SpotON – our blog around digital compliance in enterprises
SpotON – Digital Compliance
Read here regularly on selected topics, developments and news from the areas:
SAM & Cloud – use software legally compliant and cost-effective
IT Security & Threat Intelligence – protect the IT landscape effectively
Data & Digitization – manage digital assets across the lifecycle
Complion Insights – look behind the scenes of digital compliance consultants
20/08/2026
My first six months in IT Management consulting: lessons learned and the omnipresence of PowerPoint
Over six months ago, I started my first day as an IT management consultant - full of anticipation and, to be honest, with no real idea of what to expect. Today I know: The job lives up to all the clichés, and there’s so much more to it than that. Time for a look back - and a subjective insight into a profession that many know only through stereotypes.
We bet you’re facing at least one of these 6 licensing issues
Summer. The vacation season is in full swing. Your inbox is finally a little lighter, the phone rings less often, and many projects are on hold. Perfect conditions to put your feet up—or to take an honest look at your own license management.
From the lecture hall to Complion. Our student employee shares: “I never would have thought I’d be able to take on responsibility so quickly.”
What’s it really like to start at Complion? What can students expect during their internship semester or as a working student with us, and which skills from their studies actually help in their day-to-day work?
We spoke with our working student, Luca. In this interview, he explains why he chose Complion, what surprised him during his first few weeks, and why he recommends that other students take the plunge into consulting.
5 days in the Harz Mountains - working, laughing, and as a “thank you,” we were thrown off a 100-meter-high bridge.
Some companies send their employees to a dark conference room for team-building. We at Complion, on the other hand, head to the lush Harz Mountains, climbed a 100-meter-high suspension bridge, let ourselves be catapulted about 40 meters into the air (in this case, I was one of the catapult victims), and plunged 100 meters into the depths—but more on that later. For a week, the Complion team gathered in Elbingerode to work together, exchange ideas, have fun, and, of course, explore the area.
A ruling on the structure of U.S. government agencies brings down the EU-U.S. data agreement
At first glance, a dispute over the dismissal of an FTC commissioner seems to have little to do with data protection. But upon closer inspection, the U.S. Supreme Court has thereby removed the pillar on which the entire legal basis for data transfers from the EU to the U.S. rests.
SAP Is Always Evolving—Companies Must Take the Initiative!
SAP is accelerating the pace of change: artificial intelligence, portfolio shifts, cloud migration, new support models, data platforms, and usage-based licensing models are gradually transforming the operational, contractual, and cost models of many customers.
The Cloud Act, the Patriot Act, data transfers to third countries: Anyone who hosts their Office infrastructure with U.S. providers relinquishes a significant portion of their digital sovereignty. For companies in regulated industries, for public administration, and for any organization handling sensitive data, this poses a compliance risk.
AI-Based vulnerability discovery in the age of Anthropic, Mythos, and others: A turning point or just a fleeting trend?
The use of AI-based systems is steadily increasing. This applies not only to businesses but also to individuals, threat actors, and researchers. Anthropic recently made a particularly strong impression with announcements surrounding its latest AI model, Mythos. “Too dangerous for the public,” the media headlined.
The tool certainly seems efficient, as it finds 27-year-old security holes in OpenBSD, hundreds of vulnerabilities in Firefox, and countless bugs in the Linux kernel.
Does this now spell the end of software security in enterprises? Are we even facing a paradigm shift – or just a hyped-up trend?
More AI, More Control, More Costs: What’s Behind Microsoft 365 E7
With the new Microsoft 365 E7, Microsoft introduced the first new enterprise licensing tier since the launch of E5 in 2015. Officially, Microsoft calls the package “The Frontier Suite”—and the name alone makes it quite clear where the journey is headed: more AI, more automation, and an even stronger tie to the Microsoft ecosystem.
Project Report: DORA Contract Compliance Implementation
The Digital Operational Resilience Act (DORA) requires financial institutions, effective January 17, 2025, to enforce new minimum contractual requirements for ICT (Information and Communication Technology) contracts with their ICT service providers. The topic of DORA has been with me since the start of my career. My project team and I were commissioned by a German financial institution to ensure its DORA contractual compliance. Based on this project experience, I would like to report in this article on our approach to the project and the insights we gained.
Communities are at the heart of modern software asset management
Those who rely solely on tools and processes in software asset management lose sight of the most important thing: people. Software asset management is no longer an IT niche but a company-wide governance discipline with a variety of specialized roles: from the SAM manager and the license manager to interfaces with procurement, controlling/finance, and IT. Only through the collaboration of all stakeholders can license-compliant and economically efficient software usage be achieved.
The Crisis as a Wake-up Call – Digital Sovereignty and the Software Supply Chain
Part 1 of the series addressed Europe’s digital dependence on non-European providers and how the flagship GAIA-X project has done little to change this. The second part focuses on open-source software and specific initiatives that can serve as alternatives to major software products in areas where Europe’s dependence is particularly acute.