Cybersecurity in the IT Landscape

Cybersecurity in the Modern IT Landscape: Protection Measures and Strategies for Advertising Agencies
Last updated: January 2025
Digital transformation has fundamentally changed the advertising industry. Workflows are increasingly digitized. Managing sensitive customer data presents new challenges. As an advertising agency, you face the challenge of effectively protecting your digital assets. This guide is based on current insights from the Federal Office for Information Security (BSI). It offers you practical insights into modern cybersecurity strategies.
The Current Threat Landscape
According to the current BSI Report on the State of IT Security in Germany (see BSI Report), the threat of cybercrime is continuously increasing. Small and medium-sized enterprises (SMEs), which include many advertising agencies, are particularly vulnerable. The BSI continues to classify the threat level as tense to critical.
Key threats include:
- Ransomware attacks
- Phishing and social engineering
- DDoS attacks
- Data theft
- Business Email Compromise
Legal Basis and Compliance
GDPR Requirements
The General Data Protection Regulation (GDPR) sets specific requirements for advertising agencies. You should pay particular attention to the following points:
- Documentation obligations
- Maintenance of a record of processing activities
- Documentation of technical and organizational measures (TOMs)
- Proof of compliance with GDPR principles
- Technical and organizational measures (TOMs)
- Encryption of personal data
- Ensuring confidentiality and integrity
- Regular review and evaluation of protection measures
ISO 27001
The international standard ISO 27001 defines important requirements with which you can demonstrably increase information security in your agency:
- Establishment of a documented management system
- Regular risk assessments
- Implementation of security controls
- Continuous improvement
(Note: A more in-depth article on ISO 27001 for marketing agencies is in planning. There you will learn more about the specific implementation and certification.)
Fundamental Security Measures
Access Protection and Authentication
Based on BSI recommendations, the following measures are essential:
- Implementation of Multi-Factor Authentication (MFA)
- Role-based access control
- Regular review of access rights
- Strong password policies (e.g., complexity requirements and regular updates)
Data Backup
The BSI strongly recommends a robust backup strategy, for example, according to the 3-2-1 principle:
- 3 copies of your data
- 2 different storage media (e.g., local hard drive and cloud storage)
- 1 copy in an external or network-isolated location
Additionally, the following points are relevant:
- Encryption of backups
- Regular testing of recovery procedures
- Offline backups as ransomware protection
Technical Protection Measures
Network Security
A secure network forms the foundation for your IT environment. According to BSI IT-Grundschutz, the following components should be used:
- Up-to-date firewall systems
- Network segmentation (separation of sensitive systems and public areas)
- Encrypted communication (TLS 1.3)
- VPN for remote access (e.g., for employees working from home)
Endpoint Security
To protect the end devices - laptops, desktops, smartphones - in your company, the following measures are key:
- Up-to-date antivirus software
- Regular security updates (operating systems, applications, browsers)
- Hard drive encryption (e.g., BitLocker on Windows or FileVault on macOS)
- Mobile Device Management (MDM) for smartphones and tablets
Employee Training and Security Awareness
The BSI emphasizes that employee training is a central factor for cybersecurity. Regular training should therefore be an integral part of your security concept:
- Recognition of phishing emails (patterns, sender, links)
- Secure handling of customer data (encryption, transport, storage)
- Password hygiene (using password managers, unique passwords)
- Social engineering prevention (awareness of manipulation techniques)

Incident Response
A documented emergency plan (Incident Response Plan) is crucial for an emergency. It should clearly regulate:
- Defined responsibilities (Who takes care of what?)
- Escalation processes (When is management informed?)
- Communication strategies (How and when are customers, partners, or authorities informed?)
- Recovery procedures (How is the system quickly and safely put back into operation?)
Practical Recommendations for Advertising Agencies
Based on the BSI IT-Grundschutz, the following recommendations for action arise for you:
1. Conduct a Risk Assessment
- Identification of critical assets (e.g., customer data, creative assets, internal tools)
- Assessment of potential vulnerabilities (e.g., unencrypted data storage, outdated systems)
- Documentation of protection measures (What solutions are already in place?)
2. Implement Basic Security
- Up-to-date antivirus software on all end devices
- Regular updates (operating system, software, plugins)
- Secure backup strategy (3-2-1 principle, offline backups)
- Employee training (awareness training and regular refreshers)
3. Continuous Improvement
- Regular security audits (self- and external audits)
- Adaptation to new threats (monitoring current cybersecurity trends)
- Updating documentation (e.g., emergency plans, policies)
Further Resources
- BSI for Businesses
- BSI IT-Grundschutz-Kompendium
- Alliance for Cyber Security
This article is based on official BSI recommendations and is regularly updated. For the latest information on specific security measures, it is recommended to consult the linked sources directly.
Would you like to learn more about ISO 27001? Check out its practical application in marketing and advertising agencies in the further article. There you will find more detailed information. We will delve deeper into the certification process and the specific implementation steps there.

Mario Lohe
General Manager with 15+ years of experience in business operations, agile transformation, and AI enablement. Former Director of Operations at Havas Creative Group, Head of Operations at Audiencly. Certified: CSPO, CSM, ISO 31000, Systemic Coach (DCA).
Verwandte Artikel

The Ecological Footprint of AI: Challenges and Solutions
The rapid development of artificial intelligence (AI) brings with it enormous potential as well as significant ecological challenges. AI technologies are fundamentally reshaping our daily lives and business...

Automation: Balancing Relief and Control
Automation is becoming increasingly important for accelerating processes and drastically improving efficiency in companies. But what if these automations arise without formal approval...

Is Our Digital Life Still Safe? Strategies Against Data Theft
In an increasingly digitized world, data theft poses a serious threat. When personal data such as names, addresses, bank information, or access data falls into the wrong hands...

