In the interview with Ralf Luithle, Co-CEO of Luithle + Luithle

In today's digital world, companies are more reliant than ever on IT security – but what does this mean in practice, and how can organizations tackle the growing threats posed by cyberattacks and meet the demands of new regulations? We discuss these and other questions with Ralf Luithle, Co-CEO and one of the founders of Luithle + Luithle GmbH.
With over 30 years of experience in the IT industry and a passion for IT security, Ralf Luithle is one of the leading experts in his field. As the technical mind behind the company, which was founded in 1991 in Gemmrigheim near Stuttgart, he has not only significantly shaped the development of L+L but has also driven innovative approaches in the IT security industry. Under his leadership, both the data centers and company locations have been certified according to the internationally recognized standard DIN ISO/IEC 27001:2022 – a testament to L+L’s unwavering commitment to the highest standards.
In the interview, we not only highlight the most pressing challenges in IT security, such as defending against ransomware attacks and the role of emergency plans, but also discuss the often underestimated influence of human factors on security architecture. Other key topics include the implementation of the NIS2 Directive, the importance of AI for future security solutions, and the role of Information Security Management Systems (ISMS) within the framework of ISO certification.
Get ready for an in-depth conversation with one of the industry’s thought leaders, who not only brings technical expertise but also practical solutions for tomorrow’s IT security challenges. The interview offers exciting insights and valuable tips not just for executives.
Silicon Valley Europe: Mr. Luithle, ransomware attacks are increasing worldwide. What current trends do you see in this area, and how can companies protect themselves effectively?
Ralf Luithle:
Unfortunately, that’s correct – this area is very dynamic, and criminals are constantly coming up with new ideas.
Here’s an overview of current figures (global):59% of all companies/organizations were affected in 2024. 70% of attacks resulted in actual encryption, meaning they were successful. Ransom demands have increased fivefold compared to the previous year! Nearly one-third of attacks were due to unpatched vulnerabilities. These figures come from the 2024 Ransomware Report by our long-standing security partner Sophos[1]
We are increasingly seeing cases where attackers focus on Office365. Web session tokens are spotted, and as a result, attackers often have an easy time. This enables highly efficient phishing campaigns to obtain details about privileged user accounts or relevant information, for example, from company management.
The emergence of AI has added even more momentum to this issue: phishing emails, for example, were easy to spot for a long time if you checked spelling and phrasing. The content, such as the frequently referenced "Arabian prince," also provided a clear indication for a long time that the email might not be valid. With the support of AI, attackers who do not master the language can now also formulate convincing emails. Criminals no longer have to search websites themselves for relevant information about the target audience to increase the likelihood of clicks. But AI not only facilitates data collection and communication for criminals; it also enables coding for less technically skilled criminals. Overall, we can therefore speak of a lower barrier to entry for potential cybercriminals.
This simplification of attack options has a wide range of negative effects. Criminals are becoming increasingly persistent, and so-called "double extortion" (additional extortion by threatening to publish data) as well as the professionalization of ransomware attacks (Ransomware-as-a-Service) are on the rise. This also means that the circle of potential victims is growing. It is no longer just large corporations and critical infrastructures that are becoming targets for attackers.
At the same time, a positive counter-trend can be observed: AI offers major advantages not only for criminals. IT security teams also benefit from the technology and use machine learning to quickly and reliably detect attacks.
In my view, good education and a correct understanding of IT security are the basis for effective protection against ransomware and other attacks: Anyone who, faced with horror stories, spends a lot of money as quickly as possible to implement as many protective measures as possible and then puts the issue aside has not understood the principle! Effective protection against cybercrime can be compared much more to oral hygiene: Brushing your teeth once will not protect them from cavities, but continuous effort will.
It also helps to break down the topic into individual phases and reflect on the respective technical and organizational measures for each phase. So, we initially consider the "Identify" phase – this is primarily about identifying the potential impact a failure of (parts of) the IT infrastructure could have on the company and where the probability of occurrence is increased.
The second phase, "Protect," is characterized by an almost creative development of concepts. Possible risks must be considered in order to provide adequate protective measures for a wide range of scenarios. This ranges from obvious and probable threat scenarios to concepts for dealing with, for example, extreme weather.
