside the organization is one of the requirements that make heads of security break out in a cold sweat. Yet updating or repairing firmware, for example, is precisely what can get a reactor control system or a packaging machine going again in no time at all. In an independent project, this requirement was addressed and scanning for malicious software established. It is now possible to connect an ICAP server that is part of the genubox security solution and checks data connections and files for malicious software before they enter the network. “It is a fantastic expansion that we planned with genua based on the locations‘ feedback and then implemented with the help of our provider,” says Rocks, delightedly. The implementation of features such as this, which have been requested by end users, is another reason for the high level of acceptance at Bayer: “We regularly receive positive feedback from our users. The productive nature of the collaboration is also clear from the fact that the solution is no longer used only for remote maintenance but now also for internal administration. In addition, we often receive constructive suggestions as to how the service can be expanded further and which additional features would be helpful,” says Krämer. Seamless Integration “The main benefit of a remote maintenance solution is the cost saving due to on-site visits by suppliers now rarely being necessary. This saves time and money and helps us to respond quickly – which is particularly valuable in the event of a malfunction, because there‘s no need for someone to be on site,” says Krämer. “In relation to this, I‘d add the increased flexibility. At some locations, employees also intensively use the solution for access when they‘re working from home, for example,” says Rocks. The genua solution gives every Bayer location the choice as to whether the access is, for example, arranged via time-controlled remote maintenance, or whether the security approval is only granted from within the company. It depends on factors such as the division and whether a production line is subject to GMP or GXP rules, how the network has been segmented and whether special IT solutions are in use. Existing systems can also be used. Connecting to a cloud identity provider such as Okta or Azure Active Directory enables the full integration of genua remote maintenance into a central user management system with commonly used multi-factor authentication. Companies benefit from scalable client, role and rights concepts and users can authenticate themselves via their usual method. The genua solution has been very well received by Bayer users and provides a lot of added value. Jani Alexander Krämer , Information Technology Security Analyst at Bayer Development Continues To closely link the security of the company‘s own plants to crucial success factors such as availability and flexibility, other functions are already being planned: “We are placing a lot of hope in web-based remote maintenance. In fact, the heads of various locations have written to me directly to register their interest after hearing about it,” says Krämer. The work required to implement it should be relati- vely minimal, as only one additional web server will need to be installed in the demilitarized zone. This server will have its own security requirements and need its own security review, but “genua is definitely taking a step in the right direction with this, because the biggest problem for external companies is not letting any third-party executables run on their company computers. In contrast, a browser-based solution can be used in all companies without having to fulfill lots of preconditions,” explains Rocks. A test setup for web-based remote maintenance is currently in progress and the solution is being put through its paces to ensure that it works as planned. “I think it will be the biggest new feature to be hopefully rolled out this year,” says Krämer. It will be one more thing in the toolbox of the people working intensively to protect the plants and thus ensure that the rapid rise in damage events is curbed effectively in the future. Author: Frank Jablonski, mylk+honey, Würzburg Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Remote Maintenance Industry 4.0 Share Article Related Links Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Back to Overview

