SpotON – our blog around digital compliance in enterprises
SpotON – Digital Compliance
Read here regularly on selected topics, developments and news from the areas:
SAM & Cloud – use software legally compliant and cost-effective
IT Security & Threat Intelligence – protect the IT landscape effectively
Data & Digitization – manage digital assets across the lifecycle
Complion Insights – look behind the scenes of digital compliance consultants
11/09/2026
Digital Sovereignty at Any Cost? – What Happens When Data Protection Concerns Meet Reality (Part 2)
This blog post examines questions surrounding digital sovereignty. More specifically: is the call for digital sovereignty understandable in the case of the encrypted Senate administration? And where is digital sovereignty currently failing in the EU?
Since the content of this blog post is based on the cyberattack against two Berlin Senate administrations, I recommend reading the first part of this series.
A Cyber Incident with Political Explosive Potential – Attack on Berlin’s Senate Administrations (Part 1)
In the middle of last month, more precisely between August 7 and 12, two Berlin Senate administrations were successfully targeted in a cyberattack: the Senate Department for Urban Development, Building and Housing, on the one hand, and the Senate Department for Mobility, Transport, Climate Protection and the Environment, on the other. At that point, however, it was not yet known that the incident was actually much more serious and that the first signs had already been detected in June.
I never intended to become a consultant. I studied history and geography to become a secondary-school teacher, and I was a teacher out of conviction.
However, I realised fairly quickly that I would spend late nights preparing and refining my lessons, trying to make them as good as possible. At the same time, I saw that others were investing no effort at all. That frustrated me. Schools are not meritocracies. What matters is not who puts in the most effort, but how many years someone has been in the profession—and at the time, that did not seem fair to me.
SAP to Adjust Maintenance Fees in 2027 – What Companies Should Consider Now
As of January 1, 2027, SAP will adjust the maintenance fees for existing support contracts. The adjustment will affect SAP Standard Support, SAP Enterprise Support, and SAP Product Support for Large Enterprises.
The amount of the adjustment will be based on the relevant local Consumer Price Index (CPI) or on the benchmark indices applicable to the respective market. SAP is capping the increase at a maximum of 5 percent.
My first six months in IT Management consulting: lessons learned and the omnipresence of PowerPoint
Over six months ago, I started my first day as an IT management consultant - full of anticipation and, to be honest, with no real idea of what to expect. Today I know: The job lives up to all the clichés, and there’s so much more to it than that. Time for a look back - and a subjective insight into a profession that many know only through stereotypes.
We bet you’re facing at least one of these 6 licensing issues
Summer. The vacation season is in full swing. Your inbox is finally a little lighter, the phone rings less often, and many projects are on hold. Perfect conditions to put your feet up—or to take an honest look at your own license management.
From the lecture hall to Complion. Our student employee shares: “I never would have thought I’d be able to take on responsibility so quickly.”
What’s it really like to start at Complion? What can students expect during their internship semester or as a working student with us, and which skills from their studies actually help in their day-to-day work?
We spoke with our working student, Luca. In this interview, he explains why he chose Complion, what surprised him during his first few weeks, and why he recommends that other students take the plunge into consulting.
5 days in the Harz Mountains - working, laughing, and as a “thank you,” we were thrown off a 100-meter-high bridge.
Some companies send their employees to a dark conference room for team-building. We at Complion, on the other hand, head to the lush Harz Mountains, climbed a 100-meter-high suspension bridge, let ourselves be catapulted about 40 meters into the air (in this case, I was one of the catapult victims), and plunged 100 meters into the depths—but more on that later. For a week, the Complion team gathered in Elbingerode to work together, exchange ideas, have fun, and, of course, explore the area.
A ruling on the structure of U.S. government agencies brings down the EU-U.S. data agreement
At first glance, a dispute over the dismissal of an FTC commissioner seems to have little to do with data protection. But upon closer inspection, the U.S. Supreme Court has thereby removed the pillar on which the entire legal basis for data transfers from the EU to the U.S. rests.
SAP Is Always Evolving—Companies Must Take the Initiative!
SAP is accelerating the pace of change: artificial intelligence, portfolio shifts, cloud migration, new support models, data platforms, and usage-based licensing models are gradually transforming the operational, contractual, and cost models of many customers.
The Cloud Act, the Patriot Act, data transfers to third countries: Anyone who hosts their Office infrastructure with U.S. providers relinquishes a significant portion of their digital sovereignty. For companies in regulated industries, for public administration, and for any organization handling sensitive data, this poses a compliance risk.
AI-Based vulnerability discovery in the age of Anthropic, Mythos, and others: A turning point or just a fleeting trend?
The use of AI-based systems is steadily increasing. This applies not only to businesses but also to individuals, threat actors, and researchers. Anthropic recently made a particularly strong impression with announcements surrounding its latest AI model, Mythos. “Too dangerous for the public,” the media headlined.
The tool certainly seems efficient, as it finds 27-year-old security holes in OpenBSD, hundreds of vulnerabilities in Firefox, and countless bugs in the Linux kernel.
Does this now spell the end of software security in enterprises? Are we even facing a paradigm shift – or just a hyped-up trend?