• Contact
  • Customer Portal
  • Partner Portal
  • Jobportal
  • Search
  • DE
LogoGenua Logo
  • Solutions
    IT Security Solutions

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Firewalls & Gateways

      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN

      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance

      • Remote Service Solution genubox
    • Mobile Working

      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes

      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security

      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter

      • Central Management Station genucenter

    Comprehensive Security Solution genusecure Suite

    Comprehensive solution for workplaces complient with the classification level German VS-NfD
    [Translate to English:]
  • Fields of Use
    Fields of Use

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Public Sector

      IT Security Solutions for Authorities and Public Institutions

    • Critical Infrastructure

      Protection of Critical Infrastructures and Sensitive Systems

    • Defense

      IT Security for Military Networks and Data Communications

    • Classified Industry

      IT Protection for Projects with Confidentiality Requirements

    • IT Security for Mechanical and Plant Engineering

      IT Security for Networked Machines and Systems

    Fotocollage zur High Resistance Firewall genugate (Verwendung nur für die Presse)

    Our sales team will be happy to answer your enquiries. Let us advise you!

    Get in Touch

  • Service & Support
    Service & Support

    Contact

    + 49 89 991950-0info@genua.deContact us
    • IT Security Services

      On-site Support, 24/7 Hotline and Regular Update Services

    • Trainings

      Product and Solution Trainings for Your Team - Practical and Up-to-date

    • Hacking Bootcamp

      Improve the Defence of Your Systems and Get to Know the Techniques of Real Hackers

  • Topics & Trends
    Topics & Trends

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Topics

      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base

      Case Studies, White Papers, Specialist Articles, Interviews and Insights from the IT Industry

    • Research Projects

      Whether it's Post-Quantum Cryptography or a Secure Cloud - Here You Will Find an Overview of our Current Research Projects

  • Partners
    Partners

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Sales Partner

      Benefit from the expertise of our qualified Sales Partners

    • Partnerlocator

      Find your genua Sales Partner in our overview

    Three employees in a sales dialogue

    In our Partner Portal we provide services to support you in your sales activities.

    To the Partner Portal

  • Career
    Career

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Working at genua

      Start Your Career with the Leading IT Security Specialist

    • Vacancies

      Our current vacancies at all locations

    • Speculative Application

      Send us your application now.
We look forward to hearing from you.

    Two genua employees engrossed in a cheerful conversation

    Start Your Career now at the Leading IT Security Specialist genua

     Career site

  • About Us
    About Us

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Facts & Figures

      Milestones in genua's Success Story: a Look at the Figures

    • News

      The Latest News on Products and Company Updates

    • Trade Fairs & Events

      Meet us and Our Experts at the Most Important IT Security Events

    • Press & Media

      Press Releases and Media Downloads

    • Trainee Firm genufix

      Fast & Free Help for Charitable and Social Organisations in and Around Kirchheim near Munich

    • genukids

      In-house Childcare for Employees and Residents of Kirchheim

  • DE
  • Solutions
    • Firewalls & Gateways
      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN
      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance
      • Remote Service Solution genubox
    • Mobile Working
      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes
      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security
      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter
      • Central Management Station genucenter
  • Fields of Use
    • Public Sector
    • Critical Infrastructure
    • Defense
    • Classified Industry
    • IT Security for Mechanical and Plant Engineering
  • Service & Support
    • IT Security Services
    • Trainings
    • Hacking Bootcamp
  • Topics & Trends
    • Topics
      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base
    • Research Projects
  • Partners
    • Sales Partner
    • Partnerlocator
  • Career
    • Working at genua
    • Vacancies
    • Speculative Application
  • About Us
    • Facts & Figures
    • News
    • Trade Fairs & Events
    • Press & Media
    • Trainee Firm genufix
    • genukids
  • Contact
  • Customer Portal
  • Partner Portal
Displaying results 129 to 144 of 210.
Results per page:
pages 93
press 48
knowledgebase 37
news 16
product 16

Sovereign Clouds And IT Security: Cyber Security in The Cloud Era

Insights 24.01.2024 Cyber Security and Strategy Sovereign Clouds and IT Security: Cyber Security in the Cloud Era How can we develop trust in the security of critical digital infrastructures and sovereign clouds? And what is needed ultimately to justify this trust? A geostrategic analysis of cyber security in the cloud era. In der neuen Arbeitswelt gilt für die IT Security mehr denn je: velocity is king. Schließlich verkürzen auch die Angreifer ihre Zyklen bei der Entwicklung neuer Methoden und Tools. , Michael Barth, Head of Strategy Department Geostrategic Perspectives And Cyberspace Michael Barth, Head of Strategy Department by Michael Barth The world has become a less safe place. Instead of bloc confrontation like that experienced during the Cold War, today different players on different fronts operate with, in part, fluid alliances. By recognizing cyber as a further organizational area in addition to the army, navy and air force, almost all of the world's armed forces have documented through coherent action just how decisive superiority in the information space is – for their own information and command capability, but also in order to disrupt the infrastructure and defense capability of the enemy. A New Era For IT Security IT security was once considered a niche area that could cause limited damage. Today, it is a matter of digital sovereignty and therefore national security. Severe disruption of civil information infrastructure for power plants, energy networks, hospitals, pipelines, airports or railroads is automatically of great interest from a military perspective. This becomes evident not least in the war in Ukraine and from previous hacker attacks on civil infrastructure. Attacks for military purposes can quickly and unintentionally spill over into civil structures. At the same time, the operating space of cyber domains offers possibilities for the manipulation and impairment of infrastructures which are below the threshold of armed conflict. The risk of escalation for state actors is thus lower than in other areas of the confrontation. They are therefore the preferred means. Consequently, it is logical that the EU wants to use its legislation to as far as possible close these gaps in the cyber domain in order to safeguard the provision of public services. The NIS2 directive and the Cyber Resilience Act are particularly noteworthy. Here, it can no longer be assumed that security can be achieved by purely technical means. Instead, instruments such as ISMS, ISO 27001 and IT basic protection in line with specifications from the German Federal Office for Information Security (BSI) are aimed at reducing attack surfaces, strengthening organizational structures as well as establishing a forward-looking risk management including plans to deal with the worst-case scenario. Germany And Europe Are Setting Standards For Cyber Security Defense in depth, i.e., the principle of additional security mechanisms, should the first fail, is applied not only at a technical level, but also from a political perspective. Here, Germany and Europe are setting standards. In addition to NIS 2.0, the Cyber Resilience Act and AI Act on a European level, Germany is implementing, e.g., the cloud standard BSI C5 on a national level. What is frequently branded as prohibitionism has a multitude of positive effects. As with the GDPR, C5 has also resulted in multinational companies such as Amazon, Google or Microsoft conforming to European regulations. In terms of its gross domestic product, the European Economic Area is more than equal to the USA. In this respect, Europe often undervalues itself and, owing to the diverse voices in the Council and Commission, does not appear as homogeneous as the USA. There, a quite specific paradigm such as zero trust may on occasion be decreed for Federal Authorities by way of presidential order. Sovereign Key Technologies For Trustworthy Sovereign Clouds In recent years, we have seen not only the increasing relevance of zero trust for sovereign information processing, but also the desire to consolidate official information processing using cloud technologies, as has long been the case in business and commerce. The cautious approach of the public sector is understandable: Unlike private enterprise, it would be a mistake for the State to spontaneously apply the trial-and-error method, because the subsequent effects take a long time to deal with. Even the procurement law in its current form is only partially suitable for implementing contracts with uncertain outcome in terms of technology. At the same time, niche areas such as authorities entrusted with processing classified information ask themselves whether and how they can benefit from the promises that use of the cloud offers. Also, it must be clear that the requirements in terms of security features will be greater than for classic administrative tasks. This is because the information processed is by definition such that if misused it can be at least detrimental to the continued existence of the Federal Republic of Germany. For this reason, it is clear that central functions such as access to cloud services and also the separation of client and information in the cloud need to be additionally hardened by means of trustworthy services to enable usage in the context of classified information. In this respect, these trust anchors would therefore be indispensable key technologies, the use of which should be demanded by state users to ensure continued control over the critical data. Technical Perspectives Regarding IT Security And Sovereign Cloud Alexander von Gernler, Head of Research and Innovation by Alexander von Gernler For a long time, the cloud was considered to be "just somebody else's computer". In other words, if I can't trust the cloud operators, I shouldn't use the cloud for calculations and applications. Simply saving data is OK, just as long as it is properly encrypted. Using the cloud for remote file storage, however, unlocks barely any of its benefits. What I don't have under my physical control can't, from a technical viewpoint, be secure. This is why, well before the advent of the cloud, the era of service level agreements and security by contract began. It was relied upon that the service providers would not ruin their own business by handling data carelessly. From Perimeter to Zero Trust Along with the cloud movement, networks have also developed further in recent years. The previous perimeter paradigm (inside good, outside bad) went from microsegmentation (firewalls between individual parts of the network), intrusion and exfiltration detection, and software-defined networking to the assumption of zero trust, i.e., that local networks should actually be regarded as irrelevant or compromised. Previously, if the filtering of data took place at packet level and based on technical characteristics (IP address, port), the filter criteria became more and more powerful with each higher ISO/OSI layer. In today's zero trust setups, the most important criterion is the identity of the users. All other criteria can additionally contribute to a defense-in-depth approach. One hope still not realized in practice is computation on encrypted data, in other words homomorphic encryption. This quickly reaches its limits as soon as more complex mathematical operations are necessary. The known methods scale poorly in terms of time and computing effort. Many have not yet been used extensively enough to develop real trust. In der neuen Arbeitswelt gilt für die IT Security mehr denn je: velocity is king. Schließlich verkürzen auch die Angreifer ihre Zyklen bei der Entwicklung neuer Methoden und Tools. , Alexander von Gernler, Head of Research and Innovation New Hope: Confidential Computing A promising candidate recently appeared on the scene: confidential computing. Here, special features of common processors (e.g., AMD or Intel) are used to completely encrypt the main memory of an enclave and to decrypt it only when loading data to the CPU. This can be verified cryptographically from outside, similar to measured boot in trusted computing. In this way, it is no longer necessary to trust the cloud provider, but instead just the processor manufacturer. This is acceptable as the processor manufacturer had to be trusted prior to this. Moreover, a manipulated CPU provides considerably poorer attack possibilities than a manipulated cloud stack. At present, confidential computing still suffers from measurable deficits in terms of performance. The question concerning the final architecture is also as yet unanswered. Furthermore, a compatible framework that can be used to reliably and scalably check whether the desired virtual machines or Kubernetes pods are really in a secure enclave is also important. Three Requirements Regarding The Security of Sovereign Clouds If we now turn our attention to a secure and sovereign official information processing – also for classified information – regardless of whether in a private or public cloud, what should our requirements be as a whole? First: The available confidential computing system should be functional, tested and performant. Second: Data should not be processed at a whim, but in accordance with a plan from the relevant authority, i.e., the German Federal Office for Information Security. Third: To ensure supply reliability, we urgently need a functioning market of national providers and sovereign cloud solutions. For the purposes of controllability, available proprietary solutions, such as m365 planned by Delos in the national datacenter, require the possibility of inspection by the BSI and users. And it is absolutely essential that we do not fall short of the existing standards such as BSI C5. An abridged version of this article also appeared in Edition 1/2024 of the trade journal ix. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Cloud Security Share Article Back to Overview

Critical infrastructures: attack detection according to BSI specifications

Insights 06.06.2023 Critical Infrastructure and IT-SiG 2.0 Three Steps toward Attack Detection According to the BSI With the German IT Security Act 2.0 (IT-SiG 2.0), both the German "Act on the German Federal Office for Information Security" (BSIG) and the German "Electricity and Gas Supply Act" (EnWG) have been rendered more precise in relation to critical infrastructure. It is now compulsory to put in place attack detection systems . How can the requirements of the German Federal Office for Information Security (BSI) be met? Summary As of May 1, 2023, operators of critical infrastructure must demonstrate use of state-of-the-art attack detection systems to obtain certification ► The "Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung" ("Orientation guide to using attack detection systems") by the BSI defines the BSI's requirements in more detail This guide is also intended to act as a reference point for auditing bodies in the future According to the guide, the tasks of attack detection systems can be divided into three categories ► Systems must detect security-relevant events by continuously evaluating the information gathered ► The data generated through logging must be analyzed for deviations ► An adequate response to the security-relevant events identified by the detection system must be implemented ► Practical tip: intelligent attack detection with a state-of-the-art Network Detection and Response (NDR) system ► Attack Detection According to the BSI Paragraph 8a of the German "Act on the German Federal Office for Information Security" (BSIG) makes it obligatory for operators of critical infrastructure and companies of special public interest to use attack detection systems as of May 1, 2023. These systems are effective means of detecting cyber attacks at an early stage and thereby avoiding or at least reducing the extent of the damage. To give affected companies additional clarity and security when it comes to implementing the new legal requirements in their individual case, the German Federal Office for Information Security (BSI) published an "Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung" ("Orientation guide to using attack detection systems") at the end of September 2022. This guide is also intended to act as a reference point for auditing bodies in the future. Functions and Task Categories of Attack Detection Systems According to the guide, the technical functions and tasks of attack detection systems can be divided into three categories: Logging Detection Response. Thus, the systems must use functions such as misuse detection or anomaly detection to continuously evaluate gathered information and thereby identify security-relevant events. In addition, they must implement measures to prevent or respond to disruption caused by attacks. The measures implemented can be technical or organizational. 1. Logging as Part of Attack Detection The quality of attack detection depends on the ability to fully scan assets and communications in the network. (Image: Screenshot of the cognitix Threat Defender for attack detection) In the common IT infrastructure, central logging services and log management solutions are widely established. They enable extensive analysis of processes and attacks. The situation is different with the Internet of Things, e.g., when it comes to networked machines and plants in industrial production. In this case, central logging is so far very rare but nevertheless essential in order to effectively detect and combat disruption and attacks. This requires the relevant log data from all components to be recorded centrally. In addition, some components in the network cannot perform any additional logging tasks because they have limited resources beyond their normal function. In such cases, the relevant network segment must be monitored externally. The findings of this monitoring must also be logged centrally. The quality of the detection is dependent on the attack detection system being able to scan an entire network. Relevant data includes which devices are present in the network, who communicates with whom, and which communication protocols are used and how frequently. Therefore, the BSI recommends also installing a network monitoring system, even if all devices are capable of logging their own activities autonomously. The reason for this is that a large data pool is essential in ensuring that the subsequent detection is successful. 2. Analyzing for Deviations – and Assessing Properly The data generated through logging must be analyzed for deviations. For this, relying purely on technical and automated analysis is not recommended. Instead, it is crucial that a human regularly checks the entirety of the logs for vulnerabilities. The BSI is aware that technical systems are very good at detecting deviations from learned patterns but very bad at predicting the effects of such deviations, and that this can cause difficulties. Especially in common plants, (desired) changes regularly overload the learning capabilities of automated methods. Therefore, detecting new and unknown disruptions and assessing whether these are malfunctions, problems or even attacks is explicitly the responsibility of specialist personnel. 3. An Effective Response Requires Clarity View of the cognitix Threat Defender cockpit. Only if everyone involved and affected has a clear picture of the threat and the necessary response can they react effectively. It is then necessary to respond adequately to the security-related events detected. In addition to naming the people responsible for handling this, it is primarily important to define and follow standardized procedures. To respond effectively, it is essential that all those involved and affected have a clear understanding of the threat and the necessary response. It is fundamentally important to weigh up implementing more or less drastic measures to combat the attack versus ensuring that the critical infrastructure can continue performing its actual core task. It is also necessary to define how and which appropriate information will be reported promptly to the relevant contact points. The more quickly and more comprehensively measures are implemented, the more effective they are. Therefore, at least in less critical areas, an automatic response is not simply an additional recommendation – it must be possible. Thus, how a network will be monitored and how active and automated intervention will be enabled must also be considered from the outset. Implementing State of the Art Attack Detection How logging, detection and response can be supported by state-of-the-art anomaly detection can be explained using the example of the Network Detection and Response (NDR) System cognitix Threat Defender . This intelligent solution meets all fundamental legal requirements for a technical attack detection system. cognitix Threat Defender offers benefits such as excellent detection of network components and incorporates all relevant systems, components and processes, such as IT, OT, datacenters and embedded systems. Operators can continually and automatically record and evaluate relevant parameters and characteristics from ongoing operation. If vulnerabilities are detected, a graduated range of response options are available. In addition to reporting anomalies, devices and communications can be isolated, slowed down or blocked completely, for example. To avoid unnecessary disruption in the network if the threat situation is unclear, cognitix Threat Defender can also respond adaptively in the event of an incident. In such cases, it only allows the affected device in the network to perform actions that have been learned as "normal" in the last 24 hours. Everything that deviates from this is slowed down or blocked and reported to those responsible for security. This gives them time for an adapted and effective response. Supporting Organizational Measures According to the BSI, however, an attack detection system is not limited to technical solutions but also includes organizational measures to ensure the cyber security of a company. As a technical component, cognitix Threat Defender has therefore also been developed with usability in mind. The modern user interface presents those responsible with the relevant information in a simple format so that they can familiarize themselves with the situation quickly. Sources and related links: [1] PDF download from the BSI: Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung (Orientation guide to using attack detection systems, German only) [2] High-performance attack detection for reliable protection of IT and OT networks: cognitix Threat Defender Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Threat Detection Critical Infrastructure Share Article Related Links Offer request cognitix Threat Defender IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

VerSeCloud: The Path to a Trustworthy, Secure Cloud

Insights 03.01.2024 Research For a Future-Proof Cloud "Made in Germany" VerSeCloud: The Path to a Trustworthy, Secure Cloud What does a secure, trustworthy and also future-proof cloud look like? The aim of the research project VerSeCloud is to provide a solution. Using a microkernel, formal methods of proof, and strictly implemented separation between customer applications, the consortium partners – Kernkonzept GmbH, genua GmbH, the University of Potsdam and the Technical University of Munich – are developing the foundations for a highly secure cloud infrastructure. by Nicolas Frinker, software engineer at genua Software engineer Nicolas Frinker (2nd from right) in the VerSeCloud team Project Details Project coordinator: Kernkonzept GmbH, Dresden Partners: genua GmbH, University of Potsdam, Technical University of Munich Duration: 04/2021 - 03/2024 BMBF project website for VerSeCloud Virtualization as the basis for cloud solutions has become a key element in today's IT infrastructure. The associated abstraction of existing physical resources into a virtual environment allows these resources to be used in a flexible, scalable and cost-effective way. However, sensitive data and applications require a high level of data security and trustworthiness, which cannot be provided by currently available virtualization solutions: Owing to their underlying operating systems, current solutions are complex and extensive and, as a result, it is extremely difficult to check that they provide reliable security. Approval or certification is therefore only feasible at great effort and expense. In the VerSeCloud research project, we together with our project partners (Kernkonzept GmbH from Dresden, the University of Potsdam and the Technical University of Munich) are working on a future-proof, reliable and secure virtualization solution also intended for security-critical cloud applications. In der neuen Arbeitswelt gilt für die IT Security mehr denn je: velocity is king. Schließlich verkürzen auch die Angreifer ihre Zyklen bei der Entwicklung neuer Methoden und Tools. , Nicolas Frinker Cloud Applications: Streamlined And Verifiable Based on the L4Re microkernel, we are developing a performant (thanks to Intel Vt-x) and flexible hypervisor which can run Linux and OpenBSD without modification. Using nested virtualization, it is also possible to run other operating systems such as MS Windows. As a result of the microkernel basis, the code base remains streamlined and verifiable. The L4Re microkernel, which runs with system rights, is only responsible for the most fundamental tasks such as separation of the applications. All other tasks are outsourced and performed only with restricted access rights. With this architecture, the security-relevant components remain streamlined and verifiable and are therefore also suitable for more in-depth reviews, e.g., in an approval process. In addition to the solid and secure technical basis, formal methods to mathematically verify security features of the microkernel and drivers are also used in the VerSeCloud research project. An abstract model of the L4Re microkernel is used to define an expected condition and an extremely large number of automatically generated tests is then used to compare the expected condition with the actual condition in the implementation. For the drivers, network drivers in particular are examined in greater detail, and common features are determined and transferred to the proof assistant Coq. There, their correctness can be proved and code synthesized, which can then substitute parts of the driver with evidentially correct code. This approach using formal methods increases security significantly. Four Questions to Nicolas Frinker Are comprehensive IT security and data protection in a cloud environment where data is accessed using many different devices including mobile devices, actually possible? Nicolas Frinker: IT security and data protection in a cloud environment depend on two factors: the provider and the used technology and software. The used technology must ensure that customers in the cloud environment are separated from each other securely and reliably. In turn, the trustworthy provider must ensure that this technology is used consistently. If both requirements are met, customer applications and data are well protected. What would be potential application scenarios? Nicolas Frinker: Today's large-scale cloud providers are mostly located in the USA and do not necessarily command the trust of many German companies. These companies therefore lack a trustworthy provider and, in addition, the used software draws attention repeatedly due to security problems. To fill the gap left by the missing, trustworthy cloud providers, many companies resort to self-hosted clouds, so-called private clouds. Here, the datacenter is installed in the company's own basement and is used exclusively by the company, so that software-based separation of multiple customers is no longer necessary. This solution is therefore secure, but at the same time the essential benefits of a public cloud, such as scalability and cost-efficiency, are lost. Here, VerSeCloud can provide the basis for a promising future: A cloud environment based on the software researched in VerSeCloud with its formally proven security features offers the necessary secure and technical basis on which multiple customers can share the same cloud environment without having to worry about their separation from other customers. If this software is then also operated by a trustworthy cloud provider, cost-effective and scalable security and data protection are possible! How is the project divided up within the team? Nicolas Frinker: Basically, Kernkonzept and genua are jointly researching improvement of the new hypervisor, while Kernkonzept together with the University of Potsdam is endeavoring to evidence security features by means of formal verification. My main task is to make OpenBSD, as a further guest system in addition to Linux, runnable on the new hypervisor. What progress has so far been made? Nicolas Frinker: The new hypervisor is now properly matured and can run Linux and OpenBSD as guest systems. There has been plenty of progress on the formal methods front too: For example, a complete, simple driver for L4Re has been synthesized from the proof assistant Coq. Related links [1] To the project page of the Federal Ministry of Education and Research (BMBF). The project is funded as part of the BMBF's ‘KMU-innovativ’ programme. [2] Read more about genua's current and completed research projects . Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Cloud Security Research Share Article Back to Overview

RFC 8391 – a Milestone in the Protection from Quantum Computers

Interviews 26.06.2018 Expert Interview: RFC 8391 – a Milestone in the Protection from Quantum Computers Collaborating on the research project squareUP, researchers from genua and the Technical University of Darmstadt have developed a post-quantum signature scheme. This procedure is technically mature and a so-called Internet draft had been written in cooperation with other universities during the project. This draft has now been released as RFC 8391 and is the first universally recognized standardized procedure for digital signatures which can withstand attacks based on quantum computers. Protection from quantum computers We talked to Stefan-Lukas Gazdag about this development. He is an engineer in genua’s research division and one of the authors of the RFC. Why is it so exceptional that researchers from genua have worked on an RFC? The process from an early draft evolving into an RFC is, as with many attempts to establish a standard, sometimes a cumbersome process. However, this process is unavoidable before a cryptographic scheme can be used in practice as developers have to have a reference available which they can rely on during their work. And there is more to be done than simple writing. There are numerous sometimes contrary opinions and requirements from various people and organizations to be considered in a draft. Many experts read and evaluate the document. This is extremely helpful and also necessary, as it means that the scheme being described will receive a lot of attention and that any possible inconsistencies in the document will be found more easily. On the other hand, this process is time-consuming and therefore expensive. In our case the process lasted three years. Thankfully, part of our efforts was funded by the Bavarian Ministry of Economic Affairs, Energy and Technology (StMWi). The environment around the IETF/IRTF, the organizations behind RFCs, is particularly influenced by large companies and universities. Therefore, it’s not an everyday occurrence that a relatively small German IT security company contributes to an RFC to make a new technology generally usable. genua now publishes quantum-resistant signatures for numerous products and in doing so belongs to the first IT security companies that use this procedure to secure their software updates. Could you say that we have the most secure software updates in the world? Superlatives should be used with caution but it is also true that we send out our software updates with digital signatures that are secure according to the current state-of-the-art. Through the combination of these classical procedure with a quantum-resistant alternative that is available and ready to use today, we can look forward to the coming years with confidence. This means that our customers can safely install software updates for products such as our genuscreen and genugate firewall systems even if a hostile secret service should possess a large quantum computer. A number of organizations are working on powerful quantum computers and reporting a respectable degree of success. However, they do not yet appear to be ready to be used productively, so how can you be sure that the software updates are really quantum-resistant? To elaborate this we need to clarify why the different cryptographic procedures are secure. There are a number of different approaches to describe the security of cryptographic procedures, with one important characteristic being the best-known attacks. In addition, nowadays attempts are made to provide mathematical proofs for specific procedures but that is a very difficult undertaking. Even if a procedure is shown to be secure in a theoretical model, it is possible for attacks to occur that have not been considered as part of the model. An aspect that is often used takes a more generic approach, focusing on a generic types of schemes and not just on specific algorithms. All the attacks on the procedure we use and known by the cryptographic community can be dealt with, in particular the generic ones. This applies for all classical attacks as well as those supported by quantum computers. However, absolute security does not exist here: Some genius could wake up any day now and suddenly have an idea for a successful, non-generic attack. We should also emphasize here that this applies just as much for conventional attacks as for new quantum algorithms. In addition, we only use a well understood and intensively examined primitive, a fundamental cryptographic building-block that is important for all practically relevant signatures. The whole security infrastructure will be faced with a huge problem if this is cracked. Secure software updates are without doubt an important milestone but will we also be able to protect encrypted communication from attacks with quantum computers? Securing our updates was only the first step. We are currently working on secure communication over the Internet using quantum-resistant procedures. However, this is a more complex subject which the whole post-quantum cryptographic community is currently working on. Thank you for this conversation. The TU Darmstadt was funded by the German Research Foundation (DFG) and genua by the Bavarian Ministry of Economic Affairs, Energy and Technology (StMWi). On genua's side, the project was supervised by the VDI/VDE Innovation + Technology GmbH. Related links [1] To project website of squareUP [2] New QuaSiModO Research Project Launched [3] Article: Watch Out, Crypto Hackers: The Gradual Progression to Quantum-Safe Cryptography [4] Read more about genua's current and completed research projects . Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption Research Share Article Back to Overview

Five Answers on cognitix Threat Defender

Interviews 02.09.2019 Five Answers on cognitix Threat Defender In May 2019, genua acquired IT security start-up cognitix, which is now an in-house department at genua in Leipzig and is further developing cognitix Threat Defender. The solution, which uniquely combines data analytics, and threat intelligence is now part of genua’s IT security portfolio. Interview with Arnold Krille, Head of Development for cognitix Threat Defender, about the innovative IT security solution that combines data analytics and threat intelligence. cognitix Threat Defender Why is cognitix Threat Defender a perfect match for genua’s range of solutions? Arnold Krille: genua’s products cover many areas of IT security very successfully. They are used to safeguard a network or network segment against unauthorized external access, or to control and authorize trustworthy outside access. Our focus with cognitix Threat Defender – in conjunction with the existing portfolio of genua – is on security within the actual network segments by way of a totally new approach, namely using data analytics and threat intelligence. Plus, the development of cognitix Threat Defender paves the way for other promising opportunities for collaboration at product level. Arnold Krille, head of development for cognitix Threat Defender at genua cognitix Threat Defender combines different protection features – what are they and how do they interact with one another? Arnold Krille: In the first instance, cognitix Threat Defender works on layer 2 of the OSI layer model – a layer that had relatively few protection features so far. In this way, cognitix Threat Defender can monitor all the traffic in the network and consequently the behavior of all the devices. Threat Defender can then compare this information with modeled behavior and respond accordingly. We also call this correlation, because completely different network flows can work together smoothly over extended periods of time. So, we’ve basically extended the policy scope to include tracking of information over time. Of course, we also provide a great deal of information about the context of network traffic: Layer 7 classification, geo location, asset identification, IDS and threat intelligence indicators, as well as users – the keyword here is ‘Active Directory Integration’. Naturally, all this information is available for reporting and external logging, and of course while taking into account rules and behavior modeling. "The cognitix Threat Defender could best be described as an 'intrusion detection system on steroids'." How is cognitix Threat Defender different from solutions that are marketed as intrusion detection or intrusion prevention systems? Arnold Krille: Although intrusion detection or intrusion prevention systems provide a certain feeling of security against threats in a network, this is only the case if the IDS can monitor the entire traffic in the network via port mirroring on switches. In most cases an IDS/IPS is a module on the firewall, which means that it only identifies threats or patterns that occur across network boundaries. cognitix Threat Defender is much more than an IDS or IPS. It could best be described as an ‘intrusion detection system on steroids’. The IDS usually only searches for patterns in a data stream. Our cognitix Threat Defender searches the network for patterns in the behavior of the network devices. The results provided by the IDS are only part of the information, and in combination with the remaining context and the policy engine, IDS hits are merely a criterion which is verified through further information and behavior. In this way, overreaction in the case of false positives can be effectively prevented, but completely new correlations can be discovered as well. What is the biggest benefit for companies that use cognitix Threat Defender? Arnold Krille: A key benefit in every aspect is greater transparency of their network. Incorrect configurations, network attacks, intentional or unintentional misconduct, as well as other weak areas can be identified through a wide range of analysis methods. The bonus is to be able to respond appropriately to these events and threats, but you only know how to value this once you actually have an overview of your own network. What are the next milestones in the development of cognitix Threat Defender? Arnold Krille: Besides continual improvement of the protection features and usability, our next focus is on interoperability: We will make sure that multiple cognitix Threat Defenders in an organization can be managed like an individual system. Our aim is to make protection of the entire network as easy as possible. Naturally these different cognitix Threat Defenders will then also exchange information about context. And other genua products will also be integrated. For example, the High Resistance Firewall genugate, and cognitix Threat Defender can complement each other in regards to behavior and be combined in terms of administration. In addition, we want to ensure that the administrator has more than just an overview of the organizational network; we also want to provide assistance when it comes to identification, evaluation, and appropriate responses to threats. By way of suitable assistance systems, data analyses, and learning methods we will make administrators’ lives a whole lot easier. Thank you for your time. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Threat Detection Network Security Share Article Related Links IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

RTL2: High Performance Requirements for VPN Systems

Interviews 03.12.2019 RTL2: High Performance Requirements for VPN Systems Do media companies place special requirements on IT security? And what are the current challenges? RTL2 is one of genua's long-standing customers – an interview with Reinhard Görtner, Head of IT & CIO, RTL2 Fernsehen GmbH & CO. KG. RTL2 VPN-Performance As a media company, what special requirements do you have with respect to your IT security? Reinhard Görtner: On the one hand, IT security is – as in any other company – the basis for smooth business operations. On the other hand, as a media company we are very much in the limelight and consequently have increased security needs. This is compounded by the large data volumes that arise from high-resolution videos and the fact that the throughput of this data cannot be slowed by security solutions. Have your IT security requirements changed over the years? If so, how? Reinhard Görtner: In the past, our security requirements focused on protecting our internal network against unauthorized access from the outside. Today, we need to assume that perimeter protection is just one part of our security strategy. The opening of our network for our external offices and partners around the world poses further challenges. Reinhard Görtner, Head of IT & CIO, RTL2 Fernsehen GmbH & Co. KG Is it important for you to use IT security solutions made in Germany? Reinhard Görtner: We greatly appreciate that, with genua, we have a partner that develops its products in Germany and – should the need arise – can respond quickly on-site in the event of an emergency thanks to its location in the greater Munich area. You have been using the High Resistance Firewall genugate from genua since 1998 and are among the company's very first customers. How has the firewall served you in use? Reinhard Görtner: Simply the fact we are aware of no incident since 1998 in which our genugate firewall was breached by an attacker shows that the solution has proven itself. What in particular do you value about the genugate firewall? Reinhard Görtner: Big plus points are the high availability and the possibility to completely control the data traffic that runs through the firewall. For the connection of your new locations, you opted for the Firewall & VPN Appliance genuscreen. Why did you select these systems from genua? Reinhard Görtner: We have for years had good experiences using genuscreen for encrypted data exchange via VPN with our partners. It seemed only logical to us to connect our new locations using proven technology. Do your VPN systems need to satisfy especially high performance requirements? Reinhard Görtner: As a media company we work with large data volumes, especially with video. We do, therefore, have high requirements on the performance of our VPN systems. For central administration, you use the Central Management Station genucenter. What tasks do you perform with it and how do you assess the management station? Reinhard Görtner: Up to now, we haven’t used the Central Management Station genucenter ourselves, as genua has performed that work for us thus far. That will change with the installation of the new components. genua support handles the administration of the the security solutions. What are your experiences with this service? Reinhard Görtner: The administration of our systems by genua support runs very well. Queries are processed quickly and competently. With respect to IT security, what challenges do you see for your company? Reinhard Görtner: The high-performance and secure connection of our locations and partners is, in addition to the appropriate response to future threats, one of the greatest challenges of the future. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Firewalls & Gateways Network Security VPN Share Article Related Links VPN security solutions Our VPN solutions are produced in Germany and function with the strongest encryption algorithms. Furthermore, we offer solutions that are approved for use with restricted data. High Resistance Firewall genugate Complete data analysis for maximum network security Central Management Station genucenter Convenient and efficient administration of IT security solutions Back to Overview

New QuaSiModO Research Project Launched

Interviews 14.11.2019 New QuaSiModO Research Project Launched Soon quantum computers will be expected to solve highly complex computing tasks extremely quickly. They therefore already pose a threat to the current encryption algorithms. Quasimodo research project In the QuaSiModO (Quantum-Safe VPN Modules and Operation Modes) research project, new quantum-resistant algorithms are being investigated, tested and implemented in VPN standards and VPN implementations. genua is the project coordinator and is represented in the project by Stefan-Lukas Gazdag. In the interview below, the cryptography expert answers questions about the research content. genua recognized the importance of the topic of "Consequences of the quantum computer for IT security" early on. How come? Stefan-Lukas Gazdag: As a provider of solutions for IT high security, we closely follow all new developments in network technology and network security. We first came across the term "post-quantum cryptography" around ten years ago, and immediately began preparing for the threat of large quantum computers. The first step was the squareUP research project in which we brought quantum-resistant signatures for software updates to practical maturity. Can QuaSiModO build on the squareUP research project? What are the differences between them? Stefan-Lukas Gazdag: squareUP gave us important insights into the practical use of quantum-resistant methods, but with a focus on digital signatures and the application of software updates. QuaSiModO is about securing the communication protocols with suitable key exchange procedures. This is much more complex, and an exchange with a quantum-resistant alternative is correspondingly difficult. "The QuaSiModO research project is paving the way for the practical use of quantum-resistant encryption." Various research partners are involved in QuaSiModO. What form does the cooperation actually take? Stefan-Lukas Gazdag: With ADVA and genua, two specialists for secure communication are working on similar but nevertheless different problems on different network levels. The Ludwig Maximilian University of Munich is supporting both partners organizationally and with regard to various aspects such as the evaluation of cryptographic procedures or security proofs. Fraunhofer AISEC is playing devil's advocate in this consortium, i.e. it is critically examining the results for possible avenues of attacks. What are the research objectives by the end of the project in 2022? Stefan-Lukas Gazdag: In particular, the project is intended to help extend existing protocols. We want to examine possible solutions in detail and thus support the standardization committees with analyses and proposals in their decision-making. Important aspects are the practicability of the solutions and security in practice. Thank you for your time. The QuaSiModO project is funded by the Federal Ministry of Education and Research. Related links [1] To the BMBF (German Federal Ministry of Education and Research) project page for QuaSiModO (in German) [2] To the project page for QuaSiModO [3] Article: Watch Out, Crypto Hackers: The Gradual Progression to Quantum-Safe Cryptography [4] Read more about genua's current and completed research projects . Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption Research Share Article Back to Overview

Telematics 2.0: Privacy and Data Sovereignty in Zero Trust Architectures

Insights 05.09.2023 Digital Healthcare Telematics 2.0: Privacy and Data Sovereignty in Zero Trust Architectures From: Steffen Ullrich Steffen Ullrich

Remote Work with Classified Data: How to Create a Secure Infrastructure

Interviews 23.02.2022 Speed is the Key Factor – Not Hundred-Percent Security In the context of classification level "German VS-NfD", the changeover to remote operation is a particularly challenging "acid test" for IT organization. Besides defense against massive cyber attacks, shortcomings in IT governance and cyber security architectures also need to be overcome. Arnold Krille, Head of cognitix Product Development at genua, details the priorities for action. Picture: Arnold Krille, AI expert at genua GmbH Mr Krille, in the context of German classification level "Restricted", where should those responsible for IT start in order to provide fast and effective protection for the mobile ecosystems of your organization? Arnold Krille: "Network" and "user" are key dimensions of action. In the case of "network", it's all about gaining an overview of the infrastructures and technologies which reflects both the actual situation and enables comparison with the target situation. A central topic here is the connection of users via the Internet: Can central services from a service provider to the German federal government be used for this purpose? Or does an extra solution need to be found? In the second case, although greater flexibility is possible, it must also be assumed that a higher level of safeguarding will be necessary. This is because every connection to the Internet makes you the target of attackers. In addition to the functionality and performance of the connecting services, technical security must therefore always be taken into consideration: How do I dial in? How is the system itself protected against attacks? How are intrusions into the infrastructure prevented? Especially since we are generally talking about several hundred or more users who are switching to working from home or require secure mobile devices compatible with classification level "German VS-NfD". From a purely organizational viewpoint, this involves a huge amount of work. Moreover, legal frameworks also have to be taken into consideration during implementation – however, it is often the case that no IT governance exists for the expansion of remote working. In your experience, what it is needed to provide structure and clarity in this situation? Arnold Krille: This is where the perspective of the user comes into play: Which devices, programs and access does the user need and in what quality? For example, video conferences are still not possible for some remote solutions in the public sector. However, as with everything that makes collaboration and exchange easier, they are essential for the user. As far as this requirement is concerned, it would be simpler to find the appropriate end devices and programs that are compliant with classification level "German VS-NfD", and to check whether the functional requirements match the regulatory requirements such as basic IT protection. And once this has been achieved, the user needs a whole host of other things … Arnold Krille: Correct, but IT should be accustomed to this by now. In the years before the pandemic, "velocity is king" was already the motto. In other words, getting more horsepower onto the street when planning and implementing IT projects in order to keep up with the innovation cycles of device and software manufacturers. But, as we know, of the three goals "security", "usability" and "fast introduction" it is only ever possible to achieve two of them at the same time. With "usability" and "security" it was often a case of "either-or": a highly secure and quickly introduced, but extremely difficult-to-use system, or a quickly implemented, user-friendly, but high-risk solution. "Velocity is king" is now also becoming an issue in the sense that attackers also work according to this principle and shorten their innovation cycles. During the pandemic, the "industrialization" of cybercriminality was clear to see – professional hackers develop ever more sophisticated methods and tools that also enable semi-professional players to carry out successful attacks. In the new world of work, "velocity is king" is more crucial than ever for IT security. After all, attackers also shorten their cycles when developing new methods and tools. In the new world of work, "velocity is king" is more crucial than ever for IT security. After all, attackers also shorten their cycles when developing new methods and tools. Arnold Krille , AI expert at genua How do pioneers in classification level "German VS-NfD" deal with this situation? Arnold Krille: They focus on the implementation of three objectives: Firstly, connecting employees working from home or at a mobile workplace to the internal networks according to different security scenarios. Secondly, creating security that does not put obstacles in the way of the user. And thirdly, making the whole thing scalable so that, depending on the situation, a large part of the workforce can quickly change over to working from home and then back to the company locations. First and foremost, however, they don't underestimate the risks that every employee working from home poses. It is not enough to set up a VPN (Virtual Private Network) and provide security using basic tools and software. After all, the physical safeguards that provide additional protection at the company location – secured server rooms, lockable office doors, cameras in the foyer, and sometimes even a gatekeeper – are completely absent in a home office. Organizations with highly mature IT security can sometimes be thought of as a "virtual public authority" with not five, but in some case five hundred or more locations. And, accordingly, they intensify the protection of access to the public authority network from the home offices of their employees, but also from all levels of communication within the public authority network. Organizations with highly mature IT security can sometimes be thought of as a "virtual public authority". Every home office, like every location, is protected according to the highest standards. Arnold Krille What requirements with regard to basic IT protection need to be taken into consideration for remote working to ensure compliance with classification level "German VS-NfD"? Arnold Krille: Regardless of remote working, basic IT protection requires closer scrutiny at least of the critical points in the organization networks with anomaly or attack detection. When employees switch to remote working, the VPN node then becomes such a critical point. Not only because it can be attacked from outside. But also because the work processes and communication within the public authority are changing and now take place via these points. So it is a matter of safeguarding the technology infrastructure as well as the process infrastructure. This also makes the situation highly sensitive. Because this combination is a completely new challenge for IT, which cannot be modeled perfectly according to any guideline. In what way do systems for anomaly and attack detection provide further assistance? Arnold Krille: That depends on the attack scenario. A classic example is an e-mail with infected attachment sent by a supposedly known sender. By clicking on the attachment, the user gives the attacker internal access to resources, which initially is not subject to any formal, restrictive measures. When such an infection then starts to spread, it usually takes days, weeks and months before the attack is detected. This is exactly where detection measures come in. cognitix Threat Defender could intervene here as a first step, i.e., detect the anomaly, alert an IT security officer or initiate defensive measures. Here, the response to the communication behavior of the end user can be modeled in such a way that the administrator is notified promptly and can initiate appropriate measures, without his work being hindered by false alarms. We recommend to strive for a reasonable level of prevention according to the state of technology used at the organization – but also to bear in mind that there is no such thing as hundred-percent security. How does cognitix Threat Defender differ from IDS systems? Arnold Krille: A fundamental problem of IDS systems is that due to the noise in the network and the variety and quality of the detection rules, these systems detect so many anomalies that more personnel are needed to deal with them. One of the reasons for this is that only certain patterns in individual data streams can usually be monitored. Nowadays, however, it is not so much a question of "detect everything that might be suspicious". But instead correlating suspicious input signals with the overall behavior of devices and defining a certain line of defense, i.e., individual thresholds at which you want to take action. And it is exactly here that cognitix Threat Defender comes into play. If the tool detects, for example, that a signature for the most recent Windows exploit and a Chinese hacker occurs on a Linux server, it does not need to alert anyone. With cognitix Thread Defender, you can define thresholds as of when abnormal behavior really does need to be classified as dubious. Arnold Krille If, however, 20 clients received this package one after the other and then suddenly begin to transmit unexpected data traffic, this is something that will trigger an alarm. This is the beauty of the solution: On the one hand, thresholds as of when abnormal behavior really does need to be classified as dubious are defined. On the other hand, the "last line of defense" is a huge help. For example, if you discover that on Friday evening a user starts setting up communication with all servers. And then at the weekend this user suddenly begins to access services that he has never used before. This might be a very dedicated employee – but is more likely to be an unwanted guest in the system. What happens in the event of an attack? Arnold Krille: The first step is to verify what exactly the anomaly is. To do so, the administrator needs to have as complete an overview as possible of the situation. With the right insights and appropriate context, it is then possible to decide whether the anomaly is an attack, an operational fault or just unusual, but legitimate behavior of an employee. During this time, cognitix Threat Defender can already initiate initial responses. Depending on the organization's understanding of risk, this can be initial isolation measures, whereby the affected device is restricted in terms of communication or even completely isolated. A graduated response is also possible. In this case, business-critical processes can continue. All other communication, however, is restricted and the activities of a potential attacker therefore stopped, without any negative impact on the business processes. This approach gives the personnel and machine time to gather further information, to verify the anomaly using context information and to calmly plan the appropriate response. This avoids premature business interruptions caused by false positives – and also prevents the attackers from realizing that they have already been found out. It is often better to be able to continue monitoring the attacker for a while in order to understand what he is doing, what he has done and what his apparent objective is. The better understood the motives of an attacker are, the better the response to the attack will be, both in combatting the attacker and in restoring normal business operations after removal of the attacker from the network. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Public Sector Secrecy Protection Mobile Work Home Office Share Article Related Links VPN Software Client genuconnect Secure connection of Windows devices to internal networks up to classification level German VS-NfD IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

Your Career at genua GmbH

Your Career at genua Are you looking for an exciting job in the IT security industry? At genua, a leading expert in the protection of complex and critical IT infrastructures for companies and public authorities, a wide range of opportunities await you. Whether you are an experienced professional, career starter, pupil or student - we offer you an inspiring working environment with flexible working hours and attractive benefits . Join us in shaping the future of digital security and join our team at our locations in Kirchheim near Munich, Berlin, Leipzig, Cologne and Stuttgart ! Jobportal genua – Excellence in Digital Security genua is among the leading experts for the protection of especially complex and critical IT infrastructures. As an essential part of our economy and society, these are time and again the target of new attacks – be it through new technologies or unscrupulous operators. We take on these threats. Why genua? Stable and Dynamic As an independently operating subsidiary of the Bundesdruckerei Group, genua combines high financial and strategic stability with the dynamics of the IT security market. Individual and Together At genua, you’re encouraged to be yourself. We value open dialogue and different perspectives. Our goal is to find the best solution together – and that includes allowing space for mistakes along the way. We see them as opportunities to learn and grow. Innovative and Strong in Research genua plays a large role in shaping future-oriented IT security technologies. Both in research projects as well as in product development, teams of experienced experts and career starters ensure a mix of perspectives. Recipient of Numerous genua is regularly recognized for outstanding performance in the field of information security and innovative company culture. Your Perspectives for a Career with genua Your Start with Us Already on the first day, you receive an initial training plan that is tailored both individually to you as well as to the requirements of your position. Your further Development in the Company Our employees are our most important strategic success factor. As an IT security company, we bundle highly specialized technical knowledge at genua. We are very proud of the wealth of experience, the commitment and the creative potential of our employees. We therefore place a great deal of value on maintaining and promoting these characteristics. To precisely meet the respective training needs of each individual, a wide range of methods is important: In addition to classic seminar offerings, personal development also takes place with us in the form of, among other things, e-learning, internal technical presentations, mentoring by experienced colleagues or coaching. Management Track and Specialist Careers in the genua Team A career at genua is not necessarily synonymous with a classic management track. Our specialist career track offers development perspectives with focus on your technical expertise: In the form of the career levels Senior Expert and genua Fellow, it offers employees from all areas of the company an equivalent to a management track. These levels correspond to a group or department head. In concrete terms, this means that these two positions are at the same level as the corresponding management positions, and a specialist takes on tasks with a similar level of responsibility as a manager even if not responsible for personnel. Services & Benefits: What We Offer Our Employees Our mission is to create an inspiring and stimulating working environment for our team that opens long-term perspectives, development opportunities and creative freedom. To this end, we place value on, among other things … Flexibilty Whether you need flexibility in your working hours, a working time account, part-time opportunities or the ability to work remotely - we adapt to the needs of your current circumstances, ensuring a healthy work-life balance. Competitive compensation package Success is always a team effort - we reflect this in our annual target-based income. genukids As a family-friendly employer, we offer childcare services through our genukids daycare center and provide support when your children need short-term or vacation care. Healthy and energized at work In addition to flu vaccinations, quiet rooms, and massage chairs, we support your athletic activities through the EGYM Wellpass, B2Run, and partnerships with local sports clubs GeekWeek and other Employee Events Twice per year – during GeekWeek – our employees from the "Products" area tinker away on new ideas and technologies far removed from the day-to-day business. In addition, we hold events for the entire team, such as summer festivals, Christmas parties, pizza parties and release parties. genudogs Four-legged friends that are fit for the office enrich daily life at all of genua’s company locations. Fuel your day Free fruit, muesli, hot and cold beverages: check. We also offer subsidized lunch several times a week, and our "Feel-Good" team is always coming up with new ideas like smoothie weeks or ice cream specials. Occupational pension scheme It’s never too early to plan for the future – and we support you with our company pension scheme. Care for relatives Assistance with caring for family members. Current Awards Half a year of parental leave as a manager and everything is in the same place when you return? Flexibility when negotiating working hours if the family situation requires it? It's not a dream, this is genua. Hans Hein , Leiter Enterprise Solutions Emergency in the family, overnight I had to deal with a difficult situation. An understanding supervisor and helpful colleagues were always there for me during this time. Peter Schäfer , Partner Manager Sales Professionals & Career Starters We believe that technology must make our world a better and safer place. IT security is more than just a protective shield here – it is the prerequisite for ensuring that social and entrepreneurial visions and ideas can be implemented. genua therefore ensures that complex and critical IT infrastructures are effectively defended and new technologies can develop to their full potential. We are looking for team players for this challenging task. We offer both experienced experts as well as those just getting started with their career an inspiring work environment with a great deal of freedom for new ideas, an open and collaborative work culture with flat hierarchies, exciting projects and opportunities for both personal as well as professional further development. Training & Dual Studies We offer career starters more than just off-the-peg training: From day one, you will be involved in exciting projects as part of the team and contribute to developing solutions for current IT security challenges. You can also contribute your strengths and ideas to the genufix trainee company, which is managed independently by our trainees and students. Would you like to start your working life right after graduating from school? We provide vocational training for IT specialists in system integration, application development, and digital networking. We also offer apprenticeships for IT systems management, office management and marketing communication. Are you on your way to the (technical) university entrance qualification and would like to start a course of study with practical relevance? Then talk to us about a dual study program at genua. In just four and a half years you will learn a profession (FiSi, FiAn, FiDi or MATSE) and complete a bachelor's degree in computer science. Pupils & Students During our internship weeks, students get a first impression of interesting topics in the IT working world: Together with our trainees, they program, encrypt information or find out what is important in the technical training professions when handling hardware. We also regularly organize a Girls' Day especially for female students. Here they learn everything about our apprenticeships and study opportunities, solve small programming tasks and exchange information with colleagues from our team about everyday working life at genua. Are you already in the middle of your studies and would like to apply your knowledge in the real working world? At genua this opportunity is open to you in working student jobs, internships or in the form of a practice-related thesis. In any case, we value the fact that you can contribute your skills and ideas as part of a team. The field of application can be any area of the company - for example product development, quality assurance, sales or marketing. If no suitable position is currently advertised, we look forward to receiving your unsolicited application. Students are fully integrated into our teams and everyday work. If you feel like taking responsibility and contributing ideas from the very beginning, genua is the right place for you! Sophie Forker , Human Relations Trainee Firm genufix Our trainee firm is committed to social projects Career Munich, Berlin, Leipzig, Cologne, Stuttgart: Your career with the leading IT security specialist Innovation IT research projects with genua Facts & Figures A compact overview of our key business data Workshops & Trainings Bootcamps and Product Training at genua genukids Childcare with the Highest Standards

Highly Secure in Non-Secure Networks With OPC UA

Interviews 04.06.2021 Highly Secure in Non-Secure Networks With OPC UA Industrial networks must satisfy ever increasing requirements to meet the needs of Industry 4.0. In demand are comprehensive and secure network architectures that can be dynamically scaled, offer standardized interfaces, and enable simple machine integration. Within this complex framework, OPC UA, as an open standard, is an important component for secure and platform-neutral industrial communication. How do IT security experts evaluate the networking of plants and machinery with OPC UA? And is OPC UA also suitable for critical infrastructures and sensitive plant segments? Steve Schoner, Product Marketing Manager, and Markus Maier, Product Owner for Industrial Products at the IT-security company genua, explain in an expert interview how industry can resolve the conflict between networking and security. Markus Maier, Product Owner for Industrial Security Solutions, genua GmbH Why is the topic of OPC UA so important for Industry 4.0? Markus Maier: OPC UA is the industrial protocol of the future, at least for the German and European markets. As an open, platform-independent communication standard, it is independent of the transmission layer, regardless of whether TCP IP or real-time capable protocols such as TSN. And it functions on small controllers and enterprise servers alike. This applies not only for information exchange but also for services made available by the devices. How devices communicate with one another is thereby standardized. Steve Schoner: Industry 4.0 and digitization require strong networking, and OPC UA makes exactly this possible. Instead of transforming proprietary, manufacturer-specific protocols across industrial network borders and needing to worry about how data is exchanged in networks or application layers, with OPC UA a single protocol can be used, from the sensor to the cloud. With OPC UA, I can map a large portion of the horizontal and vertical layers. We at genua see ourselves as independent IT security experts. We therefore support OPC UA as a leading standard protocol. With OPC UA, the customer is not restricted to a single provider that he must select on a layer transition in the automation pyramid. He can opt for any service provider. Can you name an example of services that are typically integrated in Industry 4.0? Markus Maier: The classic network services, e.g., for device diagnosis, is one example. There are also device-specific groups – so-called companion specifications – by means of which it is, e.g., possible to standardize which services a robot offers. Manufacturers of certain device or machine categories join forces and develop their own extensions for the OPC UA standard. Steve Schoner, Product Marketing Manager, genua GmbH From the perspective of IT security, what fundamental questions arise if a secure network is to be set up for Industry 4.0? Steve Schoner: First, you should be aware of what assets are located in the network – that perhaps the network grew organically over the years and was not always throughly documented. Our cognitix Threat Defender can help answer this question by using asset detection or asset tracking to analyze which transmitters and receivers communicate with one another. Other important questions include: How should the network be structured? How can networking be performed securely? What do you want to network together? As IT security experts, how do you assess the networking of plants and machinery with OPC UA? Is that first and foremost useful or risky? Markus Maier: Under the rubric of networking and digitization, the standard is useful for industry in any case. The topic of security plays a fundamental role, of course. IT security is part of the OPC UA standard – a separate security layer was specified for this purpose. This defines mechanisms such as how services or devices identify themselves, how data is encrypted and how the authentication of this data is ensured. It also allows secured sessions between an OPC UA client and server and offers auditing services in the spirit of "when did which device or which client, server or user use certain services." OPC UA also defines an information model specifying how data can be accessed in a structured manner, such as machine data, machine states or alarms. A separate data model exists for this purpose. Thus, the interpretation of the data is standardized as well. Steve Schoner: The OPC UA protocol thereby does in fact ensure security. It defines uniform interfaces for how data and applications are accessed. Markus Maier: You also need to be aware that you are dependent on the security of the implementation of the OPC UA protocol or stack. With a given stack, you also need to work with its weaknesses. Anyone who wants to eliminate these risks should consider supplementary security solutions like our high-security cyber-diode. This diode itself allows only unidirectional communication, for example, to channel data from sensitive industrial plants into the IT-security layer of non-secure environments, such as the Internet or a cloud. If the OPC UA stack is compromised due to vulnerabilities, this does not affect the integrity of the industrial plant. In this case, attackers have no access to the plants or machinery. We also supply an encrypted data channel via IPsec from the classified data sector, independent of the OPC UA encryption. Does this mean that OPC UA significantly simplifies communication in industrial networks but, with respect to IT security, increases the risk of a compromise? Markus Maier: You can't put it quite like that. The OPC UA standard does, in fact, address the aspect of IT security and, as already explained, does take an integrated security layer for authentication and encryption into account in the design. The problem is that the user is dependent on the implementation of the OPC UA stack of the respective manufacturer. This difficult-to-assess security risk can be intercepted very well by our solutions, e.g., by means of network segmentation or a strict network separation between sensitive and non-secure areas. With the Industrial Firewall genuwall , segmentation, authentication and automation are available to the customer for checking whether a user or a machine is authorized to use a specific OPC-UA server service. And the cyber-diode strictly separates highly critical networks in which standard firewalls do not provide sufficient protection. It offers a reliable communication channel to the Internet without leaving itself vulnerable from the outside. genua is the IT-security specialist. What expertise can the company contribute to Industry 4.0? Steve Schoner: When everything is networked to everything else, the question arises as to how individual segments can be effectively secured. This is the area in which genua has its expertise. Our solutions secure domain and segment transitions. What distinguishes our products from those of other IT-security providers is that we offer not only stateful firewalls but also have an OPC UA application filter that queries authorization layers, e.g., to determine whether someone is permitted to send a message to a certain target system. We can offer network segmentation not only on the TCP/IT layer like classic firewalls but also on the application layer. Moreover, we also enable edge computing, i.e., data preprocessing and analysis on a secure platform with flexible docker apps in your own network before the data is diverted vertically for further processing. Why OPC UA? Open Platform Communications Unified Architecture , abbreviated OPC UA , is a manufacturer- and platform-independent standard for industrial communication in the context of Industry 4.0. It enables the access of data and applications in the vertical direction, i.e., of machines or field devices, all the way to the cloud as well as on a horizontal level, from machine to machine (M2M). The open communication standard is independent of the operating system, of the application and of the programming language. This allows for secure communication directly in the protocol and without additional hardware. The bandwidth spans from OPC UA components integrated in devices, plants or machinery to enterprise servers. OPC UA also integrates security mechanisms for encryption, digital signing and authentication. OPC UA thereby offers good conditions for the successful networking and digitization of industry. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Industry Industry 4.0 Share Article Related Links Industrial Firewall genuwall Strong Protection for Production Networks Data Diode cyber-diode High-Security Industrial Monitoring Back to Overview

The Goal is Crypto-Agility: Protecting Digital Infrastructures

Interviews 07.04.2020 The Goal is Crypto-Agility In just a few years, quantum computers could be ready for practical use. This is a risk scenario that must be taken seriously when considering current cryptographic methods. The effective protection of digital infrastructures against the advanced computing capabilities of quantum chips is only possible if IT security keeps pace with this development. Cryptoagility The recommended procedures described in the document "Migration to Post-Quantum Cryptography" issued by the German Federal Office for Information Security (BSI) provide guidance in this. genua has helped develop the standard for the hash-based signatures described therein and subsequently fully implemented it. Alexander von Gernler, Head of Research at genua, characterizes which aspects are especially important for IT security at public authorities and companies in this interview. Mr. von Gernler, the BSI sees an urgent need for cryptographic applications to process information requiring extended periods of confidentiality and high levels of protection. In actual terms, what does that mean for companies or public authorities? Alexander von Gernler: First of all, this is a wake-up call to understand the impact of this issue. Now is the time to audit the cryptographic processes that are used in one’s own organization. There are, however, very few companies that develop or use this specific technological know-how themselves. Usually, it is a matter of examining the deployed software in respect to post-quantum security. This in turn generally means consulting an IT service provider or manufacturer. Alexander von Gernler, Head of Research at genua Above all, the service provider must guarantee that they are familiar with the BSI's recommended procedures and their products are post-quantum secure in this context. If this is not the case, the service provider should be given a deadline by which compliance is attained. Currently, the recommended procedures cannot be fully implemented, as some studies are still pending. However, there are no excuses for the procedures that are already feasible. What time frame is realistic? This will be difficult for many businesses to assess, especially as quantum computers are perceived as a technological possibility, but not a definite prospect. Alexander von Gernler: Of course not every company can be an expert on this. But the moment IT security must withstand the scrutiny of a professional compliance and risk management audit, addressing post-quantum cryptography cannot be avoided. Public authorities and companies with high protection needs are the forerunners here. In these cases, the compliance deadline for currently available measures should not exceed six to eight months. But many companies are already specifically auditing their service providers. This is at least the observation of our research team, which has focused on post-quantum cryptography for years. Our team is highly networked with specialized IT security experts and cryptologists – both in Germany and internationally. Are there approaches that you recommend in particular for an audit? Alexander von Gernler: First of all, I believe all the BSI recommendations are suitable. They are fully appropriate to the situation and correspond to our own findings from two research projects. In addition to the BSI document, IT security experts should also address the topic of "post-quantum VPN". We are currently doing this, for example, in a research project called "QuaSiModO" (Quantum-Safe VPN Modules and Operation Modes). What is the objective of this project? Alexander von Gernler: We want to be the first German manufacturer to offer a production quality and full featured VPN with sufficient performance that is secured against quantum computer attacks. This is precisely what our customers in the high security field are demanding from us. In the research project, we are examining and testing new quantum resistant algorithms, and realizing these as VPN standards and VPN implementations. That is to say, we are developing comprehensive protection mechanisms against the attack potential of quantum computers. These can damage components of current cryptographic methods to varying degrees. While the currently used symmetrical encryption can be salvaged by the use of longer keys, today’s public key cryptography and key exchange processes cannot. To create a VPN solution such as that offered by genua, all three components must be in a functional and quantum-resistant state. That sounds like an exciting interface between research and its practical application – are there any particular developments that you are currently observing? Alexander von Gernler: There is a common vision: the goal is crypto agility. As initially stated in this interview, service providers must commit to precisely understanding the process chain in IT security. They also must prepare resilience to provide protection in a crisis situation. If for example the expert community discovers that a cryptographic process is insecure, the service provider should guarantee a smooth transition to updated functionality. The field lengths in today's Internet protocols are an excellent example from our research: frequently, just enough space is left to accommodate the keys from current methods such as RSA or Diffie-Hellman. The significantly more complex post-quantum methods, however, require more space and do not fit as easily. In our research project, we therefore need to develop suggestions on how to adapt protocol standards to the new situation. This is complicated, takes time and also requires expertise. Fortunately, we started working on this at genua quite a while ago. Is this also related to the BSI recommended procedures? Alexander von Gernler: Yes, another important element is the secure firmware update by so-called hash based signatures. genua has contributed to the development of the XMSS (RFC 8391) standard cited by the BSI in the recommended procedures, and as a manufacturer has already fully implemented it. Thus, whenever you install an update on a genua product, you can be certain that it cannot have been tampered with by an attacker using a quantum computer. And if you as our customer did not notice the recent transition – that is what crypto-agility is about! This is the kind of flexibility we are honing our products for. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Encryption Cyber Resilience Share Article Back to Overview

Find and Become a Sales Partner of the IT Security Expert

Benefit from the expertise of our sales partners For many years, genua has worked with sales partners from various industries and market segments, building a trusting and successful relationship with them. Using their technological know-how and their comprehensive expertise in their business fields, our partners precisely identify the requirements of our customers. They plan, realize and manage solutions that meet these requirements with the highest commitment to quality. You can rely on genua sales partners: Expertise Excellence in digital security requires a great deal of know-how and experience. genua partners are excellently trained and well connected. Thanks to the combination of skills and technology, you benefit from new offers and services. Regional proximity genua partners often work across multiple regions and are active near your location. In time-critical situations, genua partners are soon on site with you. IT Security made in Germany genua partners have access to solutions that have been developed and produced in Germany and certified by the German Federal Office for Information Security (BSI). This ensures that the solutions used in your infrastructure meet the highest national and international security standards. Quality The genua portfolio is developed and optimized based on certified quality management processes. This is confirmed by numerous BSI certifications and approvals. Thanks to the close cooperation between genua and its partners, feedback from our joint customers also influences the further development of our portfolio. Responsibility Fairness, integrity and an appreciation of our joint customers are at the core of our partnership. Stability As a subsidiary of the Bundesdruckerei Group, genua stands for stability and sustainability in a dynamic market. This benefits everyone who works with us. Nationwide support: genua Partnerlocator genua products are distributed by authorized sales partners who are competent local contacts for solving your IT security challenges. Find your partner now

Neben dem Job studieren und promovieren: bei genua GmbH ist das möglich

Interviews 29.06.2019 genua macht’s möglich: Neben dem Job studieren und promovieren Sales Contact Sales + 49 89 991950-902 sales@genua.eu Share Article Back to Overview

Partnerlocator

Find a genua Sales Partner near you: -- Partner Level -- --Country -- -- ZIP range -- Name of Partner Location Website State ad2b-solutions GmbH Bayreuth, Deutschland www.prelead.de Pioneer Allgeier CyRis GmbH Hamburg, Deutschland www.allgeier-cyris.de Specialist Apro GmbH Erfurt, Deutschland www.apro.gmbh/ Atos Information Technology GmbH München, Deutschland www.atos.net/de/deutschland B.I.N.S.S. Datennetze und Gefahrenmeldesysteme GmbH Berlin, Deutschland www.binss.de Specialist Bechtle GmbH & Co. KG Bonn, Deutschland www.bechtle.com Expert BWG Informationssysteme GmbH Ettlingen, Deutschland www.technidata-bwg.de Specialist CANCOM GmbH München, Deutschland www.cancom.de CGI Deutschland B.V. & Co. KG Leinfelden-Echterdingen, Deutschland www.cgi.com/de/de Specialist Computacenter AG & Co. oHG Kerpen, Deutschland www.computacenter.com/de-de Specialist CONET Deutschland GmbH Bonn, Deutschland www.conet.de Specialist conproIT Solutions GmbH Berlin, Deutschland www.conproit.de Pioneer controlware GmbH Dietzenbach, Deutschland Berlin, Deutschland Meerbusch, Deutschland Hagen, Deutschland Langenhagen, Deutschland Ingolstadt, Deutschland Kassel, Deutschland Leipzig, Deutschland Unterhaching, Deutschland Filderstadt, Deutschland Weyhausen, Deutschland > > mehr > > weniger www.controlware.de Expert CS-Consulting GmbH Mauer, Deutschland www.cybershield-consulting.com/de Pioneer DATAGROUP Business Solutions GmbH Pliezhausen, Deutschland www.datagroup.de Specialist Deutsche Telekom AG Bonn, Deutschland weitere Standorte www.telekom.com/de Expert Deutsche Telekom Business Solutions GmbH Bonn, Deutschland weitere Standorte www.business.telekom.com/at-de Expert Deutsche Telekom Geschäftskunden GmbH Bonn, Deutschland weitere Standorte www.geschaeftskunden.telekom.de Expert Deutsche Telekom MMS GmbH Dresden, Deutschland weitere Standorte www.telekom-mms.com Expert Deutsche Telekom Security GmbH Bonn, Deutschland weitere Standorte www.telekom.de/security Expert difesa GmbH & Co. KG München, Deutschland www.difesa.de Pioneer ECOS Technology GmbH Oppenheim, Deutschland www.ecos.de Specialist ESG Elektroniksystem- und Logistik GmbH Fürstenfeldbruck, Deutschland www.esg.de eurofunk Kappacher GmbH St. Johann im Pongau, Österreich https://www.eurofunk.com/ Specialist EWE TEL GmbH Oldenburg, Deutschland www.ewe.com/de Specialist FREQUENTIS AG Wien, Österreich www.frequentis.com/de HighConsulting GmbH & Co. KG Gessertshausen, Deutschland www.crsm.biz Pioneer HIMA Paul Hildebrandt GmbH Brühl, Deutschland Neuss, Deutschland Brunsbüttel, Deutschland Schwedt/Oder, Deutschland Leuna, Deutschland Frankfurt am Main, Deutschland Ludwigshafen, Deutschland Burghausen, Deutschland Fribourg, Schweiz Schwechat, Österreich weitere Standorte > > mehr > > weniger www.hima.com/de Expert hotshells GmbH Hamburg, Deutschland www.hotshells.de Pioneer HxGN Safety & Infrastructure GmbH Bonn, Deutschland www.hexagonsafetyinfrastructure.com/de-de IBM Deutschland GmbH Böblingen, Deutschland www.ibm.com/de-de Specialist IBYKUS AG für Informationstechnologie Erfurt, Deutschland www.ibykus.de Pioneer Indra Avitech GmbH Friedrichshafen, Deutschland Langen, Deutschland www.indra-avitech.aero Specialist Infodas GmbH Köln, Deutschland Berlin, Deutschland Bonn, Deutschland München, Deutschland Hamburg, Deutschland Mainz, Deutschland > > mehr > > weniger www.infodas.com/de Expert IT-Planet GmbH Magdeburg, Deutschland www.it-planet.com Pioneer ITventive AG Ludwigsburg, Deutschland https://itventive.com/ Pioneer K4 Digital GmbH Saarwellingen, Deutschland www.k4.digital Specialist LNB Lipinski Electronics e.K. Domagen, Deutschland www.lnb.de Pioneer MATERNA Infrastructure Solutions GmbH Dortmund, Deutschland www.materna-infrastructure-solutions.de Specialist MAWOH GmbH Karlsfeld, Deutschland www.mawoh.de Pioneer MESALOGIC GmbH Merenberg, Deutschland https://www.mesalogic.de/ Specialist mioso - IT Solutions GmbH & Co. KG Hamburg, Deutschland www.mioso.com Specialist msg systems ag Ismaning, Deutschland weitere Standorte www.msg.group/de/ Specialist NECO GmbH Bochum, Deutschland www.neco-gmbh.de Specialist Netcom Connected Services GmbH Berlin, Deutschland Hamburg, Deutschland Neukieritzsch, Deutschland www.netcom-cs.de Specialist NTT Germany AG & Co. KG Bad Homburg, Deutschland services.global.ntt/de-de Orange Cyberdefense Germany GmbH München, Deutschland www.orangecyberdefense.com/de/ PDE Process Data Engineering GmbH Aschaffenburg, Deutschland www.pde-gmbh.de Pioneer Phalanx IT GmbH Heilbronn, Deutschland Nürnberg, Deutschland www.phalanx-it.de Specialist Replicant IT OÜ Peetri, Rae vald, Estland https://www.replicant.ee/ Specialist SPIRIT/21 GmbH Böblingen, Deutschland Berlin, Deutschland Dresden, Deutschland Düsseldorf, Deutschland Hannover, Deutschland Rüsselsheim am Main, Deutschland Schweinfurt, Deutschland > > mehr > > weniger www.spirit21.com Specialist steep GmbH Cölpin, Deutschland Berlin, Deutschland Bonn, Deutschland Meßstetten, Deutschland Ulm, Deutschland Regen, Deutschland > > mehr > > weniger www.steep.de Specialist Swiss IT Security Deutschland GmbH Wiesbaden, Deutschland Mogendorf, Deutschland Köln, Deutschland www.sits-d.de Specialist T-Systems International GmbH Frankfurt am Main, Deutschland Aachen, Deutschland Berlin, Deutschland Bielefeld, Deutschland Bonn, Deutschland Bremen, Deutschland Darmstadt, Deutschland Dresden, Deutschland Düsseldorf, Deutschland Hamburg, Deutschland Hannover, Deutschland Jena, Deutschland Karlsruhe, Deutschland Kassel, Deutschland Kiel, Deutschland Köln, Deutschland Leinfelden-Echterdingen, Deutschland Leipzig, Deutschland Magdeburg, Deutschland München, Deutschland Münster, Deutschland Nürnberg, Deutschland Saarbrücken, Deutschland Ulm, Deutschland Weingarten, Deutschland Wolfsburg, Deutschland Zwickau, Deutschland weitere Standorte > > mehr > > weniger www.t-systems.com/de/de Expert t4 digital GmbH Hergiswil, Schweiz t4.digital Specialist Thales Deutschland GmbH Ditzingen, Deutschland www.thalesgroup.com/de/deutschland Specialist uttenthaler mediaConsulting Pfaffenhofen an der Ilm, Deutschland www.uttenthaler.de Specialist Veridos GmbH Berlin, Deutschland www.veridos.com Information about the partner levels × Pioneer genua Pioneers are familiar with the genua portfolio and support you in the selection and procurement of genua technologies according to your requirements. Specialist genua Specialists regularly qualify themselves by attending selected product-specific training courses. They are very familiar with the genua portfolio and support you not only in the selection and procurement, but also in the implementation of genua technologies according to your requirements. Expert genua Experts regularly qualify themselves by attending selected product-specific training courses. They are very familiar with the genua portfolio and support you in the selection, procurement, implementation, operation and maintenance of genua technologies according to your requirements. An expert is characterized by the additional services they offer alongside genua technologies to ensure the ongoing operation of your IT infrastructure.

genukids Day-Care Center in Kirchheim near Munich

Family Oriented Pedagogical Concept The day-care center offers parents comprehensive childcare with highest standards in education and age-appropriate development, a pleasant atmosphere and healthy nutrition. genukids is based on a design developed by genua that is oriented towards the needs of everyone involved. Focus here is on a pedagogical concept that is implemented by specialists. The all-day center thereby meets the needs of the families and those of their employer. Quality and economic viability are reviewed and ensured by us. The entire municipality of Kirchheim likewise benefits from additional childcare places. In our day-care center, we work across all age groups, which means that our three groups mix together with one another to promote the social interaction of the children. In addition, we work with the situation-oriented approach and place special emphasis on the promotion and development of basic skills. Our qualified personnel support and encourage the children together with two individuals who are completing their year of voluntary social service, the Federal Volunteers Service of the German government or with socio-pedagogical seminar interns. We place great importance here on a high ratio of staff to children to meet the needs of children and parents alike. Opened in 2009: genua Employees Expressed a Desire for Childcare A survey conducted at genua in 2008 surprised us: even though 81% of our staff is male, there was a desire for a professional and work-friendly childcare option. On account of this survey, we did some research – and learned that, through the Bavarian Child Education and Care Act (BayKiBiG), financial assistance is also available even when the supporting organization is a company. After submitting an application to the Kirchheim municipality, the acknowledgement of a need was approved and we could start planning our day-care center. From the negotiations with politicians, authorities and craftsmen to the construction work, personnel recruitment and finally the opening of the doors, genua managed the day-care center project completely on its own. The genukids childcare option offers space for 35 children Since opening, our genukids team generally supervises 35 children aged three months to twelve years. There are three age-spanning groups. Available places are divided according to age groups: 6 after-school places, 12 kindergarten places, 16 nursery places. From September 2025, we will offer 20 kindergarten and 15 nursery places. What's special: Our day-care center is available not only to the children of our employees but also to children from the municipality of Kirchheim as well as other guest municipalities. Facts genukids Opening hours from 7.30 AM to 4 PM Healthy food Max. 30 days closing time Above-average child care ratio Impressions from genukids Contact Person Christina Kulse + 49 89 991950-780 genukids@genua.eu Contact us Directions to genukids Day-Care Center > With Public Transport from Munich Rapid-transit Railway (S-Bahn) S2 (Erding) until station Heimstetten Bus 263 (Messestadt West) until bus stop Kirchheim Rathaus Walk back the road Münchener Straße Cross the square Pfarrer-Caspar-Mayr-Platz turn right into the Merowingerstraße turn left into the Schwabener Weg Cross the Überrheinerstraße and follow the footpath to genua Subway (U-Bahn) U2 / U7 until Messestadt West Bus 263 (Heimstetten) until bus stop Kirchheim Rathaus Walk further the road Münchener Straße Cross the square Pfarrer-Caspar-Mayr-Platz Turn right into the Merowingerstraße Turn left into the Schwabener Weg Cross the Überrheinerstraße and follow the footpath to genua With Car Autobahn A99, gateway Kirchheim Turn into the road Staatsstraße 2082 towards Kirchheim Follow this road for about 2,5 km until the road Erdinger Straße Turn left into the Erdinger Straße Turn the next road left into the Liebigstraße Turn the next left into the Domagkstraße Organization genua GmbH Domagkstr. 7 85551 Kirchheim near Munich, Germany Managing Director: Matthias Ochs, Marc Tesch Munich Local Court HRB 98238 Quotes From Parents and Children About genukids In my eyes, the concept is truly unique and couldn’t be better. Parents I like to go to the kindergarten because … ... we can trade and share cars with each other there, zoom zoom. Alexandru I like to go to the after-school center because … ... we can do crafts and there’s always a fun plan for the week. Leni I especially appreciate the assistance with homework provided by elementary school teachers in the after-school center as well as the good contact with the school. Parents I like to go to the kindergarten because … ... I can always play with the other kids. Lisa I like to go to the after-school center because … ... we can play soccer. Jonas All employees are very friendly. The facility is small and cozy. There are plenty of things for the children to do. Parents I like to go to the kindergarten because … ... there are a lot of kids and great books here. Emanuel I like to go to the after-school center because ... ... there are so many great toys and we can play in the garden. Alexander Support during school breaks is so extensive that I don’t need to worry at all about vacation planning. Parents I like to go to the kindergarten because … ... I like to play with the binky doll. Elina I like to go to the kindergarten because … ... there is help with homework. Klara

1 2 3 4 5 6 7 8 9 10 11 12 13 14
Contact
+ 49 89 991950-0
+ 49 89 991950-999
info(at)genua.de
  • Genua Security made in Germany Logo
  • Genua Tüv certificate
  • Genua Tüv Rheinland Zertifikat
  • Genua Tüv Zertifikat
  • © 2026 genua
  • GCC
  • Imprint
  • Data Protection and Privacy
  • Whistleblowing System
  • Terms of use
genua bdr signet