Security Defined Networking for Flexible and Highly Secure IT

Insights 16.03.2020 Security Defined Networking for Flexible and Highly Secure IT New challenges call for new approaches. At present, for example, digitization requires an extensive restructuring of many business processes. IT departments are expected to flexibly support this dynamic development with the necessary applications. But that’s just one side of the story. On the other side, growing cyber threats demand additional security measures. In the past, increased IT security often came at the expense of flexibility in IT operations, however. Security defined networking Experts search for answers among these conflicting priorities: How can the interests of both areas be taken into consideration? With the Security Defined Network concept, genua now presents a solution. In this interview, we ask Claas Lorenz, Technology Analyst at genua, how Security Defined Networking can be used to facilitate the balance between requirements from application operation and from the area of compliance. Today we’re discussing IT security in corporate networks. Why should we talk about “Security Defined Networking” instead of about network security as in the past? Claas Lorenz: Currently, the growth of networking, critical systems and sensitive data leads to a highly complex, difficult to comprehend IT landscape and, thus to greater risks than in the past. The methods of classic network security are thereby increasingly pushed to their limits. A new security approach is, thus, needed here. This already challenging situation is compounded by the need to find a balanced response to the different requirements that arise, on the one hand, from the business area, i.e., economic area, and, on the other hand, from the IT security. Security Defined Networking should make a significant contribution here. Can you roughly describe the different requirements from the areas of application operation and IT security? Claas Lorenz: In many companies, an imbalance exists between the budgeting of IT operation and IT security in favor of application operation. The benefits of investments and operating costs for the success of the business is simply more apparent in application operation – especially if no or little risk management is performed and only weak regulation is in place. Another area of tension arises between data availability and data confidentiality. Although access restrictions serve to promote confidentiality, they inhibit availability. In practice, the decision is often made in favor of increased availability. Numerous data scandals in recent years can be attributed to insufficient or lenient access restrictions. Another challenge: While regulation and risk management are quite stable and the requirements placed on compliance continue to develop at a moderate pace, a high dynamic exists in application operation. In addition, parts of the applications are often operated decentrally by individual departments; the IT security, on the other hand, is largely managed centrally. genua’s Claas Lorenz explains how SecDN can deliver IT that is both flexible and highly secure. Display external content from YouTube? When loading this content, data is transferred to the provider and, if applicable, to third parties. For more information, please refer to our privacy policy . Always load content from Youtube Embedding EN Load content Against this background, situations arise in which the IT security becomes a bottleneck during application operation. This then results in delays in making applications available for the business processes or in carelessness in the implementation of security measures and, thus, in a breach of compliance. What should only be temporary measures, such as network shares, become the rule and, over time, the IT security becomes a patchwork. If no explicit risk management with periodic compliance auditing takes place, successful cyberattacks are only a matter of time. What contribution does Security Defined Networking make towards finding a solution to these conflicting goals? Claas Lorenz: The described underbudgeting and relatively static nature of compliance result in long investment cycles in IT security. In practice, the dynamics in the evolution of the applications are not always incorporated. As a result, processes are implemented around the existing, centralized security infrastructure. This discrepancy can jeopardize the security of the entire company if so-called shadow IT is used, something which can be understood only with great difficulty centrally. What conclusions can we draw from this? The security infrastructure should be designed flexibly, because at the time of planning all future requirements are not yet known. Security Defined Networking satisfies this requirement: The dynamics of the application evolution and processes are anticipated and supported in the best possible way by a flexible, scalable design of the security processes and infrastructure. What does Security Defined Networking look like in practice? Claas Lorenz: Introducing flexibility on the process and infrastructure level is achieved with Security Defined Networking by clearly separating the definition and the enforcement of security rules. Thus, unlike the current, purely central approach, parts of the policy definition can be delegated. For example, departments can create security rules that are appropriate for their applications. The security infrastructure for enforcing these rules is, however, managed centrally, thereby ensuring the central, permanent transparency of the network security and keeping the complexity of the infrastructure manageable. In concrete terms, this means: the security infrastructure is divided into macro- and micro-segments. Macro-segments correspond to the classic subnetworks and are centrally implemented using packet filter technology. Unlike classic setups with Next Generation Firewalls, however, they intentionally limit themselves in terms of the extent of the policies that they can enforce. The macro-segments provide a base level of security that does not impede the availability – or the performance – of the business applications. The micro-segments, on the other hand, can be set up and enforced decentrally. The delegation of administrator rights all the way down to local responsibilities allows the configuration to be adapted to local requirements as appropriate for self-managed applications without undermining the entire security of the network. This is achieved by the macro-segments and, if necessary, other centrally specified policies in the micro-segments, but above all by global visibility of the data streams by monitoring in the micro-segments. Suspicious behavior can be detected close to the source, examined and, if necessary, contained and stopped. Let’s talk about the actual implementation in the network: What differences arise here? Claas Lorenz: One significant difference with respect to classic networks is that the micro-segmentation is performed in the access network of all end devices in the company. Instead of the typical access switch, lightweight, programmable appliances such as the cognitix Thread Defender are used that can perform the segmentation individually and automatically all the way down to the application layer. Conventional approach: Network with an administration network and a research network, a DMZ, a branch office and mobile employees. Network security is implemented centrally by means of firewall and VPN. The macro-segmentation at the perimeter, on the other hand, focuses on general connectivities between large security units. For example, it is permissible to access services in the DMZ from the internet, while attempts to access hosts in the research network should always be prevented. These policies are relatively stable over time and are easy to describe. An audit is greatly simplified by this approach. At the same time, the probability of the security solution impeding the availability of the business applications is reduced. "With Security Defined Networking, the various interests from the areas of application operation and IT security are largely balanced." Stricter policies can be implemented within the micro-segments. Here, one can decide whether to intervene in the network traffic proactively or reactively. The advantage of proactive security rules is that potentially malicious communication cannot occur in the first place. On the other hand, filtering may be too strict under certain circumstances, causing the availability of the business applications to suffer. This can be remedied by shifting towards reactive security rules that attempt to detect and subsequently prevent malicious communication. The availability of applications is thereby only restricted in the event of detected attacks. Security Defined Networking: Basic security through macro-segmentation as well as VPN connections of branch offices and mobile employees is ensured on the same network. Advanced and delegated polices are implemented in a targeted manner through micro-segmentation. Coming back to the beginning of the conversation: The process orientation of Security Defined Networking and the flexibility in the technical configuration using proactive and reactive security rules thus allow for balancing of the protective goals, of the application availability and of the necessary administration resources. The ability to delegate responsibilities enables local optimization to the needs of the respective users without having to sacrifice the central transparency. With Security Defined Networking, the various interests from the areas of application operation and IT security are largely balanced. Thank you for the conversation. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Network Security Share Article Related Links Firewalls & Gateways The basis of IT security is a defense that provides maximum protection against external attacks. Our firewalls ensure the network security and safeguard data. Back to Overview