The insights gained from the first two phases are incorporated into the design of the solution for “Detect”, “Respond” and “Recover”.
We have been very successful in this regard. To date, none of the customers who have followed our strategic recommendations have been successfully compromised. Our experience shows that effective protection is possible. Although this requires numerous measures.
Silicon Valley Europe: What does a well-thought-out emergency plan look like to enable quick and targeted response in the event of an attack?
Ralf Luithle: Even a well-thought-out emergency plan does not begin only after an attack has already occurred! Important business areas and their protection requirements must be documented in the plan, responsibilities and communication channels must be clearly defined, and recovery concepts must be implemented. Individual measures can address various emergency scenarios.
To ensure that an emergency plan meets the desired quality, it is important to draft it as precisely as possible together with your security specialists or your service provider. Both technical and organizational measures must always be considered!
Such emergency plans are not only extremely helpful but are also mandatory for some companies under the NIS2 Directive. If you have not yet given this any thought, I strongly recommend that you do so as soon as possible!
You can also download our sample emergency plan for ransomware here: Luithle + Luithle - Ransomware Notfallplan
Silicon Valley Europe: It is often said that humans are the biggest weakness in IT security. How do you see this, and how can companies raise employee awareness of this issue?
Ralf Luithle: I can partially agree with this. Even in technologically well-secured environments, there is a risk if just one employee clicks carelessly or reveals valuable information during a phone call. However, employees are not only a potentially weak link in the security chain. Often, they are the link that receives the least time and money invested to integrate it into the chain. First and foremost, it is therefore important to understand employees and to question the points that may lead to unsafe behavior.
We therefore regularly train our employees through our specialists and also offer such training courses on request for our customers. We also practice dealing with phishing in a fear-free environment. This ensures that employees never hesitate to communicate abnormalities or proactively address their own mistakes. To ensure that a company's security is also guaranteed at the process level, it is necessary to specifically establish a "security culture" at the highest management level. Unfortunately, responsibility and scope are often underestimated precisely here. In particular, management often tends to deliberately disregard guidelines and policies.
If you are further interested in this topic, I would be happy to refer you to the recording of my lecture on the influence of human factors: The failure of cyber resilience - Why human factors obscure the obvious.
Silicon Valley Europe: What role do regular training and awareness campaigns play in companies' security strategies?
Ralf Luithle:
As already mentioned, I consider regular training and clear awareness campaigns to be extremely relevant in IT security! Ultimately, they can make the necessary difference. Unfortunately, however, this is still not a matter of course in German companies:
We need to differentiate between the role that such training and campaigns play and the role they should play. A recently published study provides information on security training in Germany: of the more than 5,000 employees surveyed, only 36.2% state that they are regularly trained by the company. At least another 24.4% say they receive such training at irregular intervals. Particularly alarming: just over 1/5 of those surveyed state that they have never heard of such an offer in their company. In medium-sized companies (with a size of 100 to 249 employees), the proportion is even higher: a full 27.8% have never heard of such training![2]
Especially in combination with the fact that attackers are now targeting companies across all industries and of all sizes, this borders on a scandal!
In addition, this measure will become mandatory for some companies at the latest with the NIS2 Directive! But even the already established GDPR requires technical and organizational measures to protect personal data. Training and awareness measures that are intended to comply with the GDPR can be supplemented with additional content and thus take a more holistic approach to the topic of IT security.
Silicon Valley Europe: Are there technologies that can minimize human errors in IT security measures?
Ralf Luithle:
Yes, there are several options for this. In general, this can be described as a “Zero Trust philosophy.” This approach assumes that no device, user, or service is trustworthy without prior authentication and additional authorization. Here’s a handy example:
One technology that helps minimize human error is multi-factor authentication (MFA) applications. We know this from the TAN in online banking.
For cloud services, so-called “Passkeys” are significantly better suited than the familiar multi-factor authentication (MFA). Passkeys represent a new type of authentication that can replace traditional passwords. They not only provide an exceptionally secure method but also one that is particularly user-friendly. For the user, everything appears to run in the background. They are based on a public-private key pair combination. Passkeys are resistant to phishing and data leaks because they are stored locally on the user’s device and can only be used in conjunction with a specific device and a particular application.
Silicon Valley Europe: Your data centers and locations are certified according to ISO/IEC 27001. What does this certification mean in concrete terms, and what added value does it offer your customers?
Ralf Luithle:
The ISO/IEC 27001:2022 certification confirms that we have a comprehensive and effective Information Security Management System (ISMS) that meets the highest international standards.
In concrete terms, this means that we continuously examine whether the procedures we apply and the solutions we use can be improved through appropriate measures. For example, this could involve the assignment and regular review of user rights. Any identified potential or unacceptable risks are tracked and subjected to review. This ensures that the minimization of threats to our IT systems is continuously improved and that dangers remain theoretical.
For our customers, this means that we continuously question existing security measures in all areas of our company and implement corresponding improvements. This ensures that their data is reliably protected at all times.
At our company, information security is centrally considered in every business process.
Silicon Valley Europe: How complex is it to successfully implement and maintain an ISMS in a company on an ongoing basis?
Ralf Luithle:
An information security management system (ISMS) ideally encompasses all activities and processes of a company.
The first step is to develop a basic understanding and recognize that this is not about bureaucratic red tape, but rather a methodology for appropriately addressing threats. Following the motto “just start,” increasing added value is achieved through implementation in daily work and company structure.
For example, the first step should be to document and analyze all critical business processes. What risks arise from the current approach? How can these be minimized or mitigated?
Next, appropriate policies and procedures must be defined to establish information security. To ensure that information security is maintained at every level, a basic understanding of the topic must be created among all affected employees.
To keep the system intact and ensure long-term information security, the measures that have been documented must be continuously reviewed and verified. Supporting software significantly simplifies handling, for example through transparent and evaluable dashboards. Reminders and prioritization are also essential components where the right software provides significant relief.
If you are looking for information on how to successfully introduce and maintain an ISMS or fall under the NIS2 Directive or want to obtain ISO27001 certification, you can read more here: https://spotlight.llnet.de/de-de/tesseron-iso-leichtgemacht
Silicon Valley Europe: The new NIS2 Directive brings extensive requirements with it. How well are companies prepared for this, and where do you see the greatest need for action?
Ralf Luithle:
It is clear that the topic has reached the affected companies. The problem for those affected is more about determining which solution or measure is suitable for which NIS2 requirement. The flood of information on this does not make it any easier. Sometimes, the functions of products overlap, and each provider claims to have the most important tool for compliance. This is where expert knowledge is needed, which companies should obtain from their IT partners. Regular strategy discussions should ensure that the adoption of innovations takes place in a needs-oriented and targeted manner.
Silicon Valley Europe: What role do IT service providers like L+L play in supporting their customers in complying with these regulations?
Ralf Luithle:
IT security service providers are essential for some companies. Especially those affected by the directive but lacking in-house IT security specialists (which applies to most SMEs) urgently require competent support. One aspect that makes this law relatively impenetrable is the reference to “the state of the art.” Unfortunately, this wording does not provide clear guidance and would require affected companies to always be up to date with the latest IT security technologies. For those whose core business is not IT-related, this seems utopian. As a service provider in this field, we have a very good insight into the current threat landscape and the available technologies. At L+L, we support customers of various sizes and industries, giving us a broad perspective on the situation from which every customer ultimately benefits.
Moreover, our experts are absolute specialists and can deliver added value with an external perspective or ensure that invested capital serves its intended purpose in the best possible way.
Silicon Valley Europe: What role do IT service providers like L+L play in supporting their customers in complying with these regulations?
Ralf Luithle:
AI for anomaly detection has long been a feature of the products we use. Another milestone is the (already available for some time) ability to work with natural language, enabling users to conduct searches of stored events, data, or logs without in-depth SQL knowledge. For security-related queries, we receive answers summarized to the essentials. This significantly shortens response times. Additionally, AI can prevent cases from being processed twice or dependent follow-up errors from being assessed in the wrong context.
Intelligent agents not only help us classify problems but also initiate appropriate measures.
Silicon Valley Europe: Thank you for your time and the great insights into your work.
[1] Ransomware Report | Sophos
[2] to download the study: Cybersicherheit in Zahlen - IT Magazin