Zero-Trust: Implement IT/OT Security in the Industry

Insights 03.03.2022 Paradigms in IT Security Zero Trust Architectures for the Industry Many industrial plants are managed by external machine manufacturers or have connections to externally managed services, for example for cloud computing. For the industry, this means an increasing loss of control. Zero Trust architectures from the IT world help operators retain network sovereignty over their OT, thereby regaining trust in their infrastructure and operational technology. genua smart security: zero-trust architectures for the industry The digitization does not stop at operational technology (OT) in industrial environments. More and more critical processes are being digitized, and sensitive data and systems are being networked. This drastically increases the complexity of infrastructures. At the same time, dependency on digital processes is increasing, resulting in increasing demands on availability and reliable function. To date, the traditional approach to managing digital infrastructure has been centrally managed networks with a uniformly high level of security. Since compromising individual parts endangered the security of the entire network, this had to be avoided at all costs, for example through strong separation from other networks. In today's networks, however, more and more systems are managed by external manufacturers and service providers or have the necessary connections to externally managed networks, for example for edge or cloud computing. This leads to an increasing loss of control over one's own network: The traditional approach does not scale with the reality of the networks and the increased requirements for availability and reliability. What Does "Zero Trust Networking" Mean? In the Zero-Trust Networking paradigm, trust in the security of the entire network is replaced by trust in the security of specific communication endpoints, i.e. devices, services, and applications. A compromise of individual endpoints is thus limited to the permitted communication relationships and no longer endangers the entire network. This approach gives the operator back control of his systems and proactively reduces the attack surface. Reactively, it also allows faster detection and limitation of damage as well as rapid and targeted recovery. The result is more robust and resilient networks, suitable for the higher criticality and the associated requirements for reliability and control. Microsegmentation: Forrester's Zero Trust Networking Forrester's Zero Trust Networking divides an existing network within itself by deploying firewalls at strategic locations into microsegments, between which communication is regulated. In the extreme case, each device in the network is in its own microsegment. This approach lends itself well to post-hardening of existing networks and works well with legacy applications. However, a dynamic mapping between identities and IP addresses may be required, since only these are reliably visible as a decision-making criterion in data traffic. Similar to this network-based microsegmentation is host-based microsegmentation, in which centrally managed agents on each device limit its communication with other devices. However, these agents typically have to invasively intervene in the system to perform their tasks and run with high privileges. This may affect the reliability of the systems and, in the worst case, create an additional target for attack. Sample Implementation for Mesh-Based Microsegmentation A reliable implementation of the network-based microsegmentation can be achieved with the cognitix Threat Defender. This integrates transparently into the network like a switch, but allows granular, dynamic and cross-context regulation of the data streams. In contrast to switches with Network Access Control (NAC) or many firewalls, the control and restriction does not only take place at the network level, but also at the application level. These capabilities are supplemented by an integrated Intrusion Detection System (IDS) and the use of Indicators of Compromise (IOC), i.e. artefacts that indicate a compromise. Their results can in turn be included in the access rules. This makes it possible, for example, to isolate potentially infected systems in real time or to restrict their communication in order to be able to detect attacks early and react appropriately in good time. Software Defined Perimeter The Zero Trust Networking concept of the Cloud Security Alliance (CSA) is a Software Defined Perimeter (SDP), which allows external clients to access an internal infrastructure after authentication. In contrast to a classic Virtual Private Network (VPN), there is no complete network coupling here, but access is limited to individual services. The CSA's original proposal defines a special tunnel protocol for encrypting and transmitting identities, which the clients must implement. This complicates the connection of legacy applications. Alternative implementations using VPN technologies simplify this since the tunnel is implemented transparently at the network level and not at the application level. Example: Software Defined Perimeter Using Remote Maintenance A solution based on the concept of the Software Defined Perimeter is the remote maintenance solution genubox from genua. A service box from the internal network connects to a rendezvous server – the software defined perimeter – that can be reached by the external remote operator. The remote maintainer, in turn, uses the remote maintenance app to establish encrypted communication with this perimeter. After successful authentication, access to specific services is enabled, such as the desktop of the machine to be maintained, the terminal (via SSH) or selected ports. There is no network coupling. In accordance with the increased requirements for security and compliance in the industrial environment, a video recording of the desktop or the SSH connection also takes place and transferred files are checked for malware. These recordings can also be called up later. Implementation of a Zero-Trust remote maintenance with genua's Rendezvous solution Google's BeyondCorp for Web-Based Applications With BeyondCorp, Google has presented an implementation of Zero Trust Networking, in which control takes place directly on the service via an upstream Identity Aware Proxy (IAP). The connection between client and IAP is encrypted via HTTPS. This approach is very well suited for web-based applications and offers high and simple scalability. However, applications that are not inherently web-based can only be integrated cumbersomely via web-based tunnels or not at all. In the industrial environment, this approach is therefore only of limited use. Conclusion In summary, it can be said that Zero Trust networking is also a suitable security paradigm in the industrial environment in order to achieve a high level of robustness and resilience in highly networked, sometimes security-critical infrastructures. The administrator regains control of his infrastructure, even if it is partly managed by someone else and connected to external networks. Zero Trust Networking thus increases trust in the availability and security of IT/OT networks, which form the basis of industrial value-added processes. The answer to the question of which Zero Trust approach should be implemented ultimately depends on the specific framework conditions and should be discussed with an IT security expert. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Industry Industry 4.0 Share Article Related Links Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

Working with Artificial Intelligence: Organizing Hybrid Security Departments

Insights 02.06.2020 IT Security: Artificial Intelligence as Digital Trainee To err is human, especially in highly complex jobs such as software programming. And not every careless mistake in a line of code immediately results in a safety-relevant problem. But: Who checks and decides that in IT security teams, which, with their limited resources, need to concentrate on other priorities? Photo: Arnold Krille, AI-Expert at genua IT decision makers can delegate this task to an AI. After all, the technology for checking a large quantity of data in a short amount of time is unbeatable here. An example from Microsoft: With a machine learning system, the company aims to identify and prioritise the approximately 30,000 errors from some 47,000 developers (see blog post from 16 April 2020). The objective: To classify errors as not relevant/relevant as well as uncritical/critical for security – with a level of accuracy that comes as close as possible to that of a security expert. Organising "Hybrid" Security Departments To achieve such a goal, not only is the data pool decisive. Also important is how the IT security experts "train" the AI with their expertise. This was also found to be an important success factor for the accuracy of the AI results in the Microsoft project. It is precisely this experience that is so exciting. After all, it represents a development that has no historical precedent or for which any methodical blueprints exist: the creation of teams consisting of those responsible for IT security and "digital trainees", i.e., technologies that perform human tasks with a more or less high level of "intelligence" and decision-making competency. This is limited not only to error classification: A specialized and well-trained AI can, for example, better identify undetected threats, such as zero-day attacks or advanced persistent threats, than humans. These and other tasks are generally the starting point for those responsible for IT security as they explore the potential of AI support. What needs to be taken into consideration when organising a "hybrid" security department that integrates human employees and artificial intelligence? From our projects, we can share the following experiences and guidelines: 1. Define a clear range of tasks! What specific support should the AI provide: Should it identify threats, be responsible for malware prevention or be used in another area of IT security? The more precise the task description, the higher the probability that the solution achieves optimum results. Products from genua that use artificial intelligence were designed and developed with an understanding of the limits of this technology. Our focus here is on the robustness against tampering and the usability of the applied processes to ensure the expected quality of the products in the future, even against highly advanced attackers. Furthermore, a clear utility value is important, such as if AI makes suggestions on the classification of network devices according to behavior or on improving the security policies. 2. Limit the risks! Errors are not only human – as a statistical approach, AI also always makes a certain amount of mistakes. Attackers will want to exploit this as well to lead AI and, thus, users, to make false decisions that undermine security. This risk can be reduced by, e.g., using multiple AIs that cooperate with one another or work in sync and verify and check each other. In the long term, there will also be fields in which AI can only play the role of the supportive technology and the last word must lie with people. This is especially the case with tasks that require a person who not only makes decisions but who is also responsible and, if necessary, can be held liable for those decisions. These and other fields of application should be clearly differentiated from one another when designing a hybrid IT security team so as to avoid unrealistic objectives. Even in the long term, there are fields in which the last word must lie with people. Arnold Krille , AI-Expert at genua 3. Take training time into account! If the AI is to make correct decisions in a matter of seconds, it must be appropriately trained. Here, a suitable data set is to be selected: Not only the "normal state" but the types of deviations that are to be detected must also be identifiable and present, as the AI learns from examples. Companies should allocate a longer period of time for this, possibly spanning several weeks. Furthermore, the AI must be regularly retrained. After all, external circumstances change over time. For the human colleagues, this is an automatic learning process during everyday life, but for the AI this must be included already in the planning and design. The time invested here pays for itself later when the AI consistently delivers good results and supports the users for the long term. Master Dynamics and Complexity The current focus of AI in hybrid security departments may still perhaps lie on detecting and automatically classifying complex information flows. But we have determined in our projects that the range of tasks is clearly continuing to develop. One clear direction of thrust is the further development of the AI role from "tool" to "supporter", as in solutions that have already been practically implemented such as cognitix Threat Defender. In this function, AI provides suggestions on the implementation and improvement of security measures to ensure the best-possible protection in a complex and dynamic environment. Whether AI will actually be accepted in the future as a "co-worker" is, of course, dependent on other factors such as a high-performance combination with technologies like voice control, avatars or interfaces. And perhaps whether not they should also happen to make a perfectly "human" – and forgivable – mistake. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Artificial Intelligence Share Article Related Links Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks Back to Overview

Information Security in the Post-Quantum Age

Insights 09.08.2022 Quantum-Safe Cryptography Information Security in the Post-Quantum Age Recommendations for post-quantum cryptography: How to prepare your organization for future risks with solutions from genua today. Protection from quantum computers With the rapid development of quantum computers, the requirements for communication security are also growing. All asymmetric cryptographic methods that are used in Internet protocols today are in danger of being decrypted in a relatively short time in the near future. In addition, attackers such as foreign secret services or cybercriminals can already collect encrypted data today in order to decrypt it later with the help of productive quantum systems. This jeopardizes the value of the confidentiality of sensitive data. From the point of view of the German Federal Office for Information Security (BSI), post-quantum cryptography must therefore become the standard in the long term. The BSI advises organizations to weigh up when a switch to quantum-safe processes should take place at an early stage and continuously as part of a moderate risk management. Which Organizations are Particularly Affected? To mitigate the risks posed to US cybersecurity by quantum computing, US President Joe Biden signed a National Security Memorandum (NSM) in early May 2022, calling on government organizations to take preventive measures. These affect more than 50 US departments and authorities that use national security systems. This announcement has a signaling effect. Other countries could follow soon and oblige authorities, public institutions, companies that are subject to secrecy protection, and operators of critical infrastructure to take specific protective measures – i.e. to switch to quantum-resistant methods. Development Status of Quantum-Resistant Encryption Methods Internationally, there are already possible candidates for quantum-resistant encryption methods, which the US National Institute of Standards and Technology (NIST) is trying to evaluate. However, despite intensive investigations, there is still a lack of confidence in the security of the new methods and, in particular, experience in practical implementation. This means that official approvals and recommendations are currently only emerging slowly. Well Prepared with Crypto Agility Due to very slowly emerging standards and recommendations, we advise customers to use crypto agility, i.e. to pay particular attention to the cryptographic flexibility of the security mechanisms when developing and acquiring new IT security solutions. With appropriately configurable products from trustworthy manufacturers, organizations can minimize the attack surface of new types of attacks and react to future developments and security incidents. With high investment security, this lays a solid foundation for a future-proof IT infrastructure. What is important here is hybrid use with classic methods: the combination of proven and new cryptographic processes enables a safe transition into the future. Quantum-Safe VPN Solutions and Product Updates As an expert in IT security, genua develops and tests novel quantum-resistant processes and implements them, e.g. in VPN implementations. Within an international network of companies, universities and standardization agencies, we are significantly involved in the design of quantum-resistant VPN standards. As soon as these processes and solutions are ready for operation, we can safely provide them in our existing IT security solutions and new applications in the future. An important prerequisite for crypto-agility is the future-proof design of the update mechanisms of the products. This applies in particular if the update mechanism itself can no longer be updated securely. We already guarantee our customers trustworthy product updates: In addition to a classic digital signature for maximum security according to current standards, our specially developed update mechanism offers an extension with a quantum-resistant signature and thus already protects effectively against attacks with quantum computers. We thus meet the recommendations for future-proof software updates according to BSI and NIST. More on Post-Quantum Cryptography genua Solutions Offer Future-Proof Software Updates The Goal is Crypto-Agility Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption Share Article Related Links IT Security Solutions Back to Overview

Data center: High-speed coupling and geo-redundancy with FPGAs

Insights 01.02.2023 Data Center Interconnection With 40 Gbit/s: High-Speed Data Center Interconnect with FPGA Technology To ensure the security, high availability and redundancy of datacenters, IT security experts at genua are developing high-speed VPN gateways based on FPGA. The aim is to achieve extremely fast signal processing combined with maximum trustworthiness of the hardware. In this interview, Andreas Fiessler, Head of FPGA Development at genua, explains how Field Programmable Gate Arrays (FGPAs) are being used for high-performance packet processing in the project genuscreen 40G VPN. genuscreen appliance Why Is Trust a Key Factor in Datacenter Interconnect? Andreas Fiessler: For us as security manufacturers, trust is always the key focus of all of our products. Even with hardware-accelerated components, I could resort to ready-made solutions. The problem is that I can't see inside them. As a result, every backdoor and every functionality could be concealed there, installed by other people and hidden from sight. And I can't prove it, I can't rule it out. Unfortunately, that is a very realistic scenario. In the past, the possibility of such a thing was only discussed. But in just the last few months, we have seen from incidents such as supply chain attacks that these things actually happen. In this respect, developing FPGAs myself is an advantage. I can determine the wiring myself. And, of course, I can trust myself and prove that what's happening there is only what I want to happen. What Advantages do FPGAs offer for Data Center Interconnect? Andreas Fiessler: The main motivation is the speed. With FPGA-based hardware acceleration, I can achieve far higher speeds of network packet processing than would be possible on classic software-based systems. With our software-based solutions, we are currently achieving approximately 1 to 10 Gbit/s for encryption, depending on the scenario's complexity. It largely depends on what I do with the packets and how much pre- and post-processing I need. With hardware acceleration, I have completely different speed ranges, currently 40 Gbit/s, but 100, 200 or even 800 Gbit/s is a realistic aim. At the moment, we primarily intend this to be used for data center interconnect – where the number of connections is low and the speed requirements are high. This means networking multiple data center locations. How Are FPGAs Used in the genuscreen 40G VPN Appliance? close-up: genuscreen 40G VPN with FPGA expansion card Andreas Fiessler: Our new genuscreen 40G VPN Appliance is an FPGA-expanded version of the existing genuscreen, a VPN gateway that we have accelerated using the FPGA. On the FPGA, we use offloading mechanisms to accelerate the IPsec VPN connection, currently to 40 Gbit/s full duplex. We can guarantee low latency, currently of 20 μs, for packet processing. Here (image on the left), we can see an open genuscreen with the FPGA expansion card. On a normal genuscreen, the following would happen: We would have our network interfaces, and the network traffic would be processed by the normal CPU via a software-based approach. I would also be able to install larger network cards. However, at some point, an inherent maximum would be reached due to the overhead associated with software-based packet processing. In this scenario, I now have an FPGA-based card instead. It is configured via the normal CPU, via the host system. However, unlike with normal processing, I can process the packets directly on the FPGA. This means that my traffic goes in here, is processed and comes back out directly on the other interface, without an overhead. As a result, I easily achieve higher speeds. What Is It about FPGA Technology that Excites You? Andreas Fiessler: FPGA development is just fundamentally different than software development. The way of thinking is different, a bit special, but the results speak for themselves. You simply have far more options and goals that you can reach. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Network Security Data Center Share Article Back to Overview

Artificial Intelligence Training for Cyberwar

Insights 11.12.2019 AI-Based Tagging Artificial Intelligence Training for Cyberwar Artificial intelligence can assist in a targeted manner when it comes to protection of IT infrastructures – if you understand its functionality and extend its capacities. This was another busy year for businesses in the arms race against cybercriminals: According to the German Federal Office for Information Security, around 320,000 new malware items entered circulation between June 2018 and May 2019 alone – per day. This increases the pressure to establish an IT security infrastructure that can also keep up with the spectrum of future threats. Already today, AI-based programs play a key role here. The complexity of the challenges in IT security leave us with no other choice but to entrust many protection and monitoring functions to a "sentient" technology. However: Trust is one thing, transparency is better. If you hire a security service to monitor office space, factory buildings, or laboratories, you would naturally also check their references. The same applies to implementing AI in IT security: only those that provide transparency on their output make it through the door. If the AI functions and mechanisms are transparent, this also immediately makes for the right "collaboration" in the relationship: AI assists, suggests solutions, humans make decisions. Integrating Devices by Tagging The AI-based tagging feature is a good example of this transparency. Our cognitix Threat Defender uses this feature to identify attacks on company networks. Be it a smartphone, a router, or switches: If a device is recorded in a network via an IP address or a MAC address it can be tagged and also equipped with tag-specific security guidelines if necessary. This means devices with the same functions can be grouped for easier implementation of security guidelines. In this case AI takes on the helping role of permanently checking the behavior of all similarly tagged devices for deviations from the group status. For example, if something occurs at one of the five devices marked as #Printer that deviates from the behavior of the other four devices, AI raises the alarm. Find the Cat! AI specialist: Arnold Krille, Head of Development for cognitix Threat Defender at genua But how does the AI assistant actually learn what is "normal"? This is often explained by means of an image of a neural network – which AI systems use to learn things in a humanlike way, by receiving input and then independently linking this to new information. In practical AI this is not that easy. An example of the difference: We filter the "unusual" from the masses of “usual”, for example we quickly identify a cat image in amongst 100 dog images. An AI system does it differently, because it only "sees" the pattern it knows with varying degrees of certainty. If the AI system is trained to recognize dogs, it cannot recognize the single cat image amongst 100 dog images as a cat, but rather as "a dog with a 5 % degree of certainty". An AI system cannot recognize that it is being shown other animals, and cannot make any pronouncements about these. It first needs to be retrained again. This is an absolutely central challenge, particularly in AI security, as AI systems always need to relearn that a cat, cow, giraffe, etc. – that is, new threats in the network – exist, and how to respond to them. To "know" what is currently considered "normal" and is therefore expected behavior, AI systems need data that is constantly maintained. By tagging similar devices as functional groups, AI systems can always determine the behavior of the group or the average behavior of the group's members, and can detect deviations from this in individual devices – and in so doing detect deviations from "normal behavior" even if this changes over time. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Artificial Intelligence Share Article Back to Overview

IT Security Solutions From genua Withstand Quantum Computer Attacks

Insights 17.11.2020 IT Security Solutions From genua Withstand Attacks With Quantum Computers Thanks to the quantum-resistant signature scheme XMSS, IT security solutions can be securely updated even in the case of an attack with a quantum computer. Research into post-quantum cryptography Promising trials with quantum computers have taken place in recent months, attracting a great deal of attention from the public. Teams of researchers from established universities and digital companies such as Google, IBM, Intel and Honeywell are outdoing one another with superlatives in this highly competitive research field. With their special computational model, quantum computers are, in some cases, able to calculate extremely complex tasks such as climate models or chemical processes in pharmaceutical and materials research in an extremely short time. The first commercial quantum computers can be expected in just a few years. Quantum computers will also able to calculate the mathematical fundamentals on which most of today's cryptographic encryption and signature processes are based relatively easily and extremely quickly. The conventional encryption methods in today's commonly used public-key encryption methods, which are intended to secure sensitive IT infrastructures, would be cracked or, at the very least, weakened. Experts are therefore working on cryptographic methods that can defy the attacks with quantum computers. NIST Recommends the Practical Application of XMSS XMSS is one of the world's first signature schemes ready for practical use that can withstand attacks with quantum computers. At the core of the scheme are hash functions which, in principle, function only in one direction. Due to their properties, cryptographically secure hash functions are considered to be resistant against quantum computer attacks. The effectiveness of the attacks is, unlike other promising alternatives, already well understood today. The US National Institute for Standards and Technology (NIST), a world leader in the area of cryptographic standards, recommends the use of the first quantum-resistant signature schemes , XMSS and LMS, to protect against attacks with quantum computers. The German Federal Office for Information Security (BSI) also names XMSS as a reference. genua Uses Hash-Based Signatures for Updates Software update are the most suitable use case for hash-based post-quantum signatures. This ensures that a software update on a customer system actually came from the manufacturer and was not tampered with on the way to the customer. genua already satisfies the recommendation of the NIST as, in addition to the classic signature method, it utilizes XMSS to guarantee the authenticity and integrity of the sent software updates for the IT security solutions – as a digital replacement for signature and seal, so to speak. IT security solutions can thereby be securely updated even in the case of an attack with a quantum computer. Already six years ago, genua began to work together with the Technical University (TU) of Darmstadt on preparing the XMSS digital signature scheme for market. In 2017, the scheme was finally released as the first Internet standard for post-quantum signatures. More on Post-Quantum Cryptography Post-Quantum Cryptography: The Gradual Progression to Quantum-Safe Cryptography Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption Share Article Related Links IT Security Solutions Back to Overview

IT security solutions from genua for the public sector

Comprehensive IT Security Know-how for Future-oriented Administration Tasks here range from e-government solutions to the safeguarding of official internal and external communication. Two areas of activity are especially relevant here: the sensitization of employees and citizens for ongoing improvement of the IT security as well the technical security, e.g., in regard to the network security, transmission security of confidential messages or patch management. With genua’s product portfolio for the public sector, public authorities and organizations with security tasks can conveniently exchange restricted data via the Internet. Furthermore, an especially strong encryption algorithm enables secure connections by mobile laptop users as well as by employees working from home on networks that are classified for use with restricted data. As the provider of the first approved firewalls, we have special expertise in these areas of activity. Our IT security solutions for the public sector are always designed for stability and sustainability. As a company of Bundesdruckerei and close cooperating partner of the BSI, genua is able to offer a unique perspective for a reliable, long-term business relationship. More Information Whitepaper: Highly secure remote access to classified networks (PDF) Reasons Why IT Security Made in Germany For us, the label "IT Security Made in Germany" means combining quality, performance and service at a world-class level with a company culture whose pillars are integrity, customer orientation, sustainability and loyalty to location. Maximum Security genua meets the highest national and international security standards, a fact documented by, among other things, certificates and approvals. Our VPN solutions, for example, are approved by the German Federal Office for Information Security (BSI) up to the German classification level RESTRICTED (Classified – For official use only). Stability and Reliability genua considers itself to be part of the IT security ecosystem in Germany. As a company of Bundesdruckerei, we combine long-term, strategic and financial stability with innovation and research intensity. Effective Solutions From a Single Source genua accompanies public organizations and authorities from the conception of the IT security infrastructure to the selection and implementation of the right IT security products and support during an accelerated approval process. Quality Without Compromise The solutions from genua are developed on the basis of certified quality management processes. Our QM certification verifies the highest quality standards for products, services and processes. Furthermore, genua uses the IT security certificates of the BSI for periodic quality assurance by an external, recognized testing authority. Our sales team will be glad to answer your questions. We are looking forward to the contact with you. Contact us Products genua Ensures a Secure IT Infrastructure in the Public Sector Comprehensive Security Solution genusecure Suite Comprehensive solution for workplaces complient with the classification level German VS-NfD High Resistance Firewall genugate Complete data analysis for maximum network security Certified Approved Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks Certified Approved High-Speed VPN Appliance genuline Secure high-speed transfer of large amounts of data with FPGA technology Approved VPN Software Client genuconnect Secure connection of Windows devices to internal networks up to classification level German VS-NfD Approved IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Data Diode vs-diode One-Way Data Transfer in SECRET-Classified Networks Approved Highly Secure Certificate Solution genutrust Highly Secure Certificate Solution Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Central Management Station genucenter Convenient and efficient administration of IT security solutions ECOS SecureBootStick SX Flexible solution for VS-NfD-compliant working in the home office Approved High Resistance Firewall genugate Virtual Virtualized application level gateway for processing classified data Certified Approved Zero Trust Application Access genusphere Secure, browser-based access to shared applications See all IT security solutions We selected the genugate firewall from genua because this solution meets our requirements the best. (…) The combination of a BSI-certified security system in which the entire source code must also be presented and a two-level, hardware-based firewall technology from Germany is convincing. Andreas Pecher , IT-Administrator, Gemeinde Kirchheim b. München Decisive for this system were a solid connection concept, the high level of certification as well as relevant references. Andreas Wittwer , Consultant beim IT-Systemhaus Bechtle, Landratsamt Ansbach Our connection concept with the two-tier firewall was expressly praised by Bayern-CERT. In addition to the entire district administration including its five branch offices, 34 municipalities today use the Internet connection and, in spite of constantly increasing data quantities, can count on reliable bandwidth and IT security. Walter Dittrich , Leiter EDV Landratsamt Ansbach, Landratsamt Ansbach Get More Information Would you like to establish a highly secure and sustainable IT infrastructure for your public authority or organization? Our experts will be glad to assist you: ANREDE Mr. Ms./Mrs. Various Keine Angabe Salutation * First Name Last Name * E-Mail * Phone Public Authority or Organization * Your Request * For further information on the processing of your personal data, please refer to our data privacy police . Submit Public Sector genuas Solutions for Government Organizations Critical Infrastructure genuas Solutions for Critical Infrastructure Organizations Industry genuas Solutions for Industrial Value Networks Protection of Classified Information genuas Solutions for Projects with Confidentiality Requirements

The service offer of genua at a glance

Services Service for our IT security solutions is provided directly by genua or our trained sales partners. We can provide you with support for all of your security needs. In addition, we offer a 24/7 hotline and a regular update service. We would also be happy to put a custom service package together for you. Your advantages: The IT security systems run faultlessly and are always up-to-date, you save the cost for employing highly qualified administrators – and can concentrate on your actual core business. Download Service Flyer Powerful IT security 24/7: An Overview of genua's Service Offer Security System Management Using strongly encrypted Internet connections, we constantly monitor our systems installed within your network to ensure complete IT security. We carry out all maintenance work and keep our systems up to date at all times. Should a system nevertheless malfunction, we will know immediately and take remedial action straight away. System Management If you opt for the comprehensive system management, you don't need to take care of anything else. We have more than ten years experience with unix-based system management and TCP/IP networks. Because we have excellent knowledge of external systems based on AIX, Solaris, Linux and the BSDs, we can take charge of your complete network administration: the construction as well as the configuration of the systems, the setting of backup procedures and continuous monitoring, up to the import of upgrades and installation of new software and hardware. In addition, we provide you with comprehensive support for IT security, system enhancements and system changes. Hotline Service Just call us or send us an email – you will get qualified support for our IT solutions immediately. Instead of wasting time with long formalities we start solving the problem. A 24/7 hotline service in German or English is optionally available. Contact Us Update Service Our update service guarantees automatic supply of all new versions. In addition, you have access to our complete patch database. This means that your systems are always up to date. Visit Customer Portal Hardware Support For our hardware we provide Germany-wide next business day replacement service: If one of your appliances breaks down, you will receive an identical exchange unit on the next working day. We also ship exchange units to international locations, but due to shipping restraints cannot guarantee delivery until the next working day. Depending on the hardware model, this service is free up to three years after purchase. Individual Software For Customized IT Security When standard solutions cannot cover important processes or can fulfil requirements only inadequately, the development of customized software is the right approach. Sometimes customized software is called for: When standard solutions cannot cover important processes or can fulfil requirements only inadequately, the development of customized software is the right approach. In the field of IT security, we guarantee that, upon completion of the project, genua’s customized solutions will precisely meet your requirements profile. We can make this commitment to our customers, as we are able to draw upon many years of expert knowledge. The method we follow in projects requires a regular exchange with the users and thereby eliminates the possibility of undesirable developments. Advantages of Customized Software Development with genua Exact implementation of your requirements Regular tests and acceptance of important development steps Comprehensive support starting with the design all the way to ongoing support Our sales team will be glad to answer your questions. Contact Us Customer Statements on the Services of genua The security of the company network and fault free operation of the global remote maintenance of our print machines have top priority in manroland’s IT. This can be ensured through the very proactive and flexible, reactive service by genua. Karlheinz Huber manroland Even though firewalls and VPN systems only form a part of our complex security strategy, it was extremely important for us that the hardware offers a high potential for integration and that our partners have extensive expertise both as a solution and as a service provider. Therefore we are pleased to have found the right solutions for our needs with a company such as genua, giving us the optimal strategic preparation we require. Andreas Braunmiller RTL 2 We can rely on genua’s service at all times. We receive quick and competent assistance if we have any queries. They not only provide us with solutions but are also always there with useful background information. I can recommend genua every time. Martin Marshall Schreiner Group We have been working with genua since the first genuboxes came on the market. Since then, genua has helped us to develop a complex system linking and providing Internet access for our sites. This collaboration is characterized by a high level of technical expertise and extraordinary helpfulness. The comprehensive and reliable service provided by genua enables us to operate our IT systems securely. Rüdiger Schwan Julius Kühn-Institut genua has been reliably meeting our IT security needs since 2004. The genua Team has always shown a high level of competence and engagement, whether they were developing the first security policy or implementing the rigorous Bavarian Administration’s network guidelines. System modifications and extensions were technically sound and implemented quickly, pleasantly and with a minimum of trouble. genua is very recommendable. Walter Dittrich Ansbach District Office Do you need more information? Contact Us

1 2 3 4 5 6 7 8 9 10 11 12 13 14
Contact
+ 49 89 991950-0
+ 49 89 991950-999
info(at)genua.de
  • Genua Security made in Germany Logo
  • Genua Tüv certificate
  • Genua Tüv Rheinland Zertifikat
  • Genua Tüv Zertifikat
  • © 2026 genua
  • GCC
  • Imprint
  • Data Protection and Privacy
  • Whistleblowing System
  • Terms of use
genua bdr